Updates 2025-03-11

Happy St. Patrick’s Day, Folks!

Today is Patch Tuesday for March, 2025.

It’s as safe as it’s going to be to upgrade to Windows 11 24H2 or macOS 15/Sequoia.

If your Windows 10 (or older) computer can not be upgraded to Windows 11, or if you used a registry or installation bypass to install an older version of Windows 11 on it that is no longer supported, then it’s time for you to start looking for a replacement computer. Actually, the time was 6 weeks ago. Pickin’s are thin right now. 🙁

There were 575+ major hacks, and over 300 application updates this month. Even so, it’s a relatively minor month, with about 2.5 GB of updates for most users.

This Month in Technology

1inch, 1X Internet, 365labs, Access2Jobs, 49,000 Access Management Systems AMS), ACDC Express, Acqua Development, ACTi Corporation, Adrenalina, Adval Tech, Advantage Home Construction Insurance, Aeonsparx, AJ Taylor Electrical Contractors, Alabama Ophthalmology Associates, Albion Online, Alf DaFrè, All4Labels, Allied Tenesis, AllTrust, Allworx, Ally Financial, Almost Famous Clothing, Amalgamated Sugar, Amerman Ginder, an American political action committee (PAC), Andover Family Medicine, Android, Angel One, Anne Arundel County, Apache Atlas, Apache EventMesh, Apache Ignite, Apache Pinot, Apache Tomcat, ¡appa!, Apparel Group, Apple Safari, Archie Cochrane Ford, Arcusin, Armed Forces of the Philippines, Artistic Family Dental, Ashlar-Vellum Cobalt, Aspire Rural Health System, Aurora Boardworks, Aurora Public Schools, Australian National University, Autodesk Navisworks, Autohaus Kießling, Autoschade Pippel, Avery Products Corporation, Aya Healthcare, Azamara Cruises, Baltimore Country Club, Bangladesh Navy, Bank of America, Barhite & Holzinger Inc, Bassford Remele PA, Bay Cove Human Services, Belgium State Security Service (VSSE), Bell Ambulance, BeniPlus, Benjamin Consulting Services, Benton Police Department, Berg Engineering Consultants, Berkeley Research Group, Best Collateral, Bethany Lutheran Church, Better Auth, BH Aircraft Company, Biagi Bros, Inc, Bikur Rofeh, Birch Medical LLC, Birdsall Muller LLC, Bis Industries, Black Basta ransomware gang, Black Star, BluAgent Technologies, Blue & Co, Blue Planet, Blue Shield of California, Bosowa Berlian Motor, Boys and Girls Clubs of the Tennessee Valley, British Virgin Islands London Office, Bulgaria’s Supreme Administrative Court, Bulldog Oilfield Services, Bulverde Glass, Burdick Painting, Burlington Hydro, Bybit, Cache Valley ENT, Cafe Zupas, Callico Distributors, Cardiology of Virginia, Carolina Arthritis Associates, Carruth Compliance Consulting, Castle Rock Construction, CCL Products India, CCT Technologies, CDS in Texas, Central District Health Department, Central New York Cardiology, Central Texas Pediatric Orthopedics, Charleston Area Medical Center, Chicago Doorways, Chicago Public Schools, Chimu Agropecuaria, Ciba Cobertura Medica, City of McKinney, City Of Roseburg, City of Tarrant, City of Van, Turkey, City Plumbing & Electric Supply, Claris Vision Holdings, Clawson Honda, Cleveland Municipal Court, Cocospy, Color Dating, Colorado River Adventures, Columbus Division of Fire, Comercializadora S&E Perú, Command & Conquer Generals: Zero Hour, Community Care Alliance, Commvault Webserver, Compound Solutions, Connekted, Consultants in Pain Medicine, Convert Solar, Couri Insurance Agency, CPS Solutions, Craft CMS, Crayfish, Cricadda, Cronos Europa, Crossroads Trading Company, Cyncly Company, Dacas Argentina, Daniels Homes, Datavant Group, Delta Electronics CNCSoft-G2, Delta Electronics ISPSoft, Detroit PBS, Digital Technology Co, Dinizulu Law Group, DISA Global Solutions, Django, DocsGPT, DOGE, Donna G Rogers, CPA, Doxbin, DRClaims FL, Dynamic Closures, DZL, EAC Consulting, Edesur Dominicana, Edimax IC-7100 IP, El Corte Inglés, Elastic Kibana, Elite Advanced Laser Corporation, Endless Mountains Health Systems, Engikam, Erie Management Group, Essex County OB/GYN Associates, Euranova, Ewald Consulting, Executive Agenda, EzyLegal, F&V Capital Management, Fairhaven Shipyard Companies, FANTIN group, Fickling & Company, Fillmore County Hospital, Financial Services of America, Finastra, Finck Cigar, First Defense Fire Protection, First Federal Savings & Loan, Flat Earth Sun, Moon and Zodiac App, Flightsim Studio, FlowiseAI, Fort St. John, Fortinet FortiWeb, Franklin County, Friendship House, FTECH R&D, G&M Direct Hire, G&S Electric LLC, Gala Tech, Garantex, Genea, Georgian Government, GitLab, Goldstein Law Group, Google Chrome, Google Chrome extension platform, Government of Brazil, Government of Pakistan, Grafitec, Greencastle-Antrim Senior High School, Greenwood Village South, Gregory & Appel Insurance, Grubhub, Grupo Baston Aerossol, GS Retail, Haggin Oaks Golf, Hall Law Group, Hammond Trucking & Excavation, Hancock Public School, Hanson Cold Storage, Hatolna, HCRG Care Group, HealthRev Partners, LLC, Heartland Health Center, Help Me Grow Yolo, Heritage South Credit Union, Hewlett Packard, Hewlett Packard Enterprise, Hickory Law, Hillcrest Convalescent Center, Inc, Hipshipper, Hirsch Enterphone MESH, Hisingstads Bleck, Holiday Comfort Inn, Hollandia Dairy, Home Assistant, HomeTeamNS, Houston Symphony, HP LaserJet Pro MFP 3301fdw, Humboldt Independent Practice Association, iCloud, Indian Ministry of Culture, INDIC Electronics, Indonesian Firefighting Services, Infini, InfoReach, Inland Empire Distribution Systems, Innovative Renal Care, Insight Partners, Insyst GmbH, Interjet, INTERLINK Health Services, Internet Corporation for Assigned Names and Numbers (ICANN), 86,000 Internet of Things devices, InternetWay, Inversiones Clinica Del Meta, InvestHK, Investing.com, IRS, Island Realty, IT-IQ Botswana, Italian Government, iTP Partners, Ivanti Connect Secure (ICS), Ivanti Endpoint Manager, Ivanti Policy Secure (IPS), Ivanti Secure Access Client (ISAC), Jaguar Land Rover, Jaime Schwartz MD, Jefferson Elementary School District, Jerue Companies, Jewish Child Care Association of New York, Jildor Shoes, Johnson’s Nursery, JP Express, Juniper Networks Session Smart Router (SSR) devices, Kelsey-Seybold Clinic, Kendall Auto Group, Kensington Glass Arts, Keystone Pacific Property Management, Kings River Union Elementary, Klesk Metal Stamping, Krisala Developer, Krispy Kreme, Kronick Moskovitz Tiedemann & Girard, Kuwaiti Government, Kyocera International, Inc, La Unión, Label Studio, LandAirSea, LANIT, Laravel, Las Cruces, Laurens School District 56, Law Diary, Leadership Strategies, Leading Edge Specialized Dentistry, Leantime, Leeds United, Legacy Professionals, Legal Aid Society of Salt Lake, Lexmark, Lietvaris, Ligentia, LINKGROUP, LINTEC & LINNHOFF Holdings, Linux Kernel, Lost & Found, Loyola University Maryland, LRT, Lucee, Lucent Health Solutions, Lumen Technologies, Luminus Management, M-1 Toolworks, Mac Jee, Mackay Memorial Hospital, Magnolia Manor, Mainline Information Systems, Makai, Manning Publications, Mars Hydro, Martin Energy Group Services, Matagorda County, Medefer, Medusind, Inc, Meet and Chill, Memorial Hospital and Manor, MercadoLibre, Mercury Paper Inc, Mercy Supply, Merkanti Bank, Meta E2 F, Metro Supply Chain Group, Metropolitan Borough of Gateshead, Microsoft Edge, Microsoft Sharepoint, Microsoft Windows Debugger, Microsoft Windows Installer Service, Microsoft Windows KDC Proxy, Microsoft’s partner website, Minaris Medical America, Ministry of Agriculture, Indonesia, Ministry of Defence, India, Ministry of Foreign Affairs, Ukraine, Ministry of Health of Palau, Minnesota Exteriors, Minnesota Orthodontics, Mission, Texas, Missouri Department of Conservation, MITRE Caldera, MNJ Technologies Direct, Monroe Transportation Services, Moodle, Mosley Glick O’Brien, MOVITOOLS MotionStudio, Moxa PT Switches, MTN Group, Muller Insurance, Mundelein Park & Recreation District, My New Jersey Dentist, mySCADA, Naphix, Naples Heritage Golf & Country Club, NASCAR, National AirVibrator, National Presto Industries, Navien, NBA, Neaton Auto Products Manufacturing, Nebraska Irrigation, Nelson & Townsend, CPA’s, Neopoly, Netcom-World, New Era Enterprises, Inc, New Era Life Insurance Companies, Newton & Associates, Next TI, NHS Tayside, NI DAQExpress, Nichino Ryokka Co, NioCorp Developments Ltd, Nippon Steel, Niva Bupa, North American Fire Hose, Northern Management, NorthWest Arkansas Community College, Novi Community School District, NTT Communications Corporation, Numotion, Nuna Baby Essentials, NVIDIA Container Toolkit, NVW Newco, LLC, Oberlin Cable Co-op, Obex Medical, Omni United, Ondunova, Openreso, OpenSSH, Orange Group Romania, Ottawa Family Physicians, Oxidized Web, PACE, Pacific Honda Company, Pacific Rehabilitation Centers, Paddington Bear, PAN-OS firewalls, Paragon Partition Manager, Parallels Desktop, Paratus, Park Place Pediatric Dentistry, payapps.com, Paysera, PDF-XChange Editor, Pebble, Pedensia Graphics Distribution, Penn-Harris-Madison, Perrin Performance, Persante Health Care, Pervedant, Peter Glenn Ski Sport, Petstop, Phoenix Rehabilitation and Nursing Center, Polish Space Agency (POLSA), Portland Schools, PostgreSQL, PostHog ClickHouse, Pound Road Medical Centre, Power Pages, PPS Services Group, Praxis Eins, Precision Orthopedics and Sports Medicine, Primary Health-SMMPP & U.S. HEALTHWORKS-SMMPP, Princeton Hydro, PS, Pump.fun X account, QBurst, Quality Home Health Care, Radco Industries, Rainbow District School Board, Ray Fogg Corporate Properties, Raymond Lifestyle, Raymond Limited, RCDPRO, Reading Cooperative Bank, Reddit, Regency Media, Rennes University, Renton School District, Restorix Health, RFA Decor, Riverdale Country School, Rivers Casino Philadelphia, a prominent Riyadh-based real estate and construction firm, RJ IT Solutions, ROCK SOLID Stabilization & Reclamation, Roswell Park Comprehensive Cancer Center, Rowe Tactical, Rubrik, Ruby on Rails, RxSight, RZD, S3-Proxy, Safe-Strap Company, Saracen Properties, Sault Ste. Marie Tribe of Chippewa Indians, Schmiedetechnik Plettenberg GmbH & Co, SCLARC, Scott County, Iowa, Scottish Qualifications Authority, Seabank Group, Semyonishna, Shetland Islands Council, Shields Facilities Maintenance, Shinn Fu Company of America, Siegel Group, Signal, SimonMed Imaging, Sittab, SMC Corporation of America, Soco Systems, Solar Data Systems, SolarWinds, Somnia, SonicWall firewalls, Sorare, Sorbonne University, South African Weather Service, SPEED Co, Spring Management OK, LLC, Spyic, Spyzie, SSK Plastic Surgery, St. Andrew’s Resources for Seniors System, Star Solution Services, State Bar of Texas, Stateside Seattle, Sterling BMW, Storenvy, Story Environmental, Stram Center for Integrative Medicine, StubHub, Sublette County, WY, Summit Home Health, Sunflower Medical Group, PA, Sunnking Sustainable Solutions, SushiCo, Synelixis Solutions, System Pavers, T J Machine & Tool, T-Mobile, TensorFlow, Thai Metal Aluminium, The Agency, The Grove at Valhalla Rehabilitation and Nursing Center, The Northwestern Illinois Association, The Pension Specialist, The Phoenix Rehabilitation and Nursing Center, The Siegel Group, The Smeg Group, The Townsley Law Firm, Therma Seal Insulation Systems, Thong Sia, Thornton Engineering, Tie Down Engineering, TikTok, Title 9 Sports, Inc, TOT Mobile, Town Counsel Law & Litigation, TP-Link routers, Transak, Transkid, Trident Maritime Systems LLC, Trimble SketchUp, Tugwell Pump & Supply, Turning Point of Central California, UFCW Local 135, Unimicron, United Community Health Center, US Coast Guard, US Dept Of Defense, US Dept of Housing and Urban Development (HUD), Utsunomiya Central Clinic, Vector Engineering, VectraRx Mail Pharmacy Services, Vela Server, Vermeer Mexico, Versant Technologies, Via Credit Union, Vicky Foods, Virginia Attorney General’s office, Vičiūnai Group, VMware ESX, Volt, Vue, Wayne County, Michigan, WDNA, Webex for BroadWorks, Weed Man Canada, Wendy Wu Tours, Whitman Hospital & Medical Clinics, Wilkinson Rogers, Williamsburg-James City Schools, Window World of Raleigh, WJCC Public Schools, Woman’s Athletic Club of Chicago, WordPress Chaty Pro plugin, WordPress Essential Addons for Elementor plugin, WordPress Jupiter X Core plugin, Workforce Group, Wylie Steel Fabricators, Xactus, Xen hypervisor, Xerox VersaLink C7025, XWiki, Yahoo, Yorke & Curtis, YouTube, Zacks Investment Research, Zimbra, ZITADEL, zkLend, and Zurich Insurance have reported hacking or compromises this month.

