Welcome back, Folks!
Today is Patch Tuesday for January, 2022.
It’s a big one. This month has been insane. There’s always a surge in hacking events near holidays, but this month had almost double the *known* hacking events from previous months. What’s worse is that many of the vulnerabilities used were known weeks and sometimes years in advance, though the patches were not yet installed or the specific applications and services were simply not being maintained or secured. Grrrr.
This Month in Technology
A New Leaf, Inc., Advocate Aurora Health, Alabama Department of Rehabilitation Services, All in One SEO, Amedia, Andrew Sauchelli, DMD, Apache httpd, Apple Blossom Family Practice, Azure App Service, Bansley and Kiener (B&K), Belgium’s Military, Bernalillo County, BioPlus Specialty Pharmacy Services LLC, Brazil’s Health Ministry, Broward Health, C.E. Niehoff & Company, Chaddock, Ciox Health, Commission on Elections, COVID-19 Home Tests, Crawford County Assessors Office, Daniel J. Edelman Holdings, Inc., DatPiff, The De Montfort School, Douglas C Morrow ODPC, Duneland School Corporation, Evanston Township High School, Expresso and SIC, Fertility Centers of Illinois, PLLC, FinalSite, FlexBooker, Florida Digestive Health Specialists LLP, Forensic Science Ireland, Fresenius Kabi infusion pump systems, Garrett metal detectors, Georgia Bone & Joint Surgeons, P.C., Google Docs Comment Platform, Grass Valley, CA, Gumtree, H2 Database, Hellmann Worldwide Logistics, Impresa, Inetum Group, iPhone 13, James Kagan, MD, Jefferson Surgical Clinic, Kearsarge Regional School District, LastPass, Log4j (several times), Loyola University Medical Center, Luxemburg-Casco School District, macOS powerdir, McMenamins, MedQuest Pharmacy, Inc., Microsoft Active Directory, Microsoft Teams, Monkey Kingdom (via Grape), Monongalia Health System Inc., Monroe Public Schools, Monterey Peninsula Unified School District, Netgear Nighthawk, Northwest Broward Orthopaedics Associates, North Shore Hebrew Academy High School, OG department store, ONUS, Oregon Eye Specialists, Peck & Associates, PC, Pithadia Medical Professional Services, Inc., Protemps, PulseTV, QNAP, Ravkoo, RedLine Stealer, Rhode Island Public Transit Authority, R.R. Donnelley & Sons, Running Warehouse LLC, Sainsbury’s, Saltzer Health, Saskatchewan Liquor and Gaming Authority, SEGA, Shelley School District, Shutterfly, Skate Warehouse LLC, Skin Care Specialty Physicians, Sotheby’s Realty’s Brightcove, Southern Orthopaedic Associates, Spar Stores, Standard Bank, Superior Plus, Surgery Group SC, T-Mobile, Tackle Warehouse LLC, Tennis Warehouse LCC, Tiyuli and Lametayel, UAW Retiree Medical Benefits Trust, Uber, Ubisoft, UK Defence Academy, Ultimate Kronos Group, US Commission on International Religious Freedom, UScellular, Utah Department of Health, Virginia Division of Capitol Police, Virginia General Assembly, Volvo, Walgreen Co., WD MyCloud, Welfare, Pension and Annuity Funds of Local No. ONE, I.A.T.S.E., and Zoho UEM have been hacked.
Norton 360 is now opting you in for their CPU cryptomining if you have their software installed. The very same software designed to protect you from evildoers that would take advantage of your computer to do this kind of thing…is now doing it. Apple has released an Android app under the auspice of helping users discover Tracker devices that might be tracking them…by enabling your device to allow them to communicate with the Apple Tracker network. Firefox still doesn’t properly support OCSP stapling. Dell BIOS updates are crashing devices. Microsoft has integrated their own financing platform into Edge.
Microsoft rang in the new year by breaking Microsoft Exchange (on-prem) for every server that had filtering enabled (almost all of them). Microsoft acknowledged the problem about 20 hours after it began and released resolution steps by deleting and rebuilding the scanning engine about 31 hours after it began. Sonicwall, too.
Cloudflare, AWS, Twitch, Zoom, PSN, Slack, Hulu, Imgur have had extended outages this month.
Please, for all that is holy, check your backups!
Phishing is an ever-growing problem. Sophos reminds us how to check for scams like this.
Now for the good news:
Mozilla has added Secure DNS to Firefox, now enabled by default. Unfortunately, this bypasses DNS filtering options you may have assigned yourself – so if you use Firefox you’ll need to enable your own DoH URLs within the settings.
