{"slug": "runtime-the-smallest-patch-tuesday-of-the-rest-of-your-life", "title": "Runtime: The smallest Patch Tuesday of the rest of your life", "summary": "Microsoft shipped nearly 1,000 patches on September 8, 2026, pushing its total software patches for 2026 past the combined totals for all of 2025 and 2024, according to Zero Day Initiative's Dustin Childs. The surge follows the debut of cybersecurity AI models earlier in 2026, and US security agencies separately accused six Chinese AI model companies of \"engaging in aggressive, malicious, and targeted distillation activities at an industrial scale.\" Visa, Mastercard, and Alipay also announced a partnership this week to develop standards for agentic commerce.", "body_md": "*Welcome to Runtime! Today: Software patching is getting harder to manage by the month with no end in sight, the US government launches a broadside against AI model distillation, and more.*\n\n*Please forward this email to a friend or colleague! If it was forwarded to you,* __sign up here__ *to get Runtime for free every week, or* __level up here__*.*\n\n### First up: A patch of fog\n\nAfter the debut of cybersecurity AI models earlier this year so powerful that a hall pass was required to access their most powerful capabilities, security professionals quickly realized that a deluge of software patches would be arriving in the second half of 2026. But knowing something is coming and having enough time to prepare for it are different things.\n\nMicrosoft has now shipped more software patches to date in 2026 than it released for all of 2025 and 2024 combined, thanks to the nearly 1,000 patches that arrived last Tuesday. \"With nearly 1,000 CVEs coming out from Microsoft and [__a healthy release from Adobe__](https://helpx.adobe.com/security/Home.html?ref=thestack.technology) as well, there’s a phrase from my military days that comes to mind: embrace the suck,\" ZDI's Dustin Childs [__said in a blog post__](https://www.zerodayinitiative.com/blog/2026/9/8/the-september-2026-security-update-review?ref=thestack.technology).\n\nIf you're a glass-half-full person, a huge increase in the number of vulnerabilities that have been identified and addressed should be a cause for celebration; who knows how many of these flaws would have gone undetected for years if not for the new batch of cybersecurity models?\n\nFor the pessimists, however, the problems are just getting started: Managing an enormous patching to-do list without taking down mission-critical apps is easier said than done, and advanced AI models give defenders less time than they think to respond, given how quickly they can create exploits for known vulnerabilities.\n\nBelieve it or not, security companies increasingly believe that AI will be the solution to the problem caused by AI, in no small part because [__they are part of the small club__](https://www.thestack.technology/cant-get-access-to-gpt-5-6-cyber-palo-alto-networks-will-take-your-money/) that has exclusive access to the top-tier models that can defend as well as attack. For now, [__security experts advise__](https://www.thestack.technology/patching-in-the-ai-era-move-fast-even-if-it-breaks-things/) sticking with old-school methods while moving as quickly as possible, and we'll see how that goes over the rest of the year.\n\n### The rest of The Stack\n\n**Know your agent**: Identity-verification systems designed for people won't necessarily work in a world where AI agents are handling a lot of their tasks, and just like their counterparts in enterprise software, the payments networks of the world have realized they'll need a new approach. Visa, Mastercard, and Alipay announced a new partnership this week to develop standards for agentic commerce after pursuing their own, separate approaches to date.\n\n**Distill shall pass**: US security agencies put six Chinese AI model companies on blast Tuesday, accusing them of \"engaging in aggressive, malicious, and targeted distillation activities at an industrial scale\" in order to produce the open-weight models that have caught the eye of many enterprises this year. It does not appear they are planning to take any action, but US AI companies were warned to improve their defenses against distillation, which [__many of them already have done__](https://www.thestack.technology/stolen-valor-how-researchers-discovered-some-open-weight-models-might-have-cut-corners/).\n\n**NATS not great**: Flight disruptions at UK airports after an hours-long outage at NATS Tuesday stretched well into Wednesday as airlines tried to recover from a groundstop that lasted several hours. No initial cause was provided for the outage, but it does not appear to have been the result of a cyberattack and NATS has been [__ordered to produce an explanation__](https://www.theguardian.com/world/2026/sep/09/uk-flight-cancellations-nats-martin-rolfe-heidi-alexander?ref=thestack.technology) in a week.\n\n**Downtime, down money**: The NATS outage will likely have a financial impact on airlines, but probably not as bad as last month's cyberattack on Boston Scientific, which told investors Tuesday that it will miss financial targets for the third quarter and calendar year as a result of the incident. The outage \"impacted the company’s ability to manufacture as well as process and ship customer orders,\" it said, and even though it was able to recover the damage was done.\n\n### Stacking up: The week ahead\n\n**Oracle reports earnings Thursday**, and [__investors are looking for__](https://finance.yahoo.com/quote/ORCL/analysis/?ref=thestack.technology) $19.1 billion in revenue, which would be a 28% jump compared to last year, as well as an update on its AI capacity buildout.\n\n**Dreamforce** [__kicks off Tuesday in San Francisco__](https://www.salesforce.com/dreamforce/?ref=thestack.technology), and who knows which furry mascot Salesforce will debut this year.\n\n**The AI Infra Summit** will [__take place Tuesday through Thursday__](https://www.ai-infra-summit.com/?ref=thestack.technology) in Santa Clara, Calif, featuring speakers such as Intel CEO Lip-Bu Tan and AWS hardware guru Peter DeSantis.\n\n**VerkadaOne** [__hits Miami Beach Wednesday through Friday__](https://www.verkada.com/verkada-one/?ref=thestack.technology) to discuss the intersection of physical security and AI.\n\n**AGNTCon + MCPCon** speakers [__will be in Amsterdam next Thursday and Friday__](https://events.linuxfoundation.org/agntcon-mcpcon-europe/?ref=thestack.technology) for an update on the progress of building agents around MCP.\n\n### We're also reading:\n\n[**__Astra for Coding: Why Are We Doing This Again?__**](https://lucumr.pocoo.org/2026/9/7/astra-why/?ref=thestack.technology): Flask creator Armin Ronacher shared his early thoughts on coding with OpenAI's GPT-6, and they are decidedly mixed.\n\n[**__Procedural Graphs: Self-Evolving Execution Structures for LLM Agents__**](https://arxiv.org/pdf/2609.09153?ref=thestack.technology): A new paper from researchers at Google explores a method for reminding your AI agents what they're supposed to be doing over a long-running session.\n\n*Thanks for reading — see you Saturday!*", "url": "https://wpnews.pro/news/runtime-the-smallest-patch-tuesday-of-the-rest-of-your-life", "canonical_source": "https://www.thestack.technology/runtime-the-smallest-patch-tuesday-of-the-rest-of-your-life/", "published_at": "2026-09-10 15:05:17+00:00", "updated_at": "2026-09-10 15:14:30.338179+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-agents", "artificial-intelligence"], "entities": ["Microsoft", "Zero Day Initiative", "Dustin Childs", "Adobe", "Visa", "Mastercard", "Alipay", "NATS"], "alternates": {"html": "https://wpnews.pro/news/runtime-the-smallest-patch-tuesday-of-the-rest-of-your-life", "markdown": "https://wpnews.pro/news/runtime-the-smallest-patch-tuesday-of-the-rest-of-your-life.md", "text": "https://wpnews.pro/news/runtime-the-smallest-patch-tuesday-of-the-rest-of-your-life.txt", "jsonld": "https://wpnews.pro/news/runtime-the-smallest-patch-tuesday-of-the-rest-of-your-life.jsonld"}}