Flight Radar 24,Mastercard, Microsoft 365, Outlook.com, X/Twitter, and ZServers/XHost (yay!) have suffered from outages this month.

Last months updates broke AutoCAD 2022, Classic Outlook (again), Microsoft 365, Outlook Drag & Drop, Windows 11 SSH, and Windows Server 2025. Microsoft did release an out-of-cycle BIOS update to fix crash bugs in ASUS devices that has persisted since October.

In other news…

Apple’s AI sucks at transcription. And they’ve disabled end-to-end encryption for users in the UK.

Microsoft is never going to give up trying to get your files into OneDrive so they can use them to feed their AI. After this, their next step will be to “accidentally” turn it on in a month or two then apologize for it later. “Oops.” Microsoft has announced they’re killing off Skype in only a couple months. An ad-supported version of Microsoft Office/365 is currently in beta.

Microsoft accounts are being targeted by an insane “password spraying” attack over the last month or so. Due to the way their authentication works, where all it takes is your email address to send you an email or text with a passcode to log you in, it’s resulting in hundreds or even thousands of messages to Microsoft account holders with these one time pin numbers.

As Microsoft launches their new 24/7 screen capture and content collection service, Recall, they are removing the Location History feature in Windows.

Many websites are now “fingerprinting” your browser to uniquely identify “you” – and the net effect is that it actually allows malicious actors to impersonate you really well.

ReliaQuest has released information about how a “tsunami of phishing messages” followed by a massive deluge of spam in order to allow hackers the cover they needed to hijack their network. It’s a great birds-eye view of how this kind of thing works. The lesson here: Don’t simply ignore a massive uptick in phishing messages or spam.

A series of vulnerabilities exist in undocumented functions in the Espressif bluetooth chips used in over a billion devices.

YouTubers are being targeted with threats of copyright strikes if they don’t spread malware. And you thought the content was bad already.

Now for the good news:

The EFF has released a tool to detect cellular spying.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is relatively minor this month. The typical computer should see roughly 2.5 GB in updates today. Let’s get started.

Microsoft released 39 updates to address 72 vulnerabilities in .NET, ASP.NET Core & Visual Studio, Azure Agent Installer, Azure Arc, Azure CLI, Azure PromptFlow, Kernel Streaming WOW Thunk Service Driver, Microsoft Edge, Microsoft Local Security Authority Server (lsasrv), Microsoft Management Console, Microsoft Office, Microsoft Office Access, Microsoft Office Excel, Microsoft Office Word, Microsoft Streaming Service, Microsoft Windows, Remote Desktop Client, Synaptics, Inc., Visual Studio, Visual Studio Code, Windows Common Log File System Driver, Windows Cross Device Service, Windows DNS Server, Windows exFAT File System, Windows Fast FAT Driver, Windows File Explorer, Windows Hyper-V, Windows Kernel Memory, Windows Kernel-Mode Drivers, Windows MapUrlToZone, Windows Mark of the Web (MOTW), Windows NTFS, Windows NTLM, Windows Remote Desktop Services, Windows Routing and Remote Access Service (RRAS), Windows Subsystem for Linux, Windows Telephony Server, Windows USB Video Driver, Windows Win32 Kernel Subsystem, and MSRT. This includes security updates. A reboot is required.

Apple released updates for iOS 18.3.2, iPadOS 18.3.2, macOS Sequoia 15.3.2, Safari 18.3.1, tvOS 18.3.1, and visionOS 2.3.2. This includes security updates. Use Apple Software Update to install the most current versions.

iOS 18.3.2 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 18.3.2 are security updates. Use Settings, General, Software Update to install the most current update.

tvOS 18.3.1 is a security update. Use System, Software Update to install the most current version.

visionOS 2.3.2 is a security update. Use System, Software Update to install the most current version.

Google ChromeOS 133.0.6943.146 and Google ChromeOS LTS 126.0.6478.265 and 132.0.6834.211 are security updates. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sequoia (15.x) means that macOS Monterey (12.x) and older are no longer supported. If you can not install at least macOS Ventura (13) on your Mac then you should immediately remove your device from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v24H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it. If not, switch to Linux (Mint is nice) or replace your computer.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with a SaferPC Subscription and we will install updates each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 25.3.1 adds support for new hardware, feature and performance improvements, and resolves several bugs. This is not a security update.
https://www.amd.com/en/support

Crucial Storage Executive 11.01 does not provide a change log so should be treated as a security update.
https://www.crucial.com/support/storage-executive

Intel Driver and Support Assistant 25.1.9.6 is a security update.
https://www.intel.com/p/en_US/support/detect

VIISAN OfficeCam 7.2.7.0 doesn’t provide a change log so should be treated as a security update.
https://www.viisan.com/en/download/type1.html

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.76.74 is a security update.
https://brave.com/

Google Chrome 134.0.6998.88 is a security update.
https://www.google.com/chrome/

Firefox 136.0.1 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 128.8.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Vivaldi 7.1.3570.60 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

DavMail Gateway 6.3.0 improves compatibility and resolves several bugs. This is a security update.
https://davmail.sourceforge.net/

Spark 3.21.3.100475 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.21.3.100474 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 136.0.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 9.0.4 resolves several crash bugs. This is not a security update.
https://anydesk.com/en/downloads

AnyDesk (macOS) 9.0.0 is a major update adding several new features and resolves compatibility and stability bugs. This is not a security update.
https://anydesk.com/en/downloads

curl 8.12.1 improves tests and resolves several bugs. This is not a security update.
https://curl.haxx.se/windows/

Dropbox 219.4.4463 resolves several stability bugs. This is not a security update.
https://www.dropbox.com/

FreeFileSync 14.2 resolves a crash bug. This is not a security update.
https://www.freefilesync.org/download.php

Google Drive 105.0 resolves several bugs. This is not a security update.
https://drive.google.com/start

Grocy Desktop 2.13.0 improves compatibility. This is not a security update.
https://github.com/grocy/grocy-desktop

MeshCentral 1.1.42 resolves several bugs. Note that this version has conflicts with Windows 7 and 2008R2 so do not enable update on these platforms. This is not a security update.
https://meshcentral.com/info/downloads.html

Microsoft Teams 1.8.00.4966 enables AI by default, feature improvements and now consumes Skype links. Skype is dead. This is not a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 31.0.0 updates libraries and resolves dozens of bugs. This should be treated as a security update.
https://nextcloud.com/

Npcap 1.81 adds several new features and performance improvements. This is not a security update.
https://nmap.org/npcap/

Rclone 1.69.1 improves compatibility and resolves several bugs. This is not a security update.
https://rclone.org/

Signal 7.45.1 resolves several bugs. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.36.2 adds chat history migration support. This is not a security update.
https://signal.org/android/apk/

Technitium DNS Server 13.4.3 improves reliability and performance. This is not a security update.
https://technitium.com/dns/

Telegram 5.12.3 resolves several bugs. This is not a security update.
https://telegram.org/

WinSCP 6.3.7 is a security update.
https://winscp.net/eng/index.php

Zoom 6.3.11.60501 resolves several bugs. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.15 improves clothing and other interactions. This is not a security update.
https://en.3tene.com/

Bitwig Studio 5.3.2 resolves several bugs. This should be treated as a security update.
https://www.bitwig.com/download/

darktable 5.0.1 resolves dozens of bugs. This is not a security update.
https://www.darktable.org/

Grayjay 285 improves sync and resolves several bugs. This is not a security update.
https://grayjay.app/index.html

iTunes 12.13.6.1 adds support for new iOS and iPadOS versions. This does not provide a detailed change log so should be treated as a security update.
https://www.apple.com/itunes/download/

KaraFun Player 3.5.3 improves offline mode and remote. This is not a security update.
https://www.karafun.com/karaoke-windows/

Plex Desktop 1.108.1.307 doesn’t provide a change log so should be treated as a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Media Server 1.41.5.9522 improves ad detection feature, performance and resolves a bunch of bugs. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.62.01 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

PS5 2025.225 improves performance and stability. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2025.03.10 resolves several bugs and improves stability. This is not a security update.
https://store.steampowered.com/news/app/593110

SteamOS SteamDeck Update 2025.03.04 is a security update.
https://store.steampowered.com/news/app/1675200/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Illustrator 28.7.5 and 29.3 are security updates.
https://helpx.adobe.com/security/products/illustrator/apsb25-17.html

Adobe InDesign 19.5.3 and 20.2 are security updates.
https://helpx.adobe.com/security/products/indesign/apsb25-19.html

Adobe Reader DC 25.001.20432, 24.001.30235 and 20.005.30763 are security updates.
https://get.adobe.com/reader

Adobe Substance 3D Designer 14.1.1 is a security update.
https://helpx.adobe.com/security/products/substance3d_designer/apsb25-22.html

Adobe Substance 3D Modeler 1.20.10 is a security update.
https://helpx.adobe.com/security/products/substance3d-modeler/apsb25-21.html

Adobe Substance 3D Painter 11.0 is a security update.
https://helpx.adobe.com/security/products/substance3d_painter/apsb25-18.html

Adobe Substance 3D Sampler 5.0 is a security update.
https://helpx.adobe.com/security/products/substance3d-sampler/apsb25-16.html

Aronium 1.45 resolves several bugs. This is not a security update.
https://aronium.com/

Artweaver 8.0.3 resolves several bugs. This is not a security update.
https://www.artweaver.de/

Audacity 3.7.2 resolves over a dozen bugs. This is not a security update.
https://www.audacityteam.org/download/

Calibre 7.26.0 resolves several bugs. This is not a security update.
https://calibre-ebook.com/

Columns++ 1.2 improves parsing and adds additional escapes and search options. This is not a security update.
https://github.com/Coises/ColumnsPlusPlus

Kdenlive 24.12.3 resolves over a dozen bugs. This is not a security update.
https://kdenlive.org/

Kindle for PC 2.7.70978 doesn’t provide a change log so should be treated as a security update.
https://www.amazon.com/kindleforpc

LibreOffice 24.8.5 resolves over 60 bugs. This is a security update.
https://www.libreoffice.org/

LibreOffice Fresh 25.2.1 resolves over 75 bugs. This is a security update. The “Fresh” line is beta software and should be avoided in favor of the standard release.
https://www.libreoffice.org/

Manager 25.3.11.2151 improves inventory feature. This is not a security update.
https://www.manager.io/

Nextcloud Desktop 3.16.0 resolves dozens of bugs. This is not a security update.
https://nextcloud.com/

Notepad++ 8.7.8 resolves several bugs. This is not a security update.
https://notepad-plus-plus.org/

Paint.net 5.1.5 adds JPEG XL support, updates libraries and resolves several bugs. This is not a security update.
https://www.getpaint.net/

PDF-XChange Editor 10.5.2.395 is a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

Operating System Updates

These are for specific Linux flavors and alternative operating systems and, sadly, are unlikely to be of interest to most people.

Tails 6.13 is a security update.
https://tails.net/install/download/index.en.html

Security Software Updates

One or more of these is likely to be of interest to most people.

