Updates 2024-09-10

Welcome back, Folks!

Today is Patch Tuesday for September, 2024.

We’re one month closer to the next build of Windows 11 and the next release of macOS, both due in mere weeks. A new major version of Office (aka Microsoft 365) is due at the same time, as well.

When the new build of Windows 11 is released all versions of Windows 11 prior to 23H2 will no longer be supported. Upgrade to 23H2 now if you have not done so yet, then do not upgrade to 24H2 when it is released. Let everyone else be the guinea pigs.

When the new build of macOS is released all versions of macOS prior to 13/Ventura will no longer be supported. If you can’t upgrade your Mac to Ventura you need to switch it to Linux or replace it.

Windows 10 now has only 13 months of support left. If your computer can not be upgraded to Windows 11 either start planning for a switch to Linux or replacing your computer.

There were 310+ major hacks, and over 200 application updates this month.
It’s a relatively small month, with only about 2.0 GB of updates for most users.

This Month in Technology

ABC Parts International, Acadian Ambulance, Adina Design, Advanced Medical Management, LLC, Aioi Nissay Dowa Insurance, Air International Thermal Systems, Akeela, Alabama Cardiology Group, Alcampo, Allergy Medical Group of the North Area, Inc, Ambulnz Holdings, AMD, American Clinical Solutions, an “industrial company” in Somerset County, NJ, an Israeli IT company, Android, Angus Council, Apache OFBiz (Open For Business), Apache Tomcat, Applause, Arden Claims Service, Argentine Air Force, Armour Coatings, Around the Clock Companies, Artifact Uprising LLC, Asus RT-N15U, Australian Cancer Research Foundation, Autel Maxicharger, AutoCanada, Avis, AVTECH CCTV cameras, 15,000 AWS Load Balancers, Azure Health Bot, Baird Mandalas Brockstedt LLC, Baker Places, Inc, Banham Poultry, Bank Rakyat, Baptist Health Medical Center Drew County, Bar2, Barrie, Behavioral Health Alliance of Rural Pennsylvania, Beng Kuang Marine, Benson Kearley IFG, Biggin Hill’s Charles Darwin School, bitcoin hardware wallets (Dark Skippy), Blain Jacobson DMD, CAGS, Blooms Today, Boutiqaat, BPOTech, Bromley GP, BVI Electricity Corporation, Caja Los Andes, CannonDesign, Canvey Island Infant School, Carehands, Carespring Healthcare, Catholic Charities CYO of The Archdiocese of San Francisco, CBIZ Benefits & Insurance Services, Cellular Plus, Centers for Medicare & Medicaid Services, Chevrolet, Chris Leong, CinemaTech, Cisco Identity Services Engine, Cisco Smart Licensing Utility, City of Columbus, OH, City of Flint, MI, City of St. Helena, CA, Clabots, Communication Federal Credit Union, Compex Legal Services Inc, Confidant Health, Connex health portal, Consilium Staffing, Consulting Radiologists LTD, Covenant Care California, LLC, Crain Group, Dahua cameras, Data Bilgi Islem, Davidoff Hutcher & Citron LLP, DBA ATC Home Care, Deutsche Flugsicherung (DFS), Dibcase, Dick’s Sporting Goods, DimeCuba, Dingding Talk, Disney Cruise lines, Disneyland, Domino’s Pizza Singapore, Durex India, Ecovacs, EnglishCentral, Enroll Confidently, Inc, Eric Rossi CPA LLC, Erie Meats, EV infrastructure, Exotel, Explore Talent, External Secrets Operator, Facial Pain Center, Farmers’ Rice Cooperative, Fish Nelson & Holden, FlightAware, Florida Department of Health, Fortra FileCatalyst Workflow, Fota Wildlife Park, Free Russia Foundation, Futurity First Insurance Group, GDB International, GeoServer Project, GitHub Enterprise Server, GiveWP WordPress Plugin, Google Chrome, Gramercy Surgery Center, Granville Recreation District, Greater Manchester Council, Grid Subject Matter Experts, Halliburton, Highline Public Schools, Hospital Sisters Health System, HP Security Manager, HPE HP-UX, IBM webMethods Integration Server, ICWI, Imetame, Imperial Sprinkler, LLC, Infosys McCamish Systems LLC, Institut National des Langues Luxembourg, iPhone, Isuzu Motors