Akamai researchers have developed an AI-driven tool, PatchDiff-AI, designed to automate the root cause analysis of vulnerabilities patched during Microsoft's regular Patch Tuesday updates. This system leverages large language models in a multi-agent configuration to rapidly analyze patched binaries, identify the underlying security flaws, and generate detailed reports, including attack vector analysis and exploitability. The tool demonstrated over 80% success in fully automated report generation, significantly accelerating the defensive response to newly disclosed vulnerabilities.
A recent case study applied PatchDiff-AI to CVE-2025-60719, a use-after-free vulnerability in the Windows Ancillary Function Driver (afd.sys) for Winsock, which affects nearly all supported Windows versions. The flaw allows local privilege escalation by enabling a low-privilege attacker to manipulate kernel memory and gain system privileges. Microsoft addressed the issue by introducing a synchronization barrier to prevent unsafe unbinding of socket endpoints during critical operations. The research and tool were presented at Black Hat Europe Arsenal, highlighting the growing role of AI in vulnerability analysis and mitigation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Akamai disclosed PatchDiff-AI, a multi-agent LLM-based system designed to automate root cause analysis of Microsoft Patch Tuesday vulnerabilities. The research reported strong accuracy across identifying patched executables, vulnerable functions, and root causes, and highlighted case studies including CVE-2025-24991 and CVE-2025-32713.
Akamai researchers published a technical analysis of CVE-2025-60719, explaining that a race condition in afd.sys can be triggered via racing IOCTL calls and may require heap spraying for reliable exploitation. The company also advised defenders to apply the patch, monitor for suspicious IOCTL activity, and use detection rules such as YARA.
Microsoft addressed CVE-2025-60719, a critical use-after-free vulnerability in the Windows Ancillary Function Driver (afd.sys), by adding synchronization barriers to prevent socket endpoints from being unbound during critical operations. The flaw could allow a local low-privilege attacker to escalate to SYSTEM privileges on many supported and unsupported Windows versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.