IISCrypto 4.0.18 adds support for Windows Server 2025, improved logging, controls, profiles and resolves a couple bugs. This is not a security update.
https://www.nartac.com/Products/IISCrypto/Download

JShelter 0.20 resolves several bugs. This is not a security update.
https://jshelter.org/install/

KeePass 2.58 improves cosmetics, controls and adds several new import and export capabilities. This is not a security update.
https://keepass.info/

MalwareBytes Desktop Security 5.2.7.167 resolves several bugs. This is not a security update.
https://www.malwarebytes.org/antimalware/

OnionShare 2.6.3 updates libraries, resolves several bugs, improves compatibility, and log capability. This is not a security update.
https://onionshare.org/

OpenSSL 3.4.1 is a security update.
https://slproweb.com/products/Win32OpenSSL.html

ProtonVPN 3.5.3 improves stability. This is not a security update.
https://github.com/ProtonVPN/win-app/releases/latest

RogueKiller 16.1.1 resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

Stinger 13.0.0.300 adds new detections. This should be treated as a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

Capture Updates

These are unlikely to be of interest to most people.

Open Broadcaster Software 31.0.2 resolves several crash and stability bugs. This is not a security update.
https://obsproject.com/

SnagIt 25.0.0 updates libraries, adds “step capture”, smart redaction, removal of background noise and customizable sharing. Unfortunately, it also now attempts to install SQL Server Compact Edition which has been unsupported for over three years with outstanding security vulnerabilities. It also introduced a crash bug when exporting to PNG format. This is a security update. Kinda sad isn’t it: Fix a few vulnerabilities and intentionally add even more? Sigh.
https://www.techsmith.com/screen-capture.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.3.7 adds support for new hardware and improves stability. This is not a security update.
https://www.dvdfab.cn/download.htm

HandBrake 1.9.2 resolves a couple bugs. This is not a security update.
https://handbrake.fr/

StreamFab 6.2.2.5 resolves several bugs and improves compatibility. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 3.0.1.0 resolves several bugs and adds support for newer hardware. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Education updates

One or more of these are likely to be of interest to most people.

Zotero 7.0.13 resolves a couple bugs. This is not a security update.
https://www.zotero.org/

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.10.64 resolves several bugs and improves default behaviors. This is not a security update.
https://1password.com/downloads/

balenaEtcher 2.1.0 adds support for new platforms and ability to disable analytics. This is not a security update.
https://etcher.balena.io/

Beyond Compare 5.0.6.30713 resolves several bugs. This is not a security update.
https://www.scootersoftware.com/download

BgInfo 4.33 doesn’t provide a change log so should be treated as a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/bginfo

Bitwarden 2025.2.1 improves user interface and adds 2FA for unrecognized devices. This is not a security update.
https://bitwarden.com/

Carbonite 6.5.1 improves compatibility. This is not a security update.
https://account.carbonite.com/

CCleaner 6.33.11465 resolves a couple bugs. This is not a security update.
https://www.ccleaner.com/

DesktopOK 11.63 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.4.2.0 resolves several bugs and improves console support. This is not a security update.
https://dngrep.github.io/

ESEDatabaseView 1.77 improves database reading. This is not a security update.
https://www.nirsoft.net/utils/ese_database_view.html

Fing 3.8.1 resolves several bugs. This is not a security update.
https://www.fing.com/products/fing-desktop-download-windows

GoodSync 12.8.5 resolves several bugs and improves compatibility. This is not a security update.
https://www.goodsync.com/

grepWin 2.1.8 resolves a couple bugs. This is not a security update.
https://github.com/stefankueng/grepWin/releases/latest

GSmartControl 2.0.2 resolves several bugs. This is not a security update.
https://gsmartcontrol.shaduri.dev/

Homedale 2.18 adds Thai language support. This is not a security update.
https://www.the-sz.com/products/homedale/

HWiNFO 8.22 adds support for newer hardware. This is not a security update.
https://www.hwinfo.com/download/

IsMyHdOK 4.21 improves hardware detection and compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

LessMSI 2.7.0 adds several new translations. This is not a security update.
https://lessmsi.activescott.com/

MultiMonitorTool 2.20 adds scaling capabilities. This is not a security update.
https://www.nirsoft.net/utils/multi_monitor_tool.html

NTLite 2025.03.10344 improves component selection and resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

OSForensics 11.1.1003 improves triage, hash sets, and other improvements. This is not a security update.
https://www.osforensics.com/download.html

osquery 5.16.0 resolves a couple bugs and improves python, deb and rpm package support. This is not a security update.
https://osquery.io/downloads

PowerToys 0.89.0 adds transcoding to advanced paste, improves stability and resolves over a dozen bugs. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

PSAppDeploy 4.0.6 resolves dozens of bugs. This is not a security update.
https://psappdeploytoolkit.com/

RoboForm 9.6.5 removes Security Center from installed app and resolves several bugs. This is not a security update.
https://www.roboform.com/

Starwind V2V Converter 9.623 improves compatibility and resolves several bugs. This is not a security update.
https://www.starwindsoftware.com/starwind-v2v-converter

TeamViewer 15.63.5 resolves several bugs and improves logging. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/

Ventoy 1.1.05 improves compatibility and resolves a couple bugs. This is not a security update.
https://www.ventoy.net/en/index.html

WinGet 1.10.340 improves stability. This is not a security update.
https://github.com/microsoft/winget-cli/releases/latest

WinRAR 7.10 resolves over a dozen bugs and improves MOTW propagation. This should be treated as a security update.
https://www.rarlab.com/

WizFile 3.11 improves threading, user interface and resolves several bugs. This is not a security update.
https://antibody-software.com/wizfile/

WizTree 4.25 improves CSV import and export and resolves a 32-bit compatibility bug. This is not a security update.
https://www.diskanalyzer.com/

XnConvert 1.104.0 adds command line file and list options. This is not a security update.
https://www.xnview.com/en/xnconvert/

ZoomText 2025.2502.63.400 adds ARM64 support and live text view. This is not a security update.
https://support.freedomscientific.com/Downloads/ZoomText

Developer Updates

These are unlikely to be of interest to most people.

.NET Runtime 9.0.3 is a security update.
https://dotnet.microsoft.com/en-us/download/dotnet

Android Studio 2024.3.1.13 resolves dozens of bugs. This is not a security update.
https://developer.android.com/studio

GDevelop 5.5.226 updates libraries and resolves several bugs. This is not a security update.
https://gdevelop.io/download

GitHub Desktop 3.4.18 updates libraries and resolves several bugs. This is not a security update.
https://desktop.github.com/

Go 1.24.1 is a security update.
https://go.dev/

Godot 4.4 adds dozens of new features and improvements. This is not a security update.
https://godotengine.org/

Inno Setup 6.4.1 improves autocompletion and tooltips, and resolves several bugs. This is not a security update.
https://www.jrsoftware.org/isdl.php

Microsoft Visual C++ 2022 Redistributable 14.42.34438.0 is a security update.
https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist

Node.js 18.20.7 resolves over a dozen bugs. This is not a security update.
https://nodejs.org/en/

Node.js 23.9.0 updates dependencies and resolves dozens of bugs. This is not a security update.
https://nodejs.org/en/

Rustup 1.28.1 resolves several bugs. This is not a security update.
https://www.rust-lang.org/

SQLite 3.49.1 resolves several bugs. This should be treated as a security update.
https://www.sqlite.org/download.html

Visual Studio Code 1.98.1 resolves several bugs. This is not a security update.
https://code.visualstudio.com/

Web Package Updates

These are likely to be of interest only to web developers.

Adminer 5.0.4 resolves dozens of bugs and improves various language integrations. This is not a security update.
https://www.adminer.org/en/

Grocy 4.4.2 improves Open Food Facts integration and resolves several bugs. This is not a security update.
https://github.com/grocy/grocy

HumHub 1.17.1 improves registration controls and resolves several bugs. This is not a security update.
https://www.humhub.com/en

Joomla 4.4.12 is a security update.
https://www.joomla.org/

Joomla 5.2.5 is a security update.
https://www.joomla.org/

Piwigo 15.4.0 resolves over a dozen bugs. This is not a security update.
https://piwigo.org/

bbPress 2.6.12 is a security update.
https://wordpress.org/extend/plugins/bbpress/

Conditional Widgets 3.3 updates documentation and improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/conditional-widgets/

Contact Form 7 6.0.5 resolves a couple bugs. This is not a security update.
https://wordpress.org/extend/plugins/contact-form-7/

Duplicator 1.5.12 improves compatibility and resolves several bugs. This is not a security update.
https://wordpress.org/plugins/duplicator/#developers

Redirection 5.5.2 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/redirection/

Sucuri Security 1.9.9 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/sucuri-scanner/

WP Cerber Security 9.6.7.3 resolves several bugs and improves performance. This is not a security update.
https://wpcerber.com/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2021-06-08

Welcome back, Folks!

Today is Patch Tuesday for June, 2021. There have been another couple dozen major security incidents, as well as some significant revelations impacting health, security and privacy. The latest Windows 10 release, v21H1, is out and it doesn’t change that much. Google has finally stopped their weekly security update cadence, though other vendors (including Microsoft Edge and Brave) have continued.

This Month in Technology

ABC affiliatesApple AirTagsAXA, Biden’s Venmo accountBrenntagCNA FinancialColonial Pipeline (again), DigitalOcean, European biomolecular research instituteFirst Horizon Bank, U.S. Agency for Global MediaGuard.meHerff Jones, Ireland’s Department of Health (HSE), JBSMonday.com, Microsoft PatchGuardNY MTAOGUsersOne Treasure IslandRapid7Scripps Health and Whistler have been hacked.

A Qualcomm hardware vulnerability affects almost 40% of all mobile phones. Additionally, a dozen security vulnerabilities (called FragAttacks) have been discovered that apply to all Wi-Fi devices. (I’ll bet you miss that cable now, don’t you?)

Google released a “trial” feature to many Chrome users that effectively broke Chrome on their devices. Disabling the trial allowed Chrome to operate again. This is a perfect example of why you should never be forced into being in a beta program. iOS 14.6 is chewing through batteries. Microsoft released an update that broke compatibility with their own Office 365 services – Teams, Outlook and OneDrive. Google’s Nest thermostats are giving people the cold shoulder. Spectre is back again.

The antivirus that can’t protect you from crypto mining malware will now mine crypto on your device so they can use you to generate even more revenue for them. Better hope Norton 360 doesn’t get your home raided.

Amazon, the UK government, BBC, Bloomberg, CNN, The Guardian, NYT, and and many other major sites were taken offline today in a huge outage.

When your paranoid friend says the security app you’re using might be a government trojan, believe them.

Google & Apple are still making it impossible for users to keep their location privateTor is being used to spy on “secure” user traffic. Again. A new privacy-compromising mechanism via cross-browser tracking installed apps can effectively identify your device. The TikTok App is collecting biometric data. The UK Test & Trace app does far worse.

GitHub has disabled FLoC. This is a good thing. Despite federal law, Chinese surveillance equipment is gaining US government customers. Taproot isn’t the privacy panacea it is perceived to be. On the topic of Snowden, he’s been vindicated (again).

Apple shares iCloud keys with CCP, Apple’s Find My can be used to leak secrets, has a “few” issues with notification reliability, and their techs regularly violate their users’ privacy. Due to so many arbitration cases Amazon is now allowing you to sue them…just in time, as they are now sharing your Wi-Fi with passersbyDell lied about their Alienware laptop upgradeability. There’s a reason why so many people treat Microsoft Edge as malicious.

The Epic vs Apple lawsuit testimony is over, but Apple’s AppStore is still allowing malicious and fraudulent apps, while they pat themselves on the back for not taking even more money from their users.

Dr. Fauci lied about sponsoring gain of function research for biological warfare. He dismissed what he knew to be true, the lab-leak theory, and the effectiveness of hydroxychloroquine. He perjured himself. The MSM helped.

Biden shut down the last Wuhan lab investigation. What are the chances there will be a real investigation? Intelligence agencies claim otherwise and you know they have never lied. As is typical of the political elite, instead of broadcasting this everywhere, they’re targeting those that exposed it with death threats.

Governments and the MSM are concealing any true risk/benefit analysis, the miscarriages, Freudian slips, and VAERS spikes behind missing data, bad science, vastly overcounted cases, and propaganda. They’ve been caught red-handed manipulating the data.

The truth is the COVID death numbers are still dropping while post-vaccination infectionand death – are not rare. 5-10% suffer from severe adverse reactions in the hundreds of thousands. The CDC’s new rules acknowledge what many have known all along, vindicating those who opposed masks and vaccines and the vaccines are far from safe or effective.

The worst part is that there are still unsubstantiated and illegal mandates (that are supported by the low-information crowdforever), and insane dogma that violates all reason. Such as yellow stars for the unvaxxed, forbidding the unvaccinated from  church, employmentUniversity (sometimes even the vaccinated) and even West Point. The Red Cross won’t even accept blood from the vaccinated.