International Operations (Thailand), Ivanti Virtual Traffic Manager, Jangho Group, JAS Forwarding, Jenkins, Jewish Home Lifecare, Katz Nannis + Solomon, PC, Keene School District, Kentucky Corrections Department, Keycloak, Keystone Pacific Property Management, Kingdom Trust, King’s Choice, KlockMetal, Kootenai Health, Lake Washington Institute of Technology, Lakeland’s Watson Clinic, LAPOR, Laybuy, LDLC, Leal.co, LiteSpeed Cache WordPress Plugin, Lookiero, Los Angeles County Department of Mental Health, Market Moveis, McDonald’s Instagram, Medical Center Barbour, MedicaMall, Metro Pacific Tollways Corporation, Microchip Technology, Micron Crucial MX500, Microsoft Copilot Studio, Microsoft Entra ID, Microsoft OneNote, Microsoft Outlook, Microsoft Teams, Microsoft Word, Mid-Columbia Center for Living, Mifare Smart Cards, Mill Creek Lumber, Mitsubishi Chemical Group, Mitsui Sumitomo Insurance, Mohawk Valley Cardiology PC, Monobank, Musely AI, Muzu.co, MyFreightWorld, National Oceanic and Atmospheric Administration (NOAA), National Public Data, National Research Council of Italy, NHS Grampian, Okanogan Behavioral HealthCare, Oldham Council, Omicron Granite & Tile, Oregon Zoo, Orion, Packaging Corporation of America, Parker Development Company, ParkTree Community Health Center, Park’N Fly, Patelco Credit Union, PBC Companies, Pi Camera, Planned Parenthood of Montana, Plastix Marketing, Pocahontas Medical Clinic, Policy Administration Solutions, Port of Seattle, PostgreSQL, Prasarana Malaysia, Precom, Progress Software LoadMaster, ProPark Mobility, Public Agency Retirement Services (PARS), Quilvest Capital Partners, Radar/Dispossessor, Radiological Society of North America, RapidCMS, RCG, Regent Caravans, Relevvo, Retail Data, Rhithm Wellness App, Riverside Resort & Casino, Roberto Verino Difusion, Roblox Developers, Rochester Honkers, Rödl Management, SAP, Schlatter Industries, Scott Pharma Solutions, Sea-Tac Airport, Seirus Innovation, SenangPay Malaysia, Service Access & Management, ServiceBridge, Siam Cement Group, Sibanye-Stillwater, siParadigm, Slack, Slim CD, Software Engineering Associates, Solana, SolarWinds Web Help Desk, Sompo Japan Insurance, SonicWall SonicOS, South Carolina State University, South Orange County Community College District, Southwest Family Medicine Associates, Spanish Athletics Federation, Specialty Networks, Sport 2000, Sri Lankan Farmers Community, St. Clair County, IL, Stein Fibers, Stoxkart, Stripe CLI, Strive Medical, Strong Current Enterprises, Supreme Court of Philippines, SWISSCZ, Swissphone DiCal-RED, Tabb Inc, Tamil Nadu Labour Department Data, Taxellent Accounting Services Inc, Tewkesbury Council, Texas Centers for Infectious Disease Associates, Texas Dow Employees Credit Union, The Bakersfield Californian, The SMS Group, ThinkPHP, Thompson Davis & Co, TIAA, Toaping, Tokio Marine & Nichido Fire Insurance, Toronto District School Board, Town of Plymouth, CT, Toyota, toyyibPay, Traccar GPS System, Tracki, Traderie, Transport for London, TRENDnet TEW, Trionfo Solutions, Turkish government, Turning Point of Central California, Inc, UConn Health, UK National Crime Agency, UK Political Party Donation Platforms, Ukrainian government, Unicoin, United Services Automobile Association (USAA), United Urology Group, United Way of Connecticut, Inc, Universal Pure, University of Toronto, US Federal Bureau of Investigation (FBI), US Lottery Corporation, US Marshals Service, US Merchants Financial Group, Inc, US Transportation Security Administration (TSA), Valisana, Veeam services, VeriSource Services, Inc, Verkada, Versa Director, VMware ESXi, VMware VCenter Server, VOP CZ, Wayne Wright, LLP, WazirX, Welcome Health, WellLife Network, Western Electrical Contractors Association, WhatsApp, WinRAR, WPS Office, XPERT Business Solutions GmbH, Young Consulting, YubiKey 5, Zee Media, and Zyxel have reported hacking or compromises this month.

