/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Microsoft claims it can use AI to distinguish between security and non-security bugs 99% of the time, plans to open-source the methodology in coming months

Microsoft claims to have developed a system that correctly distinguishes between security and non-security software bugs 99% of the time …

VentureBeat Kyle Wiggers

Context & Ripple Effects

Bug classification at Microsoft has been a manual discipline for years: back in 2018, MSRC published its internal procedures for prioritizing and classifying security reports for the first time, codifying how humans decide which bugs matter. The pipeline has since been automated at both ends — MDASH now orchestrates 100+ AI agents to find vulnerabilities, and the resulting volume shows in a record-setting June 2026 Patch Tuesday fixing nearly 200 flaws.

This announcement fills the middle of that pipeline: an AI classifier that separates security-relevant bugs from ordinary ones with claimed 99% accuracy, with the methodology to be open-sourced. That follows Microsoft's earlier playbook of shipping security tooling openly, as it did when it open-sourced the Counterfit AI risk-assessment tool in 2021.

First-order effects

  • MSRC's triage teams get a filter for the growing inflow of AI-discovered findings, deciding which of the nearly 200-flaw-scale monthly queues get security engineering attention first.
  • Security researchers filing reports face faster and more consistent severity verdicts on their submissions, since classification no longer depends solely on manual reviewer judgment.

Second-order effects

  • Open-sourcing the methodology hands rival vendors and bug-bounty platforms a ready-made template, pressuring them to adopt or publish comparable classifiers rather than keep triage criteria proprietary.
  • With discovery (MDASH), classification (this system), and patch delivery (Patch Tuesday) each AI-assisted, tooling vendors and enterprise security teams can reprice around throughput rather than headcount.

Third-order effects

  • If the pattern holds, vulnerability management consolidates into end-to-end AI pipelines — find, classify, patch — making the open publication of methodologies a competitive norm and shifting the scarce resource from analyst time to validated model accuracy.
  • Widely shared classification models also create a common standard for what counts as a security bug, which regulators and insurers could eventually reference when judging vendor patching diligence.

The trend: Microsoft is assembling an AI-driven vulnerability lifecycle — autonomous discovery via MDASH, automated triage via this classifier, and record-scale patching — moving security operations from human-queued to machine-pipelined.

Discussion

  • @msftsecurity @msftsecurity on x
    Microsoft developed a #machinelearning model that correctly distinguishes between security and non-security bugs 99% of the time. Learn how: https://www.microsoft.com/...
  • @jordannovet Jordan Novet on x
    ‘At Microsoft, 47,000 developers generate nearly 30,000 bugs a month.’ that works out to 0.638 bug per developer per month https://www.microsoft.com/...
  • @epro Emil Protalinski on x
    “We discovered that by pairing machine learning models with security experts, we can significantly improve the identification and classification of security bugs.” https://venturebeat.com/...
  • @atomkirk Adam Kirk on x
    To me, this would imply that, in theory, there exists a way for a code analyzer to fail compile unless you handle security vulnerabilities just like Elm forces you to handle all runtime error possibilities https://twitter.com/...
  • @davegershgorn Dave Gershgorn on x
    if they're all tarantulas Microsoft could be making some serious bells https://twitter.com/...