The UK government knows what’s coming, and most will be called “unrelated illnesses.” When life insurance companies see this as a non-event and politicians ignore their own agencies to fine the science it’s hard to take it seriously. There have been decades of vaccine research, and we know they’re designing vaccines that spread themselves – isn’t that the premise of most zombie films? mRNA rewrites the genetic code and enhances the illness. This is what it is designed to do. By the way, did you know that during mRNA trials all the mammals kept dying? They proceeded with the emergency use authorization anyway. The only immunity provided by vaccines is to the manufacturer. A second Nuremburg Tribunal is on the horizon.

The Supreme Court says the Computer Fraud and Abuse Act (CFAA) is overbroad. Amazon is being sued over Antitrust law. The Ohio AG is trying to declare Google a public utility.

The government has repeatedly operated in concert with Big Tech to silence dissent, science, and discussion, in effect, laundering their censorship through third-parties. Governors and others are now going on the offense.

Now for the good news:

Dr. Shiva Ayyadurai is doing more to take down Big Tech than anyone else – by himself. Please help.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday this month is huge. The typical computer should see roughly 3.0 GB in updates today. Let’s get started.

Microsoft released updates for Windows, Edge, .NET, Servicing Stack, Internet Explorer, and MSRT (~1.5 GB). This includes security updates. A reboot is required.

Apple released updates for iOS 14.6 and iPadOS 14.6, macOS Big Sur 11.4, Security Update Mojave 2021-004, Security Update Catalina 2021-003, Safari 14.1.1, watchOS 7.5, tvOS 14.6, and Boot Camp 6.1.14. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

iOS 14.6 is a security update. Use Settings, General, Software Update to install the most current update.

iPadOS 14.6 is a security update. Use Settings, General, Software Update to install the most current update.

watchOS 7.5 is a security update. Use your updated iPhone to install the most current version through the Watch app.

tvOS 14.6 is a security update. Use Settings, General, Updates to install the most current version.

Google Chrome OS 91.0.4472.81 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Big Sur (11.x) means that macOS High Sierra (10.13) and older are no longer supported. If you can not install at least macOS Mojave (10.14) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (v21H1) is very large, for the first time it’s actually smaller than the previous release, but it will take a long time to download on slower connections. Windows 10 pushes you to get the latest Windows 10 release every 6 months and only supports any consumer builds for 18 months. If you don’t let it finish and you’re on a slow connection, this process kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Logitech Options for macOS 8.54.147 adds support for newer hardware. This is not a security update.
https://www.logitech.com/en-us/product/options

Nvidia 466.63 adds support for newer hardware, libraries and components, and resolves stability and performance bugs. This is not a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Engine 3.22.0 now defaults to having Moments off, and resolves a crash bog. This is not a security update.
https://steelseries.com/engine

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.25.70 is a security update.
https://brave.com/

Google Chrome 91.0.4472.77 is a security update.
https://www.google.com/chrome/

Microsoft Edge 91.0.864.41 is a security update.
https://www.microsoft.com/en-us/edge/business/download

Firefox 89.0 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 78.11.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 78.11.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 6.3.1 resolves several bugs and adds an adaptive resolution option. This is not a security update.
https://anydesk.com/en/downloads

AnyDesk for macOS 6.2.0 resolves stability and display issues, adds tab, cursor follow, and window focus controls. This is not a security update.
https://anydesk.com/en/downloads

curl 7.77.0 is a security update.
https://curl.haxx.se/windows/

Dropbox 123.4.4832 doesn’t provide a detailed changelog, so should be treated as a security update.
https://www.dropbox.com/

FileZilla Client 3.54.1 resolves several bugs. This is not a security update.
https://filezilla-project.org/

Minds 4.13.0 improves performance and resolves several bugs. This is not a security update.
https://www.minds.com/mobile

Prosody 0.11.9 is a security update.
https://prosody.im/download/start

Technitium DNS Server 6.3 resolves several bugs and adds more than a half dozen new features, including failover and recursion ACLs. This is not a security update.
https://technitium.com/dns/

WGet 1.21.1-1 updates libraries. This is a security update.
https://eternallybored.org/misc/wget/

Zoom 5.6.7.1016 is a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 2.0.15 resolves several bugs. This is not a security update.
https://en.3tene.com/

Picard 2.6.3 resolves several bugs. This is not a security update.
https://picard.musicbrainz.org/

Plex Media Server 1.23.2.4656 resolves several bugs. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

Steam 2021.06.07 resolves several bugs and improves cosmetics. This is not a security update.
https://www.steampowered.com/platform/update_history/index.php?skin=0&id=0

PlayStation PS3 4.88 improves performance. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps3/system-software/

Office Updates

One or more of these are likely to be of interest to most people.

Audacity 3.0.2 resolves several bugs. This is not a security update.
https://www.audacityteam.org/download/

LibreOffice Still 7.0.6 is the final release for the 7.0 branch. This version resolves 50 reliability, stability, and compatibility bugs. This is not a security update.
https://www.libreoffice.org/

Nextcloud Desktop 3.2.2 resolves several bugs and updates libraries. This should be treated as a security update.
https://nextcloud.com/

Adobe Connect 11.2.2 is a security update.
https://helpx.adobe.com/security/products/connect/apsb21-36.html

Adobe Acrobat and Reader 2021.005.20148, 2020.004.30005 and 2017.011.30197 are security updates.
https://helpx.adobe.com/security/products/acrobat/apsb21-37.html

Adobe Photoshop 21.2.9 and 22.4.2 are security updates.
https://helpx.adobe.com/security/products/photoshop/apsb21-38.html

Adobe Experience Manager 6.5.9.0 is a security update.
https://helpx.adobe.com/security/products/experience-manager/apsb21-39.html

Adobe Creative Cloud Desktop Application 2.5 is a security update.
https://helpx.adobe.com/security/products/creative-cloud/apsb21-41.html

Adobe RoboHelp Server 2020.0.1 is a security update.
https://helpx.adobe.com/security/products/robohelp-server/apsb21-44.html

Adobe Photoshop Elements 5.3 is a security update.
https://helpx.adobe.com/security/products/photoshop_elements/apsb21-46.html

Adobe Premiere Elements 5.3 is a security update.
https://helpx.adobe.com/security/products/premiere_elements/apsb21-47.html

Adobe After Effects 18.2.1 is a security update.
https://helpx.adobe.com/security/products/after_effects/apsb21-49.html

Adobe Animate 21.0.7 is a security update.
https://helpx.adobe.com/security/products/animate/apsb21-50.html

Security Software Updates

One or more of these is likely to be of interest to most people.

Tails 4.19 is a security update.
https://tails.boum.org/install/dvd-download/index.en.html

NSudo 8.2 removes ARM32 support, updates libraries, and resolves several bugs. This is not a security update.
https://github.com/M2Team/NSudo/releases/latest

OnionShare 2.3.2 resolves several bugs and updates libraries. This is a security update.
https://onionshare.org/

VT-CLI 0.9.7 doesn’t provide a changelog so should be treated as a security update.
https://github.com/VirusTotal/vt-cli/releases/latest

Capture Updates

These are unlikely to be of interest to most people.

ScreenToGif 2.31 provides cosmetic improvements, improves the updater and imgur compatibility. This is not a security update.
https://github.com/NickeManarin/ScreenToGif/releases/latest

SnagIt 2021.4.1 is a security update.
https://download.techsmith.com/snagit/enu/snagit.exe

Utility Updates

These are unlikely to be of interest to most people.

1Password for Mac 7.8.5 adds archive support, sharing indicators, and resolves several bugs. This is not a security update.
https://1password.com/downloads/mac/

1Password for Windows 7.7.807 resolves several bugs, adds Windows Hello support, and adds archive support. This is not a security update.
https://1password.com/downloads/windows/

Bitcoin 0.21.1 improves performance and resolves several bugs. This is not a security update.
https://bitcoin.org/en/download

Bitwarden 1.26.5 resolves several bugs. This is not a security update.
https://bitwarden.com/

CCleaner 5.81.8895 resolves several bugs. This is not a security update.
https://www.ccleaner.com/

Dell Command Update 4.2 improves download and logging. This is not a security update.
https://www.dell.com/support/article/us/en/04/sln311129/dell-command-update?lang=en

DesktopOK 8.88 improves compatibility and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

Everything 1.4.1.1009 improves NTFS detection. This is not a security update.
https://www.voidtools.com/

Fido 1.19 adds support for Windows 10 21H1 and eliminate requirement for Internet Explorer. This is not a security update.
https://github.com/pbatard/Fido/releases

GoodSync 11.7.3 resolves several bugs and improves stability. This is not a security update.
https://www.goodsync.com/

IsMyHdOK 3.21 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

NetworkTrafficView 2.40 adds several protocol controls and filters. This is not a security update.
https://www.nirsoft.net/utils/network_traffic_view.html

NTLite 2.1.1.7917 improves compatibility and resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

Aomei Partition Assistant 9.2.1 improves selection interface, resolves several bugs with third-party apps and integrated elevation when required. This is not a security update.
https://www.diskpart.com/

PointerStick 5.15 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

Process Monitor 3.82 resolves several bugs. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/procmon

Process Explorer 16.42 switches default search behavior from find to filter and reports CET, and resolves several bugs. This is a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/process-explorer

PsExec 2.34 changes stderr output behavior. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/psexec

RoboForm 9.1.4 resolves several bugs. This is not a security update.
https://www.roboform.com/

Samsung Data Migration 4.0 does not provide a changelog so should be treated as a security update.
https://www.samsung.com/semiconductor/minisite/ssd/download/tools/

Sigcheck 2.81 resolves a signature validation bug. This should be treated as a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/sigcheck

SimpleWMIView 1.45 improves sorting controls. This is not a security update.
https://www.nirsoft.net/utils/simple_wmi_view.html

Sysmon 13.21 adds new filter conditions and resolves a crash bug. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon

TaskSchedulerView 1.68 resolves a pagination bug and improves sorting controls. This is not a security update.
https://www.nirsoft.net/utils/task_scheduler_view.html

TCPView 4.12 adds new filter conditions and resolves several bugs. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/tcpview

TraceRouteOK 2.52 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/TraceRouteOK

WifiInfoView 2.70 improves sorting options. This is not a security update.
https://www.nirsoft.net/utils/wifi_information_view.html

WinGet 1.0.11451 is the first release version of WinGet. This is not a security update.
https://github.com/microsoft/winget-cli/releases/latest

WinObj 3.10 extends search to include symbolic link targets.
https://docs.microsoft.com/en-us/sysinternals/downloads/winobj

WinScan2PDF 7.11 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 4.2.1.0 resolves several bugs. This is not a security update.
https://developer.android.com/studio

DB Browser for SQLite 3.12.2 updates the certificate for DBHub.io. This is not a security update.
https://sqlitebrowser.org/

Godot 3.3.2 resolves dozens of bugs. This is not a security update.
https://godotengine.org/

Inno Setup 6.2.0 updates graphics and cosmetics, adds dark mode, improves logging, and adds several new scripting options and flags. This is not a security update.
https://www.jrsoftware.org/isdl.php

Node.js 16.3.0 upgrades libraries and resolves several bugs. This is not a security update.
https://nodejs.org/en/

SQLite 3.35.5 resolves several bugs and improves reliability and performance. This is a security update.
https://www.sqlite.org/download.html

Web Package Updates

These are likely to be of interest only to web developers.

Adminer 4.8.1 resolves several bugs. This is a security update.
https://www.adminer.org/en/

Dada Mail 11.14.0 resolves several bugs. This is not a security update.
http://dadamailproject.com/

Drupal 9.1.10 resolves over a dozen bugs. This is not a security update.
https://drupal.org/download

Joomla 3.9.27 is a security update.
https://www.joomla.org/

Nextcloud Server 21.0.2 updates libraries and resolves dozens of bugs. This is not a security update.
https://nextcloud.com/

phpList 3.6.3 is a security update.
https://www.phplist.org/

Piwigo 11.5.0 is a security update.
https://piwigo.org/

ScreenConnect 21.8.3558.7823 adds deep-linking support, and resolves several bugs. This is not a security update.
https://www.connectwise.com/software/control/download

WordPress 5.7.2 is a security update.
https://wordpress.org/

BuddyPress 8.0.0 improves the registration experience, xProfile fields, simplifies administration, and resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/buddypress/

Duplicator 1.4.1 resolves several bugs. This is a security update.
https://wordpress.org/plugins/duplicator/#developers

Visual Composer 36.0 resolves dozens of bugs and improves consistency. This is not a security update.
https://visualcomposer.com/

W3 Total Cache 2.1.3 is a security update.
https://wordpress.org/extend/plugins/w3-total-cache/

WooCommerce 5.4.0 resolves dozens of bugs. This is not a security update.
https://wordpress.org/extend/plugins/woocommerce/

Show IDs 1.1.7 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/wpsite-show-ids/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2021-03-09

Welcome back, Folks!