Let’s Get Busy
Now back to our regularly scheduled program.
Patch Tuesday this month is pretty big. The typical computer should see roughly 3 GB in updates today. Let’s get started.
Microsoft released updates for.NET Framework, Microsoft Dynamics, Edge, Exchange Server, Microsoft Office, SharePoint, Microsoft Teams, Active Directory, CLFS, Windows Cryptographic Services, Windows Defender, DirectX, Windows Installer, Windows RDP, Windows Remote Desktop, ReFS, Windows Security Center, Windows Storage Spaces, Windows Tile Data Repository, Windows UEFI, Windows User Profile Service, and MSRT (~2 GB). This includes security updates. A reboot is required.
Apple released updates for Safari 15.2. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.
Google Chrome OS 96.0.4664.111 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.
Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.
Important Notes
Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.
The release of macOS Monterey (12.x) means that macOS Mojave (10.14) and older are no longer supported. If you can not install at least macOS Catalina (10.15) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.
The now-current release of the Windows 10 (v21H2) is very large so will take a long time to download on slower connections. Windows 10 pushes you to get the latest Windows 10 release every 6 months and only supports any consumer builds for 18 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.
The now-current release of the Windows 11 (v21H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 6 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.
Windows 11 is still very young so I encourage you to wait a few more months before you consider switching to it.
Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.
It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.
Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.
Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com
Driver Updates
If you’re using this hardware – these updates are for you.
Display Driver Uninstaller 18.0.4.7 removes support for Vista, updates libraries, and improves cleanup. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu
Browser Updates
One or more of these are likely to be of interest to everyone.
Brave 1.34.80 is a security update.
https://brave.com/
Google Chrome 97.0.4692.71 is a security update.
https://www.google.com/chrome/
Microsoft Edge 97.0.1072.55 is a security update.
https://www.microsoft.com/en-us/edge/business/download
Firefox 96.0 is a security update.
https://www.mozilla.org/en-US/firefox/new/
Firefox ESR 91.5.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/
Iridium 2021.12.96 is a security update.
https://iridiumbrowser.de/
SeaMonkey 2.53.10.2 is a security update.
https://www.seamonkey-project.org/
Vivaldi 5.0.2497.35 is a security update.
https://vivaldi.com/
Email Updates
One or more of these are likely to be of interest to everyone.
Thunderbird 91.5.0 is a security update.
https://www.thunderbird.net/en-US/
Internet Updates
One or more of these are likely to be of interest to everyone.
AnyDesk (macOS) 6.4.0 resolves a couple bugs. This is not a security update.
https://anydesk.com/en/downloads
curl 7.81.0 is a security update.
https://curl.haxx.se/windows/
Dropbox 139.4.4896 doesn’t provide a changelog so should be treated as a security update.
https://www.dropbox.com/
FileZilla Server 1.2.0 resolves several bugs. This is not a security update.
https://filezilla-project.org/
FreeFileSync 11.16 updates libraries and resolves several bugs. This is a security update.
https://www.freefilesync.org/download.php
Omada Software Controller 5.0.29 is a security update.
https://www.tp-link.com/us/support/download/omada-software-controller/
Prosody 0.11.11 resolves several bugs. This is not a security update.
https://prosody.im/download/start
Syncthing 1.18.6 improves usability. This is not a security update.
https://syncthing.net/
Telegram 3.4.3 resolves several bugs. This is not a security update.
https://telegram.org/
Zoom 5.9.1.2581 is a security update.
https://zoom.us/
Media Updates
These are unlikely to be of interest to most people.
darktable 3.8.0 makes nearly 4,000 changes including performance, bug fixes, new hardware support and more. This should be treated as a security update.
https://www.darktable.org/install/
Picard 2.7.2 resolves several bugs. This is not a security update.
https://picard.musicbrainz.org/
TuneIn 1.25.0 does not provide a changelog so should be treated as a security update.
https://tunein.com/radio/home/
Game Updates
These are unlikely to be of interest to most people.
Steam 2022.12.16 resolves several bugs. This is not a security update.
https://store.steampowered.com/about/
Office Updates
One or more of these are likely to be of interest to most people.
