TL;DR: AI-assisted vulnerability discovery is accelerating patch volume across major vendors, with Microsoft’s July Patch Tuesday reaching 570 fixes, Chrome rising to 429, and Adobe more than doubling month over month, according to Zero Networks. The security model is shifting from detection-first remediation toward containment, because discovery speed now outstrips human response time.
NHIMG editorial — based on content published by Zero Networks: 1,000 Fixes a Month, and It Won’t Save You, The Only Winning Move Is Not to Be Reachable
By the numbers:
- Microsoft’s monthly Patch Tuesday count rose from 120 vulnerabilities in May to 200 in June and a record 570 in July, a 375% increase in two months.
- Google’s major Chrome releases jumped from 126 security fixes on May 5 to 429 on June 2, an increase of approximately 240%, before another 433 fixes on June 30.
- Adobe’s monthly vulnerability count rose from 52 vulnerabilities in May to 123 in June, a 137% increase.
Questions worth separating out
Q: How should security teams contain risk when exploit discovery outpaces patching?
A: They should focus on the identities and secrets that a vulnerability can expose, not only on closing the flaw itself.
Q: Why do broad internal trust paths make AI-speed attacks harder to stop?
A: Because automated attackers can use the same trusted pathways that legitimate users and tools already rely on.
Q: What do teams get wrong about patching and resilience?
A: Teams often mistake patch completion for risk reduction after compromise, but patching only addresses known vulnerabilities.
Practitioner guidance
- Measure first-hop reachability across critical assets Map what a representative endpoint, server, privileged identity, and workload can actually reach.
- Close unnecessary east-west pathways Remove permissive internal connections created by flat network design, legacy firewall rules, and operational convenience.
- Restrict privileged protocols at the moment of access Keep RDP, SSH, SMB, WinRM, and RPC closed until legitimate access is requested and verified.
What's in the full article
Zero Networks' full article covers the operational detail this post intentionally leaves for the source:
- The month-by-month vulnerability counts across Microsoft, Chrome, and Adobe that illustrate the pace of discovery.
- The 5-step CISO checklist with practical containment and measurement actions for internal reachability.
- The Mythos Readiness Pack components, including the Breach Map Tool and board briefing deck.
- The article’s full argument for microsegmentation as the control that limits business disruption after exploitation.
👉 Read Zero Networks' analysis of AI-driven vulnerability growth and containment →
AI vulnerability discovery vs containment: what should teams change?
Explore further
Patch velocity is no longer the decisive security variable. The article captures a real structural shift: defenders are being asked to outpace a discovery engine that can generate flaws faster than teams can safely remediate them. That does not mean patching stops mattering. It means patching alone cannot define resilience when the first compromised asset may already have broad internal reach. Practitioners should treat this as a containment problem first and a remediation problem second.
A question worth separating out:
Q: Who is accountable for limiting business impact when an exploited vulnerability slips through?
A: Accountability sits with the teams that govern exposure, access, and segmentation, not only with the teams that patch software. If one compromised endpoint can reach critical systems, the organisation has a governance problem. Boards should expect evidence that pathways are constrained before the next exploit chain begins.
👉 Read our full editorial: AI vulnerability discovery is outpacing patch-driven security models