Today is Patch Tuesday for March, 2021.

This Month in Technology

Gab has been hacked at least a couple more times. (Would you trust the security of a Gab-owned bank?)

A new form of “supply-chain” attack demonstrating dependency vulnerabilities has been used against many major vendors, including Microsoft, Apple, Tesla, and dozens more.

32redAccellionAllergy PartnersAppleBombardierCA DMVClubhouse ChatsCovenant HealthCareCSXD-Link devices, Ecuador’s Ministry of Finance and Banco Pichincha, the European Banking AuthorityEXMOExperian (again), France’s Ministry of HealthGeorgetown County (SC), Hipcam (and other baby monitors), HumanaIBM, over a hundred Italian banksKeepChangeKiaKrogerLakehead UniversityMalaysia AirlinesNess Digital EngineeringNinja FormsNgrokNurseryCam, Oxford University, RealPage, RIPE NCC accountsRockwell Automation PLCsMaza, a Russian Cybercrime forum, SingtelSITA (an airline service provider), SolarCityPayPalQualysSendgrid accounts (to send spam – how could anyone tell the difference?!), Sequoia CapitalSignalT-Mobile, TMS, 15 UK schoolsUnderwriters LaboratoriesUniversal Health ServicesVMWare vCenter ServerWashington State Unemployment DepartmentWawa, Apple’s WebKit, and Yandex have been hacked.

According to a study by Bridewell Consulting, 86% of UK critical national infrastructure organizations have experienced cyber-attacks. I think it would be more accurate to present these numbers as, “14% of UKs critical national infrastructure doesn’t have the technology in place to know they were hacked.”

Even more malware related to the SolarWinds hack has been discovered. Since AWS was used for the SolarWinds hack, shouldn’t Amazon shut AWS down, too?

Microsoft is now admitting that Azure and Exchange source code has been compromised by the SolarWinds attackers.

The big news this month is that a vulnerability in Microsoft Exchange (coincidence?) has resulted in over thirty thousand servers being hackedThis is huge. So what did Microsoft do? Microsoft has announced it has changed their policy to crack down on hosted email accounts that receive a lot of email. Sigh.

Another interesting new tactic, bitsquatting, has proved far more effective than one would think. The demonstration allowed them to hijack thousands of requests intended for Microsoft. Used maliciously, this method will cause serious damage.

Censorship has finally made it before the Supreme Court, but Dr. Suess is only the latest target, while Facebook allowed actual genocide, but forbade discussion about news articles, Google acknowledges their efforts to perform censorship “better,” and Firefox has released a new extension to aid in censorship, while Streamlabs waited for the payment to clear before censoring one paid user. The Beverly Hills Police Department is using the novel approach of playing copyrighted music to prevent their actions from being observed, and Congress is now violating federal law by demanding censorship of media.

It amazes me that people actually trust “fact checkers.” Censorship doesn’t work!

Poland isn’t taking it anymore. Italy is fining Facebook, too.

Tor was hacked years ago, but new implementations (like that in Brave) are still popping up with their own problems.

Another 21 million VPN users were taught the lesson about the difference between customers and products. If you’re not the customer, you’re the product.

Instagram (like parent Facebook) is sharing everything you do with law enforcement. So is Apple’s iCloud.

The Windows 10 implementation of web fonts can be used to hack you. Apple M1 chips (less than 6 months old) have been targeted with several pieces of malware, but we should trust the MORPHEUS chip, right? BTW, M1 Macs are eating their (soldered in) SSDs, too.

It’s not just Google. Apple can disable all of your accounts and services on a whim, too. Or for your name.

Amazon has been caught duplicating products, can they be trusted to sell your products or host your content?

Is half a billion dollars enough to get you to rethink a bad user interface?

The whole point of unified interfaces and consistent logins is to ensure a familiar experience so you know whether you’re visiting the real site. Attackers take advantage of this to build their own imagekits and forms, even using their own fake security measures to convince you you’re on the “real” site since they are forced to validate that *you* are really you.

The malicious Gootkit Trojan can help the SEO of your websites. Just not for you.

Never reuse passwords. Or hard-code them. And don’t use obvious passwords either. But if you do, don’t blame a fabricated intern.

Apple claims that a new (available since 2019, but only recently launched on iOS) application execution technique will make it more difficult for iPhones to be hacked,
while yet another iPhone bug has demonstrated to successfully jailbreak every active iOS/iPhone line.

North Dakota and Arizona may save the Internet by forbidding the ability for vendors to force the use of their own app stores.

While many treat Google’s lockdown of their data APIs in Chromium as a bad thing, I see it as getting Google further out of Chromium – which can only be a net positive.

AT&T and Frontier have consistently abandoned phone networks in California, but we knew that: AT&T said they were going to do this when Title II passed. Sometimes the only thing to make a company following through is enough bad press.

Deepfakes for everyone! While most focus on Deepfakes are about their potential for evil, they can be used for good.

On patents: Intel owes $2.2 billion for saving power, and Apple has violated several biometric patents.

Dr. Fauci has known all along that the PCR test was useless. The WHO has launched their own COVID-specific version of “we investigated ourselves and found we did nothing wrong.” The dystopian concept of vaccine passports has been struck down by the Council of Europe. Unfortunately their power is mostly cosmetic.

The CDC inflated “COVID deaths” over 1600% in violation of multiple federal laws. CDS is real though. COVID has been “really good for CNN ratings,” though. Thousands of people have died in the US from the experimental COVID “vaccines,” (and elsewhere) or suffered from other harm. Many more internationally. Quarantine internment camps are a real thing. People are being harmed from the tests (or forcefully vaccinated), too. You can do something about it. (They sure won’t.) BTW, the CDC has had to remove their claim that vaccines don’t cause Autism.

Pennsylvania, New Mexico, and Texas have joined in on efforts to end lockdown insanity.

Don’t be selfishMasks still don’t work, but masks can kill you. (At least they won’t rape you.)

Keep the pedophile, but ban the words.

Green Energy killed Texas. It shouldn’t have been allowed to happen.

Governors Cuomo and Whitmer are finally being taken to task on their “accidental” murder of thousands of nursing home residents. Don’t expect the President to get involved. Genocide is just “different norms” to him. Instead of those in “National Security” investigating this, they’re convinced their time is better used calling half the population terrorists.

Facebook has had more than 20 million child sex abuse incidents, more than 20x greater than any other website, including Google. Nevertheless, the masses aren’t calling for cancelling Facebook. It’s tolerance when “they” do it.

Speaker Pelosi (who is responsible for security at the House) refused National Guard assistance, supposedly over “optics“, before the staged January 6riot“. Chris Wray lied to Congress about Antifa dressing as Trump supporters. So did former Deputy Attorney General Rod Rosenstein. They’ve knowingly falsified FISA warrants. So is it really any surprise there are calls to shut down the FBI?

Some states are finally allowing election audits, with evidence of 6% discrepancies in every single race, others as much as 78%, and other serious math problems, while others refuse to release ballots for inspection, purge election data, or allow the FBI to shred ballots without oversight or inspection. Then they poison the people they are forcing to guard them.

Is it any surprise that their Section 230 “reforms” are designed to completely silence online discourse? After all, the President doesn’t understand what “clandestine” means. (Quick tip: If you announce your intentions on the MSM, it’s not clandestine!)

The Babylon Bee is probably the best news site on the Internet, not because they actually have any news, but because they shine a light on the fraud that passes for news today.

Now for the good news:

California has finally been allowed to implement their own brand of Net Neutrality. I strongly oppose Net Neutrality, as getting government involved in something (even under the auspices of protection) always results in unintended consequences. This is, fortunately, no exception. CA Net Neutrality can now be used by myself and others to target Big Tech to penalize them for their continuous acts of censorship.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday this month is huge. The typical computer should see roughly 3 GB in updates today. Let’s get started.

Microsoft released updates for Windows, Edge, .NET, Servicing Stack, Internet Explorer, and MSRT (~2 GB). This includes security updates. A reboot is required.

Apple released updates for macOS Big Sur 11.2.3, watchOS 7.3.2, Safari 14.0.3, iOS 14.4.1 and iPadOS 14.4.1. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

iOS 14.4.1 is a security update. Use Settings, General, Software Update to install the most current update.

iPadOS 14.4.1 is a security update. Use Settings, General, Software Update to install the most current update.

watchOS 7.3.2 is a security update. Use the Watch app on your iPhone to install the most current version.

Google Chrome OS 88.0.4324.186 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Big Sur (11.0) means that macOS High Sierra (10.13) and older are no longer supported. If you can not install at least macOS Mojave (10.14) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (v2009) is huge (about 18% larger than v2004, which was 25% larger than any prior build) so will take a long time to download on slower connections. Windows 10 pushes you to get the latest Windows 10 release every 6 months and only supports any consumer builds for 18 months. If you don’t let it finish and you’re on a slow connection, this process kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

BullZip PDF Printer 12.2.0.2902 resolves several bugs. This is not a security update.
https://www.bullzip.com/products/pdf/info.php#download

Display Driver Uninstaller 18.0.3.7 improves cleanup and adds network path support. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

DirectX 9.29.1974.1 doesn’t provide a changelog, so should be treated as a security update.

nVidia 461.72 adds support for newer hardware and resolves several bugs. This is not a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.21.74 resolved several bugs. This is a security update.
https://brave.com/

Google Chrome 89.0.4389.82 is a security update.
https://www.google.com/chrome/

Microsoft Edge 89.0.774.48 is a security update.
https://www.microsoft.com/en-us/edge/business/download

Firefox 86.0 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 78.8.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Vivaldi 3.6.2165.40 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 78.8.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

Mumble 1.2.19 is a security update.
http://wiki.mumble.info/wiki/Main_Page

Prosody 0.11.8 is a security update.
https://prosody.im/download/start

Trillian 6.4.0.5 resolves a settings bug. This is not a security update.
https://www.trillian.im/

Dropbox 117.4.378 does not provide a changelog so should be treated like a security update.
https://www.dropbox.com/

FreeFileSync 11.8 resolves several bugs. This is not a security update.
https://www.freefilesync.org/download.php

Zoom 5.5.13142.0301 resolves several bugs, improves grid view, and better indicates when content is being shared. This is a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 2.0.12 adds 3 new types of motion, show/hide shortcut, and resolves several bugs. This is not a security update.
https://en.3tene.com/

Flickr Downloadr 3.3.4.1 updates the Docker image. This is not a security update.
https://flickrdownloadr.com/downloads/

Office Updates

One or more of these are likely to be of interest to most people.

Atom 1.55.0 allows git configuration without a repository. This is not a security update.
https://atom.io/

IcoFX 3.5.1 resolves several bugs. This is not a security update.
https://icofx.ro/

LibreOffice Fresh 7.1.1 resolves almost a hundred bugs. Remember that this is beta software, so should be avoided for the stable version whenever possible. This should be treated as a security update.
https://www.libreoffice.org/

Nextcloud Desktop 3.1.3 is a security update.
https://nextcloud.com/

Notepad++ 7.9.3 adds new folder features that now prevent it working on Windows XP. If you are still running XP you should really consider switching to Linux, but if you must continue to use XP then use Notepad++ 7.9.2. This is not a security update.
https://12pd.com/click?npp32

VideoCleaner 5.8 improves Matrix, Sharpening and Mask features. This is not a security update.
https://videocleaner.com/download.html

Adobe Connect 11.2 is a security update.
https://helpx.adobe.com/security/products/connect/apsb21-19.html

Adobe Creative Cloud Desktop Application 5.4 is a security update.
https://helpx.adobe.com/security/products/creative-cloud/apsb21-18.html

Adobe Framemaker 2020.0.2 is a security update.
https://helpx.adobe.com/security/products/framemaker/apsb21-14.html

Security Software Updates

One or more of these is likely to be of interest to most people.

Tails 4.16 is a security update.
https://tails.boum.org/install/dvd-download/index.en.html

OpenSSL 1.1.1j is a security update.
https://www.openssl.org/source/

RogueKiller 14.8.5 updates core and resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

Wireless Network Watcher 2.25 improved compatibility with high-DPI. This is not a security update.
https://www.nirsoft.net/utils/wireless_network_watcher.html

Capture Updates

These are unlikely to be of interest to most people.

VideoCacheView 3.06 adds support for the new cache partitioning structure in chromium-based browsers. This is not a security update.
https://www.nirsoft.net/utils/video_cache_view.html

Converter Updates

These are unlikely to be of interest to most people.

MakeMKV 1.16.1 resolves several bugs and adds ARM support. This is not a security update.
https://12pd.com/click?makemkv

Utility Updates

These are unlikely to be of interest to most people.