Adobe Reader DC 21.011.20039 is a security update.
https://get.adobe.com/reader
Adobe Acrobat and Reader 21.011.20039, 20.004.30020, and 17.011.30207 are security updates.
https://helpx.adobe.com/security/products/acrobat/apsb22-01.html
Adobe Illustrator 26.0.2 and 25.4.3 are security updates.
https://helpx.adobe.com/security/products/illustrator/apsb22-02.html
Adobe Bridge 12.0.1 and 11.1.3 are security updates.
https://helpx.adobe.com/security/products/bridge/apsb22-03.html
Adobe InCopy 16.4.1 is a security update.
https://helpx.adobe.com/security/products/incopy/apsb22-04.html
Adobe InDesign 16.4.1 is a security update.
https://helpx.adobe.com/security/products/indesign/apsb22-05.html
Audacity 3.1.3 improves stability. This is not a security update.
https://www.audacityteam.org/download/
Krita 5.0.2 is a major update. This version adds several features, resolves bugs and improves stability and reliability. This is not a security update.
https://krita.org/en/download/krita-desktop/
LibreOffice Fresh 7.2.5 resolves almost 100 bugs. This is not a security update. The “Fresh” line is beta software and should be avoided in favor of the stable version (“Still”) by most users.
https://www.libreoffice.org/
Nextcloud Desktop 3.4.1 resolves several bugs. This is not a security update.
https://nextcloud.com/
Notepad++ 8.2 improves stability. This is not a security update.
https://notepad-plus-plus.org/
Paint.net 4.3.7 resolves a stability bug. This is not a security update.
https://www.getpaint.net/
Security Software Updates
One or more of these is likely to be of interest to most people.
elementary OS 6.1
https://elementary.io/
Gpg4win 4.0.0 is a major update adding several new features and updates libraries. This is a security update.
https://www.gpg4win.org/download.html
KeePass 2.50 improves performance and generator, updates libraries, and resolves several bugs. This is not a security update.
https://keepass.info/
OpenSSL 1.1.1m is a security update.
https://www.openssl.org/source/
OpenSSL 3.0.1 is a security update.
https://curl.se/windows/
OpenSSL 3.0.1 is a security update.
https://slproweb.com/products/Win32OpenSSL.html
ReactOS 0.4.13 provides over 250 bug fixes and improvements. This is not a security update.
https://reactos.org/
RogueKiller 15.1.5 resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/
Tails 4.26 is a security update.
https://tails.boum.org/install/dvd-download/index.en.html
TinyWall 3.2.5 resolves several bugs. This is not a security update.
https://tinywall.pados.hu/
uBlock Origin 1.40.6 improves reliability. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest
Capture Updates
These are unlikely to be of interest to most people.
ScreenToGif 2.35.4 resolves several bugs. This is not a security update.
https://github.com/NickeManarin/ScreenToGif/releases/latest
Converter Updates
These are unlikely to be of interest to most people.
HandBrake 1.5.1 updates libraries, resolves several bugs and improves stability and reliability. This is not a security update.
https://handbrake.fr/
IsoBuster 4.9 adds support for new hardware, new formats, and resolves several bugs. This is not a security update.
https://www.isobuster.com/download.php
Utility Updates
These are unlikely to be of interest to most people.
7-Zip 21.07 adds VHDX support, improved parameter handling and compatibility. This is not a security update.
https://www.7-zip.org/
Agent Ransack 2022.3283 improves performance and reliability, and resolves several bugs. This is not a security update.
https://www.mythicsoft.com/agentransack/download/
Aomei Partition Assistant 9.6.0 resolves several bugs and improves compatibility. This is not a security update.
https://www.diskpart.com/
Autoruns 14.07 resolves several bugs. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns
Active Directory Explorer 1.51 fixes a Windows Store packaging crash. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/adexplorer
CacheSet 1.02 fixes a 64 bit OS regression. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/cacheset
Beyond Compare 4.4.1.26165 resolves several bugs and improves compatibility. This is not a security update.
https://www.scootersoftware.com/download.php?zz=dl4
ControlMyMonitor 1.31 adds a new parameter for Secondary displays. This is not a security update.
https://www.nirsoft.net/utils/control_my_monitor.html
CPU-Z 1.99 adds support for new hardware and resolves a couple bugs. This is not a security update.
https://www.cpuid.com/softwares/cpu-z.html
DesktopOK 9.51 adds dark mode. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK
dnGrep 2.9.482.0 resolves several bugs. This is not a security update.
https://dngrep.github.io/
Etcher 1.7.3 is a security update.
https://www.balena.io/etcher/
Everything 1.4.1.1015 resolves several bugs. This is not a security update.