HalliburtonTransport for London, and McLaren Health have suffered from outages this month.

Last months updates broke BitLockerdual-boot (Windows + Linux), Outlook, Word, and Windows.

The National Public Data breach (leak, to be more accurate) has had an interesting turn of events, where they are now claiming that they’ve removed the entire database from their platform (it’s still available everywhere else). Opting out via their platform is dismissed and they offer no resolution. Not that one could be had.

A novel side-channel attack dubbed “RAMBO” (Radiation of Air-gapped Memory Bus for Offense) generates electromagnetic radiation from a device’s RAM to send data from air-gapped computers.

Microsoft has finally removed the defective and half-baked WinRE update causing daily and sometimes hourly errors because it couldn’t install on many devices.

Twitch force-enabled VTubers’ cameras without their consent.

Now for the good news:

The US appeals court had ruled geofence warrants are unconstitutional.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is pretty small this month. The typical computer should see roughly 2 GB in updates today. Let’s get started.

Microsoft released 41 updates to address 79 vulnerabilities in Azure CycleCloud, Azure Network Watcher, Azure Stack, Azure Web Apps, Dynamics Business Central, Microsoft AutoUpdate, Microsoft Dynamics 365, Microsoft Graphics Component, Microsoft Management Console, Microsoft Office Excel, Microsoft Office Publisher, Microsoft Office SharePoint, Microsoft Office Visio, Microsoft Outlook for iOS, Microsoft Streaming Service, Power Automate, SQL Server, Windows Admin Center, Windows AllJoyn API, Windows Authentication Methods, Windows DHCP Server, Windows Hyper-V, Windows Installer, Windows Kerberos, Windows Kernel-Mode Drivers, Windows Libarchive, Windows Mark of the Web (MOTW), Windows MSHTML Platform, Windows Network Address Translation (NAT), Windows Network Virtualization, Windows PowerShell, Windows Remote Access Connection Manager, Windows Remote Desktop Licensing Service, Windows Security Zone Mapping, Windows Setup and Deployment, Windows Standards-Based Storage Management Service, Windows Storage, Windows TCP/IP, Windows Update, Windows Win32K – GRFX, Windows Win32K – ICOMP, and MSRT. This includes security updates. A reboot is required.

Apple released updates for tvOS 17.6.1 and watchOS 10.6.1. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

watchOS 10.6.1 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 17.6.1 is a security update. Use System, Software Update to install the most current version.

Google Chrome OS 126.0.6478.252, 127.0.6533.132 and 128.0.6613.133 are security updates. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sonoma (14.x) means that macOS Big Sur (11.x) and older are no longer supported. If you can not install at least macOS Monterey (12) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v23H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it, but I recommend you continue to use Windows 10 until early 2025 before you consider switching to it.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 24.8.1 adds support for several games, including Concord, for what that’s worth and resolves several bugs.. This is not a security update.
https://www.amd.com/en/support

Crucial Storage Executive 10.07 doesn’t provide a change log so should be treated as a security update.
https://www.crucial.com/support/storage-executive

UniFi Network Server 8.4.59 adds support for Passpoint/Hotspot 2.0, Packet Capture, AP Analyzer, Pro AV and advanced IGMP snppting. This is not a security update.
https://www.ui.com/download/releases/network-server

Wacom Driver 6.4.7-3 resolves several bugs. This is a security update.
https://www.wacom.com/en-us/support/product-support/drivers

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.69.162 is a security update.
https://brave.com/

Firefox 130.0 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Google Chrome 128.0.6613.84 is a security update.
https://www.google.com/chrome/

Microsoft Edge 128.0.2739.67 is a security update.
https://www.microsoft.com/en-us/edge/business/download

SeaMonkey 2.53.19 is a security update.
https://www.seamonkey-project.org/

Vivaldi 6.9.3447.41 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

ProtonMail (Android) 4.0.19.1 resolves several bugs. This is not a security update.
https://proton.me/mail/download

Spark 3.17.6 is a security update.
https://sparkmailapp.com/

Spark (macOS) 3.17.6 is a security update.
https://sparkmailapp.com/

Thunderbird 128.2.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 8.0.14 adds ability for custom clients to disable tray options. This is not a security update.
https://anydesk.com/en/downloads

Dropbox 206.4.6506 doesn’t provide a detailed change log so should be treated as a security update.
https://www.dropbox.com/