1Password for Mac 7.8 adds native M1 support and resolves dozens of bugs. This is a security update.
https://1password.com/downloads/mac/

1Password for Windows 7.6.793 improves performance and resolves several bugs. This is not a security update.
https://1password.com/downloads/windows/

CCleaner 5.77.8521 improves cleaning and resolves several bugs. This is a security update.
https://www.ccleaner.com/

ControlMyMonitor 1.28 improves compatibility with high DPI. This is not a security update.
https://www.nirsoft.net/utils/control_my_monitor.html

Coreinfo 3.52 adds reporting for CET (shadow stack). This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/coreinfo

Cygwin 3.1.7 resolves several bugs. This is not a security update.
https://cygwin.com/

Dell Command Update 4.1 is a security update.
https://www.dell.com/support/article/us/en/04/sln311129/dell-command-update?lang=en

DesktopOK 8.66 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

Eraser 6.2.0.2992 doesn’t provide a changelog so should be treated as a security update.
https://eraser.heidi.ie/download/

Everything Toolbar 0.6.2 adds an installer, drag & drop support, elevation support, and more. This is not a security update.
https://github.com/stnkl/EverythingToolbar/

Homedale 1.93 adds an option to set the gps baud rate from the command line. This is not a security update.
https://www.the-sz.com/products/homedale/

IsMyHdOK 3.01 resolves a bug in screenshot generation. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

NTLite 2.0.0.7820 resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

OSFMount 3.1.1000 updates drivers and improves CLI support. This is not a security update.
https://www.osforensics.com/tools/mount-disk-images.html

PointerStick 5.05 updates language files. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

QuickSetDNS 1.31 adds option to start hidden. This is not a security update.
https://www.nirsoft.net/utils/quick_set_dns.html

TeamViewer 15.15.5 was released. The TeamViewer release notes have been unavailable for months now, so while it might be a security update, it would be safer to remove TeamViewer until these issues are resolved.
https://www.teamviewer.com/en/download/windows/

TraceRouteOK 2.42 updates language files. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/TraceRouteOK

WinScan2PDF 6.91 adds support for multi-page TIF and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WizTree 3.37 improves compatibility, refresh behavior, and resolves several bugs. This is not a security update.
https://wiztreefree.com/

Developer Updates

These are unlikely to be of interest to most people.

AutoHotkey 1.1.33.05 resolves several bugs and improves compatibility. This is not a security update.
https://www.autohotkey.com/download/

Node.js 12.21.0 is a security update.
https://nodejs.org/en/

Node.js 14.16.0 is a security update.
https://nodejs.org/en/

Node.js 15.11.0 resolves dozens of bugs. This is a security update.
https://nodejs.org/en/

TortoiseSVN 1.14.1 resolves several bugs. This is not a security update.
https://tortoisesvn.net/downloads.html

Visual Studio Code 1.54 resolves an extension dependency bug. This is not a security update.
https://code.visualstudio.com/

Virtual Machine Updates

These are unlikely to be of interest to most people.

PPSSPP 1.11.3 resolves several bugs. This is not a security update.
https://ppsspp.org/downloads.html

Web Package Updates

These are likely to be of interest only to web developers.

Adminer 4.8.0 adds several new features and improves compatibility. This is not a security update.
https://www.adminer.org/en/

Docker Desktop 3.2.1 updates the Docker Engine. This is not a security update.
https://www.docker.com/products/docker-desktop

Drupal 9.1.5 resolves dozens of bugs. This is not a security update.
https://drupal.org/download

HumHub 1.8.0 adds a bunch of new features, improves permissions, brute force delays, style and administration improvements, and resolves several bugs. This is not a security update.
https://www.humhub.com/en/download

Joomla 3.9.25 is a security update.
https://www.joomla.org/

MailEnable 10.32 resolves several bugs and adds LDAP support. This is not a security update.
https://www.mailenable.com/

Nextcloud Server 21.0.0 improves performance (up to 10x!), collaboration, groupware and more. This is not a security update.
https://nextcloud.com/

OpenPetra 2021.02 adds several new features, improvements, and resolves bugs. This is not a security update.
https://www.openpetra.org/

phpList 3.6.1 improves short URLs, PHP8 support, and security improvements. This is a security update.
https://www.phplist.org/

phpMyAdmin 5.1.0 resolves several bugs, improves compatibility, and adds several new options. This is not a security update.
https://www.phpmyadmin.net/

ScreenConnect 21.3.2160.7699 resolves several bugs, renamed End to Delete, and improves compatibility. This is not a security update.
https://www.connectwise.com/software/control/download

YOURLS 1.8.1 improves IDN, UTF8, time zone, and PHP8 support, removes support for PHP 7.2, and resolves several bugs. This is not a security update.
https://yourls.org/

WordPress 5.7 resolves several bugs and adds a few new features, improving accessibility, and (finally) adding a feature to update HTTP to HTTPS links throughout your site when you switch to HTTPS. This is not a security update.
https://wordpress.org/

Akismet 4.1.9 improves handling of pingbacks in XML-RPC calls. This is not a security update.

BuddyPress 7.2.0 resolves several bugs. This is not a security update.

Conditional Widgets 3 improves translation support. This is not a security update.

Contact Form 7 5.4 adds Sendinblue support, updates libraries and improves reliability and compatibility. This is not a security update.

Social Post Feed 2.19 improves error handling and reporting, cleanup, resolves several bugs and updates libraries. This is not a security update.

myStickymenu 2.5.1 improves instructions and compatibility. This is not a security update.

Postie 1.9.55 improves compatibility and removes legacy image sizing feature. This is not a security update.

Really Simple CAPTCHA 2.1 improves hash comparison. This is not a security update.

W3 Total Cache 2.1.1 resolves several bugs and adds information links and ogg caching support. This is not a security update.

WooCommerce 5.1.0 is a major update. This version improves compatibility, localization, and resolves dozens of bugs. This is not a security update.

WordPress Zero Spam 5.0.9 resolves several bugs and improves spam detection. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2021-02-09

Welcome back, Folks!

Today is Patch Tuesday for February, 2021.

This Month in Technology

Malware planted during the SolarWinds hack is still being discovered and SolarWinds is still vulnerable.

ADT (not just employee abuse), Amazon Kindle e-readersAzure Functions, the Australian Securities and Investments CommissionCisco DNA CenterCyberpunk 2077Excellus Health Plan, Inc., ExperianFiberHome routers, Forward AirGolang, various Home Assistant integrationsiOSlibgcrypt, Linux (and macOS) SUDOMalwarebytesMeetMindfulMimecast (also a SolarWinds victim), Nespresso smart cards, New Zealand Central BankNoxPlayerOffice 365OpenWRT forumPalo Alto Networks, the PentagonPerl[.]comPfizerSonicWallStormshieldUK Research and Innovationthe UNUScellularUSDA (again), Vermont Dept of LaborVIPGamesWashington State Auditor’s OfficeWestRock Co., WhatsApp, and Wind River Systems have been hacked.

The EU is fining (victims) of data breaches 39% more than two years ago. Grindr is exposing your information. SpamCop made a boo-boo by not renewing their domain on time, resulting in a huge amount of legitimate messages being treated as spam. The LogoKit phishing platform has been updated to “improve” effectiveness.

The UK Government is giving malware-infected laptops to students and the US federal government has repeatedly supported violation of the third and fourth amendments to plant recording devices on private property. There has been an increase of 93% of leaks and data breaches in 2020.

Whether you pay the ransom or restore from backups: PATCH the vulnerabilities!

I have always called for avoiding pirated software because it poses a unique security risk. Here’s an example. (avoid travelling by train in China)

Federally funded censorship and double-standards are being used to advance cancel culture in bankscoffeejournalism, patriotism, by mere association, while actually inciting violence with absurd rhetoric such as calling a kindly neighbor a terrorist for plowing your snow are being excused as acceptable. While censorship isn’t left or right only one side is willing to ban those most likely to join the military from joining.

Worse yet, they’re even targeting third-parties for cancellation for daring to support free speech. Heck, even Mike Rowe is being cancelled.

Some are actually upset that not enough censorship is taking place while ignoring actual calls for violence, funding terroristsopenly supporting child porn, hypocritically calling censorship a violation of election integrity, and arresting people for posting memes.

No matter how much the narrative is disproven – this was planned by others well in advance, and the capitol police were directly involved, which is probably why they refused assistance from the National Guard and DoD when offered multiple times. There’s plenty more.

At least there’s finally some pushback. Hopefully it’s not too little, too late.

Meanwhile, TIME acknowledges that they did, in fact, collude with big tech, large corporations and foreign governments in violation of state and federal laws in order to steal the election. (But don’t talk about it online!) By the way, is it just a coincidence that so many opponents of free speech are pedophiles?

Facebook will pay $300/ea to Illinois users for violating state biometric laws and yet, they have still violated Polish law and blocked & banned small investors while Zuckerberg bragged about how he censored Trump to prevent a free election. WhatsApp users are leaving in droves, while WhatsApp has shifted messaging to explain that user messages (notably not their “data”) can still be removed.

There’s been a surge in BSODs for some Windows devices after January updates. Microsoft has been beaten to the patch (again) by 0patch for a vulnerability in their installer system.

Google is above the law or at least, demands the ability to be excluded from it. They’ve also banned one app for supporting a popular open source file type and another for allowing access to content it doesn’t control (like Google’s own browsers), and violated their own terms to purge negative reviews in their App Store. YouTube is removing Senate testimony. It should come as no surprise then, that developers are realizing that “doing business with [Google] is a liability.” Do you really need more justification to de-Google?

Mozilla fixed a browser bug that could trigger physical damage to your SSD.

Amazon has been caught colludingendangering privacyhypocritically inciting violence, and stealing, all while pursuing the ability to run the Pentagon Defense Systems (in violation of their own Terms of Service).

Apple is throttling iPhones again, preventing sideloading on M1’s, and took five years to discover a widespread crypto miner in macOS.

Still trust your mobile security? Your operating systems have intentionally designed vulnerabilities/weaknesses.

Especially when it comes to science, sunlight remains the best disinfectant. It turns out “global warming” is worse when humans aren’t polluting the air. But sadly, facts don’t matter anymore, so months have passed and hundreds of thousands of lives were lost before political and social science caught up with actual science to acknowledge HCQ is, in fact, an effective treatment. And surely it’s just a coincidence that testing processes were changed immediately after inauguration?

Investigating and/or punishing people for refusing an experimental treatment (according to the FDA they’re not vaccines) is a violation of the Nuremberg Code, but that won’t prevent governments and corporations from doing it anyway, no matter how many times that is struck down as unconstitutional.

The CDC has illegally inflated COVID statistics, but is suppressing VAERS information about people dying like flies after injections.

Really though, can you trust any medical treatment created by people that struggle with math?

Now for the good news:

The Biden administration has dropped the federal lawsuit against the California Net Neutrality law. This will eventually be what breaks the Big Tech monopoly.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday this month is huge. The typical computer should see roughly 3 GB in updates today. Let’s get started.

Microsoft released updates for Windows, Edge, .NET, Servicing Stack, and MSRT (~ 2 GB). This includes security updates. A reboot is required.

Apple released updates for macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iCloud for Windows 12.0 (off and on again), iOS 14.4, iPadOS 14.4, Safari 14.0.3, tvOS 14.4, watchOS 7.3, and Xcode 12.4. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

iOS 14.4 is a security update. Use Settings, General, Software Update to install the most current update.

iPadOS 14.4 is a security update. Use Settings, General, Software Update to install the most current update.

watchOS 7.3 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 14.4 is a security update. Use System, Software Update to install the most current version.

Google Chrome OS 88.0.4324.109 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Big Sur (11.0) means that macOS High Sierra (10.13) and older are no longer supported. If you can not install at least macOS Mojave (10.14) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (v2009) is huge (about 18% larger than v2004, which was 25% larger than any prior build) so will take a long time to download on slower connections. Windows 10 pushes you to get the latest Windows 10 release every 6 months and only supports any consumer builds for 18 months. If you don’t let it finish and you’re on a slow connection, this process kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Display Driver Uninstaller 18.0.3.6 improves cleanup. This is a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

nVidia 461.40 resolves a dozen bugs. This is not a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.19.92 is a security update. Use Menu, Help, About to install the most current version.
https://brave.com/

Google Chrome 88.0.4324.150 is a security update. Use Menu, Help, About to install the most current version.
https://www.google.com/chrome/

Microsoft Edge 88.0.705.63 is a security update. Use Menu, Help, About to install the most current version.
https://www.microsoft.com/en-us/edge/business/download

Firefox 85.0.2 is a security update. Use Menu, Help, About to install the most current version.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 78.7.1 is a security update. Use Menu, Help, About to install the most current version.
https://www.mozilla.org/en-US/firefox/organizations/all/

SeaMonkey 2.53.6 is a security update. Use Menu, Help, About to install the most current version.
https://www.seamonkey-project.org/

Vivaldi 3.6.2165.36 is a security update. Use Menu, Help, About to install the most current version.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Mailspring 1.8.0 adds account colors, and resolves several bugs. This is not a security update.
https://getmailspring.com/

Thunderbird 78.7.1 is a security update. Use Menu, Help, About to install the most current version.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

BrowsingHistoryView 2.46 adds support for Brave. This is not a security update.
https://www.nirsoft.net/utils/browsing_history_view.html

curl 7.75.0 resolves dozens of bugs and adds several new features. This is not a security update.
https://curl.haxx.se/windows/

Dropbox 115.4.601 doesn’t provide a detailed changelog so should be treated as a security update.
https://www.dropbox.com/

FileZilla Client 3.52.2 resolves several bugs. This is not a security update.
https://filezilla-project.org/

Pocketnet-Core 0.18.18 resolves several bugs. This is not a security update.
https://pocketnet.app/

WinSCP 5.17.10 is a security update.
https://winscp.net/eng/index.php

Zoom 5.5.12494.0204 resolves a couple minor bugs. This is not a security update.
https://zoom.us/

Java 8u281 is a security update.
https://www.java.com/en/download/manual.jsp

Media Updates

These are unlikely to be of interest to most people.

