Plaintext with Rich
Cybersecurity is an everyone problem. So why does it always sound like it’s only for IT people?
Each week, Rich takes one topic, from phishing to ransomware to how your phone actually tracks you, and explains it in plain language in under ten minutes or less. No buzzwords. No condescension. Just the stuff you need to know to stay safer online, explained like you’re a smart person who never had anyone break it down properly. Because you are!
Plaintext with Rich
Patch Tuesday 206 Vulnerabilities: AI Discovery vs Remediation Speed
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Your update dashboard keeps climbing. Not ten fixes, not fifty. Two hundred and six security patches waiting for approval, and everyone is asking if work stops now. That was June 2026, the largest Patch Tuesday on record.
This episode covers why record patch volumes are becoming normal, what AI-assisted vulnerability discovery has to do with the bug pipeline, how to prioritize under pressure with a four-lens triage framework (exploitability, exposure, impact, compensating controls), and why the real problem is not volume but the speed mismatch between finding bugs and fixing them. We walk through CVE-2026-45657, the wormable kernel issue rated CVSS 9.8, and what that severity score actually means for your risk timeline. You will also get a practical approach to building a 24-hour critical patch lane, classifying assets before the next wave, and using temporary containment when patching must wait.
This is for IT leaders managing emergency change windows, security teams ranking exploit paths, and business leaders deciding when downtime is justified.
One Topic, Ten minutes, No panic.
Is there a topic/term you want me to discuss next? Text me!!
YouTube more your speed? → https://links.sith2.com/YouTube
Apple Podcasts your usual stop? → https://links.sith2.com/Apple
Neither of those? Spotify’s over here → https://links.sith2.com/Spotify
Prefer reading quietly at your own pace? → https://links.sith2.com/Blog
Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord
Follow the human behind the microphone → https://links.sith2.com/linkedin
Need another way to reach me? That’s here → https://linktr.ee/rich.greene
A Dashboard Full Of Patches
SPEAKER_00It's Tuesday morning. Your coffee's still hot, and your update dashboard? Well, it looks like it's glitching. The critical count just keeps climbing. Not 10, not 50. More than 200 security patches are sitting there waiting on your approval. And your team is already asking the hard questions here. Do we stop everything and patch now or do we wait? Welcome to Plain Text with Rich.
Why June 2026 Is Different
SPEAKER_00Today we're talking about June 2026 record Patch Tuesday and what AI has to do with the flood of bugs behind it. Now, some quick definitions before we go anywhere. Patch Tuesday is Microsoft's regular monthly release day for security fixes. A vulnerability is a weakness in software that an attacker can abuse. And in June 2026, Microsoft shipped fixes for 206 vulnerabilities in a single cycle. That's the biggest Patch Tuesday anyone has ever seen. The old record was 175, and it wasn't that long ago. Now, again, a quick callback before we dive in. If you want the ground up episode on what people actually mean when they say AI and security, I would say go back and listen to episode 15. That one's the foundation of AI and security. Today is the operational version, right? What do you do when the pile gets this big? And why does this pile keep getting bigger?
Wormable Bugs And The 9.8
SPEAKER_00I'd like to start with a word some of you may or may not have seen in the headlines, and that word is wormable. Now, a wormable flaw is a bug that can spread from machine to machine on its own with little or no help from a human. Think of a grease fire in the kitchen. It catches once and then it jumps from cabinet to cabinet before you can find the extinguisher. This cycle had a bug exactly like that. It sits in the part of a Windows server that answers requests from the web. The piece that's out there talking to the internet all day. Researchers flagged it as something an attacker could reach from anywhere with no password and without anyone clicking a thing. And that in there in itself is the recipe for wormable. If you want the receipt, it's tracked as CVE 2026 47291, and it's scored as a 9.8. I'll put it in the show notes for you. Now, in plain text, CVSS is the common vulnerability scoring system. It rates severity from 0 to 10, and 9.8 is about as loud as the alarm gets. But bump the brakes, a 9.8 does not mean instant disaster in every environment, but it does mean your margin for waiting is probably a little bit thinner. When a bug is that exposed and that easy to trigger, waiting is quite honestly a gamble. That's the kind of thing that keeps people up at night. So patch management isn't a paperwork exercise, it's risk triage under a clock. Now here's a bigger
AI And The New Bug Flood
SPEAKER_00question. Why are we seeing more bugs? And why does AI keep showing up in this conversation? Well, two things are true at the same time. Number one, software today is bigger and more connected than it was 10 years ago, right? More code, more corners for bugs to hide in. And number two, AI-assisted vulnerability discovery is getting good. Real good, real fast. What that means is researchers and attackers are using machine learning to decide where to look, to generate weird inputs, and to spot fragile code faster than any human could reading it simply line by line. If I could, if you wouldn't mind, picture a beach. People have always dropped coins and keys in the sand. If one person walks it by eye, right, they find a few. Now 50 people show up with better metal detectors, suddenly they're finding a lot more, a lot faster. The beach didn't change, the coins were always there, the search itself just got more efficient. That's exactly where we are with vulnerabilities right now. Discovery is speeding up, the fixing is getting better too, but in most shops, it is not keeping the same pace. And when those two speeds drift apart, risk tends to pile up in that gap.