https://www.voidtools.com/
Everything CLI 1.1.0.21 resolves several bugs. This is not a security update.
https://www.voidtools.com/
FileLocator Pro 2022.3283 provides performance and reliability improvements. This is not a security update.
https://www.mythicsoft.com/filelocatorpro/download
GoodSync 11.10.0 resolves several bugs and improves stability. This is not a security update.
https://www.goodsync.com/
Homedale 2.02 improves colors. This is not a security update.
https://www.the-sz.com/products/homedale/
Macrium Reflect 8.0.6495 doesn’t provide a changelog, so should be treated as a security update.
https://www.macrium.com/reflectfree
NTLite 2.3.2.8526 updates libraries and resolves several bugs. This is not a security update.
https://www.ntlite.com/download/
osquery 5.1.0 adds resource limiting, new objects, and resolves several bugs. This is not a security update.
https://osquery.io/downloads
PowerToys 0.53.1 adds several new features and resolves bugs. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest
Process Monitor 3.87 fixes resolves several bugs. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/procmon
Samsung Magician 7.0.1 is a major update, but doesn’t provide a changelog so should be treated as a security update.
https://www.samsung.com/semiconductor/minisite/ssd/download/tools/
SearchMyFiles 3.16 is a cosmetic update. This is not a security update.
https://www.nirsoft.net/utils/search_my_files.html
Sysmon 13.31 improves reliability. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon
TeamViewer 15.25.8 fixes a VOIP bug. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/
TraceRouteOK 2.71 updates language files. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/TraceRouteOK
WifiInfoView 2.72 updates the internal MAC database and resolves a high-DPI bug. This is not a security update.
https://www.nirsoft.net/utils/wifi_information_view.html
ZoomText 2022.2112.10.400 resolves several bugs and improves display. This is not a security update.
https://support.freedomscientific.com/Downloads/ZoomText
Developer Updates
These are unlikely to be of interest to most people.
Maraura 3.9.7 updates Java support and libraries, and resolves several bugs. This is a security update.
http://arianne.sourceforge.net/engine/marauroa.html
Docker Desktop 4.3.2 updates the scan engine to detect log4j vulnerabilities. This is a security update.
https://www.docker.com/products/docker-desktop
Godot 3.4.2 updates libraries and resolves several bugs. This is a security update.
https://godotengine.org/
Node.js 12.22.9 is a security update.
https://nodejs.org/en/
Node.js 14.18.3 is a security update.
https://nodejs.org/en/
Node.js 16.13.2 is a security update.
https://nodejs.org/en/
Node.js 17.3.1 is a security update.
https://nodejs.org/en/
SQLite 3.37.2 resolves several bugs. This is not a security update.
https://www.sqlite.org/download.html
Web Package Updates
These are likely to be of interest only to web developers.
Drupal 9.3.2 resolves a major stability bug. This is not a security update.
https://drupal.org/download
HumHub 1.10.3 is a security update.
https://www.humhub.com/en/download
MailArchiva 8.5.6 resolves several bugs. This is not a security update.
https://mailarchiva.com/
ownCloud Server 10.9 is a security update.
https://owncloud.org/install/
Piwigo 12.2.0 resolves several bugs. This is not a security update.
https://piwigo.org/
ScreenConnect 21.14.5924.8013 resolves several bugs. This is not a security update.
https://www.connectwise.com/software/control/download
SMF 2.0.19 is a security update.
https://www.simplemachines.org/
WordPress 5.8.3 is a security update.
https://wordpress.org/
Slider Revolution 6.5.14 updates libraries and resolves several bugs. This is not a security update.
https://revolution.themepunch.com/
WPBakery 6.8.0 improves compatibility and resolves several bugs. This is not a security update.
https://wpbakery.com/
Autoptimize 2.9.5 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/autoptimize/
BuddyPress 9.2.0 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/buddypress/
Social Post Feed 4.1.1 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/custom-facebook-feed/
Postie 1.9.59 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/postie/
NextScripts Social Networks Auto-Poster 4.3.25 is a security update.
https://wordpress.org/extend/plugins/social-networks-auto-poster-facebook-twitter-g/
Visual Composer 41.1 improves compatibility. This is not a security update.
https://visualcomposer.com/
WooCommerce 6.1.0 is a major update, resolving several bugs and adding features. This is not a security update.
https://wordpress.org/extend/plugins/woocommerce/
WordPress Zero Spam 5.2.9 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/zero-spam/
That’s all for now folks. Keep it clean out there. 😉
Regards,
Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/