3tene 2.0.10 resolves several bugs. This is not a security update.
https://en.3tene.com/

darktable 3.4.1 resolves about 20 bugs. This is not a security update.
https://www.darktable.org/install/

VLC Media Player 3.0.12 is a security update.
https://www.videolan.org/vlc/

Game Updates

These are unlikely to be of interest to most people.

Steam 2021.02.05 resolves several bugs, improves compatibility, and improves cosmetics. This is not a security update.

PlayStation PS5 20.02-02.50.00 resolves a PS4 installation compatibility issue, improves editing video clips and improves performance. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Office Updates

One or more of these are likely to be of interest to most people.

Atom 1.54.0 updates libraries and resolves several bugs. This is not a security update.
https://atom.io/

Blender 2.91.2 doesn’t have a detailed changelog so should be treated as a security update.
https://www.blender.org/download/

IcoFX 3.5 resolves several bugs. This is not a security update.
https://icofx.ro/

Krita 4.4.2 adds mesh gradients, mesh transform, gradient editor and halftone filter, new brushes, and resolves dozens of bugs. This is not a security update.
https://krita.org/en/download/krita-desktop/

LibreOffice Fresh 7.1.0 resolves hundreds of bugs and improves reliability, stability, and compatibility. This is not a security update. This is beta software and should be avoided by most users.
https://www.libreoffice.org/

Lightworks NLE 2021.1 adds dozens of new features and improvements, and resolves many bugs. This is not a security update.
https://www.lwks.com/

Nextcloud Desktop 3.1.2 adds several new features: SVG client branding, push notifications for file changes, conflict resolution trigger and more. This is not a security update.
https://nextcloud.com/

OpenOffice 4.1.9 improves stability and compatibility. This is not a security update.
https://www.openoffice.org/download/

Paint.net 4.2.15 resolves several bugs. This is not a security update.
https://www.getpaint.net/

FrameMaker 2019 Update 8 64bit (2019.0.8) doesn’t provide a changelog, so should be treated as a security update.
64-bit: https://supportdownloads.adobe.com/detail.jsp?ftpID=7063
32-bit: https://supportdownloads.adobe.com/detail.jsp?ftpID=7065

Adobe Acrobat and Reader 2021.001.20135, 2020.001.30020, and 2017.011.30190 are security updates.
https://helpx.adobe.com/security/products/acrobat/apsb21-09.html

Adobe Animate 21.0.3 is a security update.
https://helpx.adobe.com/security/products/animate/apsb21-11.html

Adobe Dreamweaver 20.2.1 and 21.1 are security updates.
https://helpx.adobe.com/security/products/dreamweaver/apsb21-13.html

Adobe Illustrator 25.2 is a security update.
https://helpx.adobe.com/security/products/illustrator/apsb21-12.html

Adobe Photoshop 21.2.5 and 22.2 are security updates.
https://helpx.adobe.com/security/products/photoshop/apsb21-10.html

Magento 2.4.2, 2.4.1-p1, and 2.3.6-p1 are security updates.
https://helpx.adobe.com/security/products/magento/apsb21-08.html

Security Software Updates

One or more of these is likely to be of interest to most people.

Tails 4.15.1 is a security update.
https://tails.boum.org/install/dvd-download/index.en.html

RogueKiller 14.8.4 resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

uBlock Origin 1.33.2 resolves several bugs. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

VT-CLI 0.9.0 resolves a bug with URL parsing. This is not a security update.
https://github.com/VirusTotal/vt-cli/releases/latest

Capture Updates

These are unlikely to be of interest to most people.

SnagIt 2021.2.0 resolves several bugs. This is not a security update.
https://12pd.com/click?snagit

Utility Updates

These are unlikely to be of interest to most people.

1Password for Windows 7.6.791 resolves several bugs. This is not a security update.
https://1password.com/downloads/windows/

Bitcoin 0.21.0 resolves over a dozen bugs and improves networking. This is not a security update.
https://bitcoin.org/en/download

Bitwarden 1.24.6 improves biometrics, search, and usability. This is not a security update.
https://bitwarden.com/

Carbonite 6.3.8 resolves a bug with NAS backups. This is not a security update.
https://account.carbonite.com/

CCleaner 5.76.8269 improves cleaning and accessibility, and resolves several bugs. This is not a security update.
https://www.ccleaner.com/

CPU-Z 1.95 adds support for newer hardware. This is not a security update.
https://www.cpuid.com/softwares/cpu-z.html

DesktopOK 8.44 improves toolset. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

DriveImage XML 2.60 doesn’t provide a changelog so should be treated as a security update.
https://www.runtime.org/driveimage-xml.htm

Etcher 1.5.116 updates libraries and improves cleanup of temp files. This is not a security update.
https://www.balena.io/etcher/

Everything 1.4.1.1005 is a security update.
https://www.voidtools.com/

Fido 1.18 adds support for the latest 20H2 refresh. This is not a security update.
https://github.com/pbatard/Fido/releases

GoodSync 11.5.6 improves stability, reliability and sync, and resolves several bugs. This is not a security update.
https://12pd.com/click?goodsync

Homedale 1.92 resolves several bugs. This is not a security update.
https://www.the-sz.com/products/homedale/

IsMyHdOK 2.81 adds automatic update and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

LessMSI 1.8.1 resolves a display bug. This is not a security update.
https://lessmsi.activescott.com/

NTLite 2.0.0.7784 resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

ProduKey 1.95 adds option to extract partial key from WMI. This is not a security update.
https://www.nirsoft.net/utils/product_cd_key_viewer.html

PSAppDeploy 3.8.4 resolves several bugs. This is not a security update.
https://psappdeploytoolkit.com/

RAMDisk 4.4.0.RC36 resolves several bugs and updates libraries. This is not a security update.
http://memory.dataram.com/products-and-services/software/ramdisk

RoboForm 9.1.1 updates credit card storage data, resolves several bugs, and now uses secure transmission for automatic updates. This is a security update.
https://12pd.com/click?rf

SimpleWMIView 1.42 adds an option to start hidden. This is not a security update.
https://www.nirsoft.net/utils/simple_wmi_view.html

TaskSchedulerView 1.66 adds pagination to the properties widow and adds Task Filename column. This is not a security update.
https://www.nirsoft.net/utils/task_scheduler_view.html

TeamViewer 15.14.5 was released. The TeamViewer release notes have been unavailable for over a month, so while it might be a security update, it would be safer to remove TeamViewer until these issues are resolved.
https://www.teamviewer.com/en/download/windows/

USB Oblivion 1.16.0.0 adds ability to preserve desktop settings and clean UserAssist keys. This is not a security update.
http://www.cherubicsoft.com/en/projects/usboblivion

WinScan2PDF 6.55 resolves several bugs and improves scanner compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 4.1.2.0 resolves a dozen bugs. This is not a security update.
https://developer.android.com/studio

MySQL ConnectorNet 8.0.23 is a security update.
https://dev.mysql.com/downloads/connector/net/

Node.js 15.8.0 resolves dozens of bugs. This is not a security update.
https://nodejs.org/en/

Node.js 14.15.5 resolves several bugs. This is not a security update.
https://nodejs.org/en/

SQLite 3.34.1 adds new features and resolves several bugs. This is not a security update.
https://www.sqlite.org/download.html

StrawberryPerl 5.32.1.1 resolves several bugs. This is not a security update.
https://strawberryperl.com/

Visual Studio Code 1.53 resolves several bugs and adds several features and controls. This is not a security update.
https://code.visualstudio.com/

WinMerge 2.16.10 resolves several bugs and adds new command-line switches and features. This is not a security update.
https://winmerge.org/

Virtual Machine Updates

These are unlikely to be of interest to most people.

PPSSPP 1.11 resolves dozens of bugs. This is not a security update.
https://ppsspp.org/downloads.html

VirtualBox 6.1.18-142142 resolves several stability and reliability bugs. This is not a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

Adminer 4.7.9 is a security update.
https://www.adminer.org/en/

Coppermine Gallery 1.6.10 improves compatibility with PHP 8.01. This is not a security update.
https://coppermine-gallery.net/

Docker Desktop 3.1.0 resolves several bugs. This is not a security update.
https://www.docker.com/products/docker-desktop

Drupal 9.0.11 is a security update.
https://drupal.org/download

Drupal 9.1.4 resolves dozens of bugs. This is not a security update.
https://drupal.org/download

HumHub 1.7.2 resolves over a dozen bugs. This is a security update.
https://www.humhub.com/en/download

Nextcloud Server 20.0.7 updates libraries and resolves dozens of bugs. This is not a security update.
https://nextcloud.com/

OpenCart 3.0.3.7 doesn’t provide a detailed changelog so should be treated as a security update.
https://www.opencart.com/

Piwigo 11.3.0 resolves several bugs. This is a security update.
https://piwigo.org/

ScreenConnect 21.2.2159.7699 adds a security tile to configure security options and resolves several bugs. This is not a security update.
https://www.connectwise.com/software/control/download

SMF 2.0.18 is a security update.
https://www.simplemachines.org/

WordPress 5.6.1 resolves several bugs. This is not a security update.
https://wordpress.org/

Social Post Feed 2.18.2 improves GDPR compatibility and resolves a deletion bug. This is not a security update.

Multisite Enhancements 1.6.1 resolves a path bug. This is not a security update.

Redirection 5.0.1 adds support for PHP 8 and resolves several bugs. This is not a security update.

NextScripts Social Networks Auto-Poster 4.3.20 resolves several bugs. This is not a security update.

Sucuri Security 1.8.25 updates the password reset process. This is not a security update.

W3 Total Cache 2.1.0 resolves several bugs and adds cache groups. This is not a security update.

WooCommerce 4.9.2 improves compatibility and disables untested plugins from status and plugin pages. This is not a security update.

WP Mail SMTP 2.6.0 improves compatibility. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

 

 

Updates 2020-12-08

Welcome back, Folks!

Today is Patch Tuesday for December, 2020. It’s a big one and huge updates are available for over a hundred applications. A new OpenSSL released today means that there will be even more updates released in the near future, so this is only the first of at least two update series’ to top off December.

This Month in Technology

Apple (and others) are trying to make slavery legal, Apple’s cloud services choked this month as a result of their new on-demand certification and telemetry collection nightmare, Big Sur even bricks some MacBook Pro models, but they’re admitting that they intentionally throttled their older hardware, and Apple had a major security issue that allowed total control of their iPhones over Wi-Fi. While Apple has fixed that bug, their hardware is vulnerable to new forensic tools used by foreign (and likely US) governments to clone all the data from your device. This is “Epic.” Apple is cutting their App Store fees to 15% for small developers.

K12 Inc, Foxconn electronics, the City of Long BeachTransLink (Vancouver public transit), EmbraerKopterShirbitRandstad NVAdvantechBowie and Miller Counties (TX), and Baltimore County Public Schools have all been hit with ransomware. If you leave your backup drives connected (tethered or networked) then there’s growing evidence that the backups will be targeted by ransomware before your active data. And some ransomware gangs are cold-calling if you try to restore from backups.

Millions of IoT devices are vulnerable to a newly discovered vulnerability, thousands of PickPoint lockersLSU Health New OrleansAspenPointe, and PlutoTV have been hacked. Dell was hacked years ago which resulted in their data being abused for scam calls to Dell customers. Class action happening now.

Walmart routers and many TCL TVs have backdoorsGionee implanted malware in 21 million phones, and battery backups are used to infect mobile devices. Google Services are still being used to distribute malware, Google ads are being used to steal MetaMask. A year after the US Army’s Stryker armored vehicles were hacked the Army is finally building security defenses, and in other US military news, the military violates your privacy through third-party apps.