The Triage Lens That Works
SPEAKER_00Now, from what I've seen, here's where teams get it wrong. They look at a huge patch month and see a volume problem. Just get through the list, right? It's a prioritization problem first. You're not trying to patch everything in the next hour, right? You're trying to patch the things or the right things first and keep the business running while you do it. So here's a triage lens I would like to think you can actually use. Okay, exploitability first. Is anyone attacking this yet? Or is there working proof of concept code floating around? Okay. Exposure, second, is the weak spot facing the internet or reachable from somewhere risky? Then we take a look at impact for our third option. What actually breaks if this gets popped? Your domain controllers, your identity systems, your production line? Those are questions to be asking. We look at controls for fourth. Do you already have something in place that shrinks the damage while you stage the patch? All right. And now honestly, that last one matters more than people think. Sometimes you cannot patch a critical production system right this minute, right? And that's honestly, truly, true, truly out of my mind. That's real life. But you can still cut the risk fast, right? Lock down the network path, turn off the risky features for now, tighten the monitoring so you'd see trouble coming, right? Patch fast where you can, contain immediately where you can't. Again, those are not opposites. They're they're partners. Better bug discovery means your patch program needs better priorities, not more panic. And also, now let me make this real for the three people who might be listening right now. If you lead IT, your job is to build a decision clock, right? Not just a ticket queue. Someone has to be able to say, go at nine at night, okay? If you lead security, your job is to rank by attack path and business impact. Then translate that into plain English for the people upstairs. And if you run the business, your job is to say yes to an emergency maintenance window when the risk earns it. Same event, different levers, one outcome, fewer days exposed. Okay.
Five Moves For Faster Patching
SPEAKER_00And for everybody else, here's your starter kit, right? We're breaking this down into five moves. Move number one, build a 24-hour critical patch lane, right? Decide right now what counts as critical, who approves an emergency window, and who can call for downtime after hours. Decide it before you need it. Move number two, classify your assets before the next wave hits, right? Tag every system by how important it is and whether it touches the internet. Then you can prioritize in minutes instead of in a meeting. Move number three, write your containment playbooks ahead of time, right? For the scary flaws, pre-plan the fast moves, the firewall rule, the isolation step, the logging you turn up. All right. Move number four, measure how long fixes actually take. Track how long your critical internet-facing bugs stay open, right? Set a target. Put it in front of leadership every single month. Move number five, run one patch Tuesday drill this quarter, right? Get IT, security, and operations in a room and walk the real decision together. Practice it before the surge, not during it. And hey, honestly, if five feels like a lot, especially for a small team, start with two. The critical patch lane and the asset list. Those two alone will do more for your next cycle than buying one more dashboard and simply hoping.
The Real Headline And Your Next Step
SPEAKER_00So let's bring it home. June 2026 gave us a record patch Tuesday, right? 206 fixes, including a wormable high severity flaw sitting right on the internet's front door. But the headline isn't the volume, the headline is the speed mismatch. We are finding bugs faster than we're fixing them, and AI is a big part of why the finding got so fast. Your edge is not working harder on the list. It's disciplined triage, faster decisions, and layered containment while the patches roll out. No panic, just better patch math. Now I want to hear from you. Send me your patch Tuesday reality, right? The weirdest change control bottleneck you've ever hit, or your best two-hour containment win after a nasty CVE drop, right? Email, DM, comments, whatever channel you like. Every message gets read and every message gets answered. If you're enjoying this, go hit subscribe or follow or whatever the button says on your listening app. It's the best way to make sure the next one lands right in front of you. And as always, if this one helped, please send it to someone who'd actually benefit from listening. This has been Plain Text with Rich. One topic, 10 minutes or less, no panic.