cd /news/ai-safety/runtime-the-smallest-patch-tuesday-o… · home topics ai-safety article
[ARTICLE · art-125889] src=thestack.technology ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Runtime: The smallest Patch Tuesday of the rest of your life

Microsoft shipped nearly 1,000 patches on September 8, 2026, pushing its total software patches for 2026 past the combined totals for all of 2025 and 2024, according to Zero Day Initiative's Dustin Childs. The surge follows the debut of cybersecurity AI models earlier in 2026, and US security agencies separately accused six Chinese AI model companies of "engaging in aggressive, malicious, and targeted distillation activities at an industrial scale." Visa, Mastercard, and Alipay also announced a partnership this week to develop standards for agentic commerce.

by read4 min views1 publishedSep 10, 2026
Runtime: The smallest Patch Tuesday of the rest of your life
Image: Thestack (auto-discovered)

Welcome to Runtime! Today: Software patching is getting harder to manage by the month with no end in sight, the US government launches a broadside against AI model distillation, and more.

Please forward this email to a friend or colleague! If it was forwarded to you, sign up here to get Runtime for free every week, or level up here.

First up: A patch of fog

After the debut of cybersecurity AI models earlier this year so powerful that a hall pass was required to access their most powerful capabilities, security professionals quickly realized that a deluge of software patches would be arriving in the second half of 2026. But knowing something is coming and having enough time to prepare for it are different things.

Microsoft has now shipped more software patches to date in 2026 than it released for all of 2025 and 2024 combined, thanks to the nearly 1,000 patches that arrived last Tuesday. "With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck," ZDI's Dustin Childs said in a blog post.

If you're a glass-half-full person, a huge increase in the number of vulnerabilities that have been identified and addressed should be a cause for celebration; who knows how many of these flaws would have gone undetected for years if not for the new batch of cybersecurity models?

For the pessimists, however, the problems are just getting started: Managing an enormous patching to-do list without taking down mission-critical apps is easier said than done, and advanced AI models give defenders less time than they think to respond, given how quickly they can create exploits for known vulnerabilities.

Believe it or not, security companies increasingly believe that AI will be the solution to the problem caused by AI, in no small part because they are part of the small club that has exclusive access to the top-tier models that can defend as well as attack. For now, security experts advise sticking with old-school methods while moving as quickly as possible, and we'll see how that goes over the rest of the year.

The rest of The Stack

Know your agent: Identity-verification systems designed for people won't necessarily work in a world where AI agents are handling a lot of their tasks, and just like their counterparts in enterprise software, the payments networks of the world have realized they'll need a new approach. Visa, Mastercard, and Alipay announced a new partnership this week to develop standards for agentic commerce after pursuing their own, separate approaches to date.

Distill shall pass: US security agencies put six Chinese AI model companies on blast Tuesday, accusing them of "engaging in aggressive, malicious, and targeted distillation activities at an industrial scale" in order to produce the open-weight models that have caught the eye of many enterprises this year. It does not appear they are planning to take any action, but US AI companies were warned to improve their defenses against distillation, which many of them already have done.

NATS not great: Flight disruptions at UK airports after an hours-long outage at NATS Tuesday stretched well into Wednesday as airlines tried to recover from a groundstop that lasted several hours. No initial cause was provided for the outage, but it does not appear to have been the result of a cyberattack and NATS has been ordered to produce an explanation in a week.

Downtime, down money: The NATS outage will likely have a financial impact on airlines, but probably not as bad as last month's cyberattack on Boston Scientific, which told investors Tuesday that it will miss financial targets for the third quarter and calendar year as a result of the incident. The outage "impacted the company’s ability to manufacture as well as process and ship customer orders," it said, and even though it was able to recover the damage was done.

Stacking up: The week ahead

Oracle reports earnings Thursday, and investors are looking for $19.1 billion in revenue, which would be a 28% jump compared to last year, as well as an update on its AI capacity buildout.

Dreamforce kicks off Tuesday in San Francisco, and who knows which furry mascot Salesforce will debut this year.

The AI Infra Summit will take place Tuesday through Thursday in Santa Clara, Calif, featuring speakers such as Intel CEO Lip-Bu Tan and AWS hardware guru Peter DeSantis.

VerkadaOne hits Miami Beach Wednesday through Friday to discuss the intersection of physical security and AI.

AGNTCon + MCPCon speakers will be in Amsterdam next Thursday and Friday for an update on the progress of building agents around MCP.

We're also reading:

Astra for Coding: Why Are We Doing This Again?: Flask creator Armin Ronacher shared his early thoughts on coding with OpenAI's GPT-6, and they are decidedly mixed.

Procedural Graphs: Self-Evolving Execution Structures for LLM Agents: A new paper from researchers at Google explores a method for reminding your AI agents what they're supposed to be doing over a long-running session.

Thanks for reading — see you Saturday!

── more in #ai-safety 4 stories · sorted by recency
── more on @microsoft 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/runtime-the-smallest…] indexed:0 read:4min 2026-09-10 ·