Social media icons are being used to inject web skimmers that are now using WebSockets to exfiltrate data using secure CloudFlare services.

If you trust your choice of password simply because a poorly designed study says that it would take thousands or millions of years to brute force a password then you should take a look at how a single quantum computer process the equivalent of 2.6 billion (with a “b”) years of computation in only 4 minutes, but using the latest quantum hardware isn’t even necessary for the vast majority of passwords since humans are so predictable.

In a random collection of news: MBAM is disabling Windows Printers. HMRC (the UKs equivalent of the IRS) has been abused to send phishing and malware messages (I warned them about this months ago). There is no end to PayPal’s hypocrisy, nor their censorship. GitHub reversed it’s decision about YouTube-dl. Twitch has failed basic EnglishComcast is capping data in 12-ish more states next year, but giving service away for free to many others. The running joke about how social censorship would be similar to your phone company preventing you from talking about certain subjects has proven to be more prescient than humorous. Cannibalism is coming to a grocery store near you. A few years ago I found that a number of IT and HVAC services in the SF bay area had their Google listings hijacked and reassigned as Korean Restaurants. It was only the beginning.

The “sciencebehind masks has never been scientific, but that won’t stop petty tyrants from mandating their use even while actively eating or drinking, or censoring dissenting voicesFalse positive tests are still leading the charge, but lockdown-related homicides are still exceeding “COVID” deaths. Censors will always target studies that demonstrate overreaching government intervention.

California is pushing out the Orwellian exposure tracking and notifications across the state.

Now for the good news:

When this election is finally resolved it’s unlikely to get to this point again any time in the near future.

As a perfect example of what 2020 has brought us – the South African lottery drew 5, 6, 7, 8, 9 and 10, which is insane enough, but the real story is that 20 people had actually selected those numbers.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday this month is huge. The typical computer should see roughly 2.5 GB in updates today. Let’s get started.

Microsoft released updates for Windows, Edge, and Servicing Stack (~ 1.5 GB). This includes security updates. A reboot is required.

Apple released updates for iCloud for Windows 11.5, and iOS 14.2.1. Expect an update to iTunes, too, in the next few days. These are security updates.

iOS 14.2.1 is a security update. Use Settings, General, Software Update to install the most current version.

Adobe Flash Player 32.0.0.465 is a security update. Since Flash is going the way of the dodo along with the Year from Hell, this could very well be the last time you may have to install a Flash update. You’re still better off removing it yourself instead of updating. 🙂
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Google Chrome OS 87.0.4280.88 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Big Sur (11.0) means that macOS High Sierra (10.13) and older are no longer supported. If you can not install at least macOS Mojave (10.14) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (v2009) is huge (about 18% larger than v2004, which was 25% larger than any prior build) so will take a long time to download on slower connections. Windows 10 pushes you to get the latest Windows 10 release every 6 months. If you don’t let it finish and you’re on a slow connection, this process kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

BullZip PDF Printer 12.0.0.2872 adds several new features, including improved email support, compatibility, and concurrent printing. This is not a security update.
https://www.bullzip.com/products/pdf/info.php#download

Crucial Storage Executive 6.09 doesn’t provide a changelog so should be treated as a security update.
https://www.crucial.com/support/storage-executive

Logitech Options 8.36.86 allows changing function keys, customizing mouse buttons, and adds on-screen battery notifications. This is not a security update.
https://www.logitech.com/en-us/product/options

Logitech Options for macOS 8.36.76 adds Big Sur support, allows changing function keys, customizing mouse buttons, gesture controls, and adds on-screen battery notifications. This is not a security update.
https://www.logitech.com/en-us/product/options

nVidia 457.51 adds support for new hardware, updates SLI profiles, and resolves several bugs. This is not a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.17.75 is a security update. Use Menu, Help, About to install the most current version.
https://brave.com/

Google Chrome 87.0.4280.88 is a security update. Use Menu, Help, About to install the most current version.
https://www.google.com/chrome/

Microsoft Edge 87.0.664.57 is a security update. Use Menu, Help, About to install the most current version.
https://www.microsoft.com/en-us/edge/business/download

Firefox 83.0 is a security update. Use Menu, Help, About to install the most current version.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 78.5.0 is a security update. Use Menu, Help, About to install the most current version.
https://www.mozilla.org/en-US/firefox/organizations/all/

SeaMonkey 2.53.5.1 is a security update. Use Menu, Help, About to install the most current version.
https://www.seamonkey-project.org/

Vivaldi 3.5.2115.73 is a security update. Use Menu, Help, About to install the most current version.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 78.5.1 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

Dropbox 111.4.472 doesn’t provide a changelog so should be treated as a security update. This version is not reliable on Windows 8.
https://www.dropbox.com/

FreeFileSync 11.4 resolves several bugs, and improves compatibility. This is not a security update.
https://www.freefilesync.org/download.php

iCloud for Windows 11.5 is a security update.
https://apple.com/icloud

Technitium DNS Server 5.5 adds support for SRV records and resolves several bugs. This is not a security update.
https://technitium.com/dns/

WinSCP 5.17.9 resolves several bugs. This is not a security update.
https://winscp.net/eng/index.php

Zoom 5.4.59296.1207 adds meeting reminders, warnings for meetings that are only partially encrypted, and resolves several bugs. This is a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 2.0.8 updates libraries, improves sync and face tracking, adds ability to call shortcuts, and resolves several bugs. This is not a security update.
https://en.3tene.com/

iTunes 12.11 doesn’t provide a changelog so should be treated as a security update.
https://www.apple.com/itunes/download/

Picard 2.5.2 resolves several bugs. This is not a security update.
https://picard.musicbrainz.org/

Game Updates

These are unlikely to be of interest to most people.

Steam 2020.12.07 is a security update.
https://www.steampowered.com/platform/update_history/index.php?skin=0&id=0

PlayStation PS4 8.01 improves reliability. This is not a security update. Note that Sony changed the URLs without adding redirects, so the new location to download updates has changed:
https://www.playstation.com/en-us/support/hardware/ps4/system-software/

Office Updates

One or more of these are likely to be of interest to most people.

Blender 2.91.0 adds several new features and controls. This is not a security update.
https://www.blender.org/download/

Adobe Acrobat (version yet to be announced) is a security update. Use Help, Check for updates to get the most current version…when it’s released.

Adobe Reader (version yet to be announced) is a security update. Use Help, Check for updates to get the most current version…when it’s released.

Adobe Lightroom 10.1 is a security update.
https://creativecloud.adobe.com/apps/all/desktop

Adobe Experience Manager 6.5.7.0 and 6.4.8.3 are security updates.
https://helpx.adobe.com/security/products/experience-manager/apsb20-72.html

Adobe Prelude 9.0.2 is a security update.
https://creativecloud.adobe.com/apps/all/desktop

Security Software Updates

One or more of these is likely to be of interest to most people.

Gpg4win 3.1.14 updates libraries and resolves several bugs. This is not a security update.
https://www.gpg4win.org/download.html

Nmap 7.90 adds 1,200 new fingerprints, resolves over 70 bugs, and provides several new features. It also removes silent install. 🙁 This is a security update.
https://nmap.org/download.html

Npcap 1.00 is the first stable release of Npcap. This is not a security update.
https://nmap.org/npcap/

RogueKiller 14.8.0 resolves several bugs. This is a security update.
https://www.adlice.com/download/roguekiller/

uBlock Origin 1.31.2 resolves reliability in Chromium. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

Tails 4.13 is a security update.
https://tails.boum.org/install/dvd-download/index.en.html

OpenSSL 1.1.1i is a security update. Releases of OpenSSL always trigger updates for every other platform that uses networking in any way, so expect a series of updates for every other web platform you use in the near future.
https://www.openssl.org/

Capture Updates

These are unlikely to be of interest to most people.

SnagIt 2021.0.2 resolves several bugs. This is not a security update.
https://download.techsmith.com/snagit/enu/snagit.exe

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 12.0.0.9 adds support for new encodings, resolves several bugs, and improves stability. This is not a security update.
https://www.dvdfab.cn/download.htm

Utility Updates

These are unlikely to be of interest to most people.

1Password for Mac 7.7 adds Privacy integration, unlock with Apple Watch, MDM integration, improved password generator, and resolves over 100 bugs. This is a security update.
https://1password.com/downloads/mac/

Agent Ransack 2019.2951 improves performance at idle and resolves several bugs. This is not a security update.
https://www.mythicsoft.com/agentransack/download/

Bitwarden 1.23.1 resolves bugs with SSO and improves GDPR compliance. This should be treated as a security update.
https://bitwarden.com/

DesktopOK 8.08 resolves several bugs and updates language support. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

Etcher 1.5.112 updates libraries, and resolves several bugs. This is not a security update.
https://www.balena.io/etcher/

Everything 1.4.1.1000 resolves a bug with silent installation, wide-character comparison, name munging and other bugs. This is not a security update.
https://www.voidtools.com/

FileLocator Pro 8.5.2951 improves performance when idle and resolves several bugs. This is not a security update.
https://www.mythicsoft.com/filelocatorpro/download

GoodSync 11.4.9 resolves dozens of bugs. This is not a security update.
https://12pd.com/click?goodsync

Homedale 1.90 adds support to load access points from CSV and improves frequency usage chart. This is not a security update.
https://www.the-sz.com/products/homedale/

HWMonitor 1.43 adds support for new hardware. This is not a security update.
https://www.cpuid.com/softwares/hwmonitor.html

MS ISO Downloader 8.44 adds support for new media (including Win10 20H2v2) and resolves several bugs. This is not a security update.
https://www.heidoc.net/joomla/technology-science/microsoft/67-microsoft-windows-and-office-iso-download-tool

NTLite 2.0.0.7726 resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

Aomei Partition Assistant 9.0 adds shred files support. This is not a security update.
https://www.diskpart.com/

PointerStick 4.88 updates language support. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

Rufus 3.13 adds support for a 20H2v2, adds support to cheat certain disk images, improves error handling, and resolves several bugs. This is not a security update.
https://rufus.ie/en_IE.html

Sysmon 12.03 fixes reporting and a possible crash condition for certain rules. This should be treated as a security update.
https://live.sysinternals.com/

SDelete 2.04 provides a new switch to avoid file/directory ambiguity. This should be treated as a security update.
https://live.sysinternals.com/

WinObj 2.23 resolves several bugs. This is not a security update.
https://live.sysinternals.com/

TaskSchedulerView 1.60 adds support for exporting tasks to JSON, and updates HTML export to HTML5. This is not a security update.
https://www.nirsoft.net/utils/task_scheduler_view.html

TeamViewer 15.12.4 resolves several bugs, improves performance, and adds support for more web cameras. This is not a security update.
https://www.teamviewer.com/en/download/windows/

WinScan2PDF 6.33 improves detection and operation with some hardware, updates language support, and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

Developer Updates

These are unlikely to be of interest to most people.

DB Browser for SQLite 3.12.1 resolves several bugs. This is a security update.
https://sqlitebrowser.org/

Inno Setup 6.1.2 adds Print support and resolves several bugs. This is not a security update.
https://www.jrsoftware.org/isdl.php

Node.js 12.20.0 updates libraries and resolves several bugs. This is a security update.
https://nodejs.org/en/

Node.js 14.15.1 is a security update.
https://nodejs.org/en/

Node.js 15.3.0 updates libraries and resolves several bugs. This is a security update.
https://nodejs.org/en/

SQLite 3.34.0 resolves several bugs. This is not a security update.
https://www.sqlite.org/download.html

Web Package Updates

These are likely to be of interest only to web developers.

Adminer 4.7.8 adds support for PHP 8 and disallows connecting to privileged ports. This is not a security update.
https://www.adminer.org/en/

Drupal 9.0.10 is a security update.
https://drupal.org/download

Drupal 9.1.0 resolves several bugs. This is not a security update.
https://drupal.org/download

HumHub 1.7.1 resolves several bugs. This is not a security update.
https://www.humhub.com/en/download

Joomla 3.9.23 is a security update.
https://www.joomla.org/

Nextcloud Server 20.0.2 resolves dozens of bugs. This is not a security update.
https://nextcloud.com/

phpList 3.5.8 adds new functionality to AJAX form and updates libraries. This is not a security update.
https://www.phplist.org/

ScreenConnect 20.12.1734.7640 resolves several bugs. This is not a security update.
https://www.connectwise.com/software/control/download

WordPress 5.6 updates libraries, adds several new features and blocks, a new theme, and more. This is not a security update.
https://wordpress.org/download/

BuddyPress 6.4.0 is a security update.

Contact Form 7 5.3.1 now passes last_contacted based on submission timestamp. This is not a security update.

Multisite Enhancements 1.5.4 fixes favicon. This is not a security update.

Theme My Login 7.1.2 improves stability and resolves several bugs. This is not a security update.

WooCommerce 4.8.0 resolves several bugs. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/