Happy New Year, Folks!
The new year brings a lot of FUD regarding the CPU security issues Meltdown and Spectre. Yes, every CPU from the last 20 years is affected. Yes, it’s a security issue that allows evil apps to access memory they shouldn’t be allowed to. Yes, the fix is going to effectively slow down devices in order to secure them. But NO, it’s not really any more severe than any other hardware or software vulnerability. It still requires the evil app to get onto your computer, which means you either have to install it or fail to patch and secure your operating system and other applications, enabling the attacker to put evil apps on there. In other words, you’re at no significantly greater risk today than you were last week. As always, patching your operating system and applications, removing unwanted and unused applications, back up your data often, and “behaving” online remain the rule of the day.
That said, the updates today address some of these CPU issues. Unfortunately, there are higher-than-normal failure rates for this patch since it was rushed out. This means you should be more wary than usual about failures following Patch Tuesday this week. If you haven’t backed up your data recently or created a system restore point: NOW is the time to run backups – before you install updates this week. Back to our regularly scheduled program…
It’s Patch Tuesday and it’s a pretty big one. The new year has begun, and there are lots of updates for almost everything.
The typical computer should see roughly 1.5gb in updates today. Let’s get started.
Microsoft released updates to Windows, Internet Explorer, Office, .NET and MSRT (~1gb). This includes security updates. A reboot is required.
Apple released updates for macOS High Sierra 10.13.2, macOS Sierra 10.12.6, OS X El Capitan 10.11.6, iOS 11.2.2, Safari 11.0.2 (again! v. 11604.4.7.1.6 and 12604.4.7.1.6), Pro Video Formats 2.0.6, and tvOS 11.2.1. This includes security updates. Use Apple Software Update to install the most current versions. A reboot is required.
Apple released security updates for AirPort Base Station 7.7.9 (wireless ac models) and 7.6.9 (wireless n models).
iOS 11.2.2 is a security update for all iPhone 5s, iPad Air, iPod touch 6th generation and newer hardware. Previous generations of hardware are no longer supported. Use Settings, General, Software Update to install the most current version. A reboot is required.
Google Chrome OS 63.0.3239.86 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.
Adobe Flash Player 28.0.0.137 is a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac
Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.
Important Notes
Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.
I’ve had a lot of calls recently from people whose computers seem unusually slow since late October. This is a side-effect of the Windows 10 upgrade cycle, which pushes out 6gb through Windows update to get you to the latest Windows 10 release every 6 months. If you don’t let it finish and you’re on a slow connection, it will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients at The Farmory, or, if you prefer to have me mail it to you please contact me for information.
Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.
It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need.
Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.
Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com
Driver Updates
If youβre using this hardware β these updates are for you.
Crucial Storage Executive 3.5 doesn’t provide a changelog, so should be treated as a security update.
https://www.crucial.com/usa/en/support-storage-executive
Display Driver Uninstaller 17.0.8.2 improves cleanup. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu
Intel Driver Update 3.1.1 improves detection and reporting. This is not a security update.
https://www.intel.com/p/en_US/support/detect
Browser Updates
One or more of these are likely to be of interest to everyone.
Google Chrome 63.0.3239.132 is a security update. Use Menu, Help, About to install the most current version.
Firefox 57.0.4 is a security update. Use Menu, Help, About to install the most current version.
Email Updates
One or more of these are likely to be of interest to everyone.
Thunderbird 52.5.2 is a security update. Use Menu, Help, About to install the most current version.
Internet Updates
One or more of these are likely to be of interest to everyone.
DiscordApp 21.12.2017 adds animated emojis, improves screensharing quality and adds PayPal support. This is not a security update.
https://discordapp.com/download
WinSCP 5.11.3 is a security update.
https://winscp.net/eng/index.php
Evernote 6.8.7.6387 resolves several bugs. This is not a security update.
https://www.evernote.com/
uTorrent 3.5.1 Build 44332 is a security update.
https://www.utorrent.com/downloads
FileZilla 3.30.0 improves logging for update failures. Since updates often include security updates, this should be treated as a security update.
https://filezilla-project.org/
MaxMind GeoIP Data 201801 is a data refresh. This is not a security update.
https://dev.maxmind.com/geoip/
BrowsingHistoryView 2.15 adds support for Pale Moon browser. This is not a security update.
https://www.nirsoft.net/utils/browsing_history_view.html
Media Updates
These are unlikely to be of interest to most people.
VLC 2.2.8 resolves several bugs. This is a security update.
https://www.videolan.org/vlc/
Game Updates
These are unlikely to be of interest to most people.
PlayStation PS4 5.03 improves performance. This is not a security update.
https://www.playstation.com/en-us/support/system-updates/ps4/
Office Updates
One or more of these are likely to be of interest to most people.
Notepad++ 7.5.4 resolves several bugs. This is not a security update.
https://12pd.com/click?npp
OpenOffice 4.1.5 resolves several bugs. This is not a security update.
https://www.openoffice.org/download/
Paint.net 4.0.20 adds a dark theme, improves high-DPI support, and resolves many bugs. This is not a security update.
https://www.getpaint.net/
Security Software Updates
One or more of these is likely to be of interest to most people.
Norton Power Eraser 20171218 is a security update.
https://support.norton.com/sp/en/us/home/current/solutions/kb20100824120155EN_EndUserProfile_en_us
Avast! Home Edition 17.9.2322 resolves several bugs. This is a security update.
https://www.avast.com/free-antivirus-download
KeePass 1.35 resolves several bugs and updates libraries. This is a security update.
http://keepass.sourceforge.net/
DNSQuerySniffer 1.70 adds TEXT and improves data preservation. This is not a security update.
https://www.nirsoft.net/utils/dns_query_sniffer.html
RogueKiller 12.11.32 improves compatibility and adds detections. This is not a security update.
https://www.adlice.com/softwares/roguekiller/
Capture Updates
These are unlikely to be of interest to most people.
XSplit Broadcaster 3.2.1711.2916 resolves several bugs. This is not a security update.
https://www.xsplit.com/get/
XSplit Gamecaster 3.1.1708.2943 resolves several bugs. This is not a security update.
https://www.xsplit.com/get/
Converter Updates
These are unlikely to be of interest to most people.
CDex 1.97 updates libraries and resolves several bugs. This is not a security update.
http://cdex.mu/?q=download
DVDFab 10.0.7.7 adds support for additional encodings. This is not a security update.
https://www.dvdfab.cn/download.htm
IsoBuster 4.1 adds XML and DFXML exports, MFS, DC42, and resolves several bugs. This is not a security update.
https://www.isobuster.com/download.php
Utility Updates
These are unlikely to be of interest to most people.
NTLite 1.5.0.5855 resolves several bugs. Ths is not a security update.
https://www.ntlite.com/download/
1Password for Windows 6.8.492 is a huge update with dozens of fixes, improvements, new features, and more. This is a security update.
https://1password.com/downloads/
GoodSync 10.7.2 resolves several bugs, improves service compabitility and performance, and now provides local-device encryption (non-portable) for authentication storage.
https://12pd.com/click?goodsync
RoboForm 8.4.6 improves reliability and Edge support, and resolves several bugs. This is not a security update.
https://12pd.com/click?rf
BFGMiner 5.5.0 updates libraries and resolves a dozen bugs. This is a security update.
https://github.com/luke-jr/bfgminer/
DesktopOK 4.93 adds autosave support. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK
HWMonitor 1.34 adds support for newer hardware and Windows 10 1709. This is not a security update.
https://www.cpuid.com/softwares/hwmonitor.html
DevManView 1.50 adds quick-filter support. This is not a security update.
https://www.nirsoft.net/utils/device_manager_view.html
NetworkTrafficView 2.12 improves detection of Microsoft services. This is not a security update.
https://www.nirsoft.net/utils/network_traffic_view.html
USBDeview 2.73 adds port name detection. This is not a security update.
https://www.nirsoft.net/utils/usb_devices_view.html
WifiChannelMonitor 1.50 resolves a live detection bug. This is not a security update.
https://www.nirsoft.net/utils/wifi_channel_monitor.html
OSForensics 5.2.1004 improves reporting, resolves several bugs. This is not a security update.
https://www.osforensics.com/download.html
PointerStick 2.99 improves reliability. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick
WinScan2PDF 3.81 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF
WSUS Offline 11.1 resolves several detection issues. This is not a security update.
http://download.wsusoffline.net/
Autoruns 13.81 resolves several bugs. This should be treated as a security update.
https://sysinternals.com/
BgInfo 4.24 resolves several bugs. This is not a security update.
https://sysinternals.com/
Handle 4.11 now exports data to %TEMP% on 64-bit machines. This is not a security update.
https://sysinternals.com/
Sysmon 7.01 resolves reliability bugs. This is not a security update.
https://sysinternals.com/
Virtual Machine Updates
These are unlikely to be of interest to most people.
VMware Player 14.1.0 is a security update.
https://www.vmware.com/products/player/
VirtualBox 5.2.4-119785 resolves several bugs. This is not a security update.
https://www.virtualbox.org/wiki/Downloads
Web Package Updates
These are likely to be of interest only to web developers.
Drupal 8.4.4 corrects dozens of bugs. This is not a security update.
https://drupal.org/download
MailEnable Enterprise 10.11 resolves several bugs. This is not a security update.
https://www.mailenable.com/
phpMyAdmin 4.7.7 is a security update.
https://www.phpmyadmin.net/home_page/news.php
ScreenConnect 6.4.15787.6556 adds several new features. This is not a security update.
https://www.screenconnect.com/Download
Akismet 4.0.2 resolves a couple bugs. This is not a security update.
Autoptimize 2.3.2 improves resolves a couple bugs and adds cache-busting. This is not a security update.
Multisite Plugin Manager 3.1.6 adds WP CLI compatibility. This is not a security update.
Register IP β Multisite 1.8.0 adds column sortability and proxy support. This is not a security update.
Theme My Login 6.4.10 resolves a couple bugs and improves security handling. This is not a security update.
WooCommerce 3.2.6 resolves over a dozen bugs. This is not a security update.
WP Mail SMTP 1.2.2 resolves several bugs. This is not a security update.
WPtouch 4.3.23 improves custom footer logic and corrects a typo. This is not a security update.
That’s all for now folks. Keep it clean out there. π
Regards,
Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/
Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36
Thanks!