Facebook Messenger 215.4.0.14.211 is a security update.
https://www.messenger.com/download

FileZilla Server 1.9.1 is a security update.
https://filezilla-project.org/

Google Drive 96.0 now alerts users to stalls and resolves several bugs. This is not a security update.
https://drive.google.com/start

MeshCentral 1.1.29 resolves dozens of bugs. This is not a security update.
https://meshcentral.com/info/downloads.html

Microsoft Teams 1.7.00.21751 adds reaction support to Town Hall feature. This is not a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 29.0.6 resolves dozens of bugs. This is not a security update.
https://nextcloud.com/

Rclone 1.68.0 adds several new backends, improves S3 support, and resolves dozens of bugs. This is not a security update.
https://rclone.org/

Signal 7.23.0 improves performance. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.15.4 doesn’t provide a detailed change log so should be treated as a security update.
https://signal.org/android/apk/

Syncthing 1.27.12 is a security update.
https://syncthing.net/

Telegram 5.5.3 resolves several bugs. This is not a security update.
https://telegram.org/

Telegram (Android) 11.0.0 doesn’t provide a detailed change log so should be treated as a security update.
https://telegram.org/apps

Trillian 6.5.0.45 resolves several bugs.
https://www.trillian.im/

WinSCP 6.3.5 is a security update.
https://winscp.net/eng/index.php

Zoom 6.1.11.45504 resolves several bugs. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.9 resolves several bugs. This is not a security update.
https://en.3tene.com/

Bitwig Studio 5.2.3 improves hardware support and resolves a key binding error. This is not a security update.
https://www.bitwig.com/download/

Grayjay 262 adds recommendations, improved comment system, and resolves several bugs. This is not a security update.
https://grayjay.app/index.html

Kodi 21.1 is a security update.
https://kodi.tv/

Plex Desktop 1.100.1.221 resolves a season poster display bug. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Home Theater 1.66.1.215 updates the web TV client. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Media Server 1.40.5.8921 is a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.23.01 doesn’t provide a detailed change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

PS5 2024.829 adds URL sharing, improves performance and hardware support. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Acrobat 24.003.20112, 24.001.30187 and 20.005.30680 are security updates.
https://helpx.adobe.com/security/products/acrobat/apsb24-70.html

Adobe Acrobat Reader 24.003.20112 and 20.005.30680 are security updates.
https://helpx.adobe.com/security/products/acrobat/apsb24-70.html

Adobe After Effects 24.6 and 23.6.9 are security updates.
https://helpx.adobe.com/security/products/after_effects/apsb24-55.html

Adobe Audition 24.6 and 23.6.9 are security updates.
https://helpx.adobe.com/security/products/audition/apsb24-54.html

Adobe ColdFusion 2023.10 and 2021.16 are security updates.
https://helpx.adobe.com/security/products/coldfusion/apsb24-71.html

Adobe Illustrator 28.7.1 and 27.9.6 are security updates.
https://helpx.adobe.com/security/products/illustrator/apsb24-66.html

Adobe Media Encoder 24.6 and 23.6.9 are security updates.
https://helpx.adobe.com/security/products/media-encoder/apsb24-53.html

Adobe Photoshop 24.7.5 and 25.12 are security updates.
https://helpx.adobe.com/security/products/photoshop/apsb24-72.html

Adobe Premiere Pro 24.6 and 23.6.9 are security updates.
https://helpx.adobe.com/security/products/premiere_pro/apsb24-58.html

Audacity 3.6.3 resolves several bugs. This is not a security update.
https://www.audacityteam.org/download/

Blender 4.2.1 doesn’t provide a detailed change log so should be treated as a security update.
https://www.blender.org/download/

Calibre 7.17.0 adds paper-edition page number support, editing, and resolves several bugs. This is not a security update.
https://calibre-ebook.com/

Formatta Filler 8.19.04 doesn’t provide a change log so should be treated as a security update.
https://www.phreesia.com/filler-ifiller/

Kdenlive 24.08.0 improves user interface for easing modes, effect groups, transform, and curve, as well as several bug fixes. This is not a security update.
https://kdenlive.org/

Kindle for PC 2.5.70951 doesn’t provide a change log so should be treated as a security update.
https://www.amazon.com/kindleforpc

LibreOffice 24.2.6 resolves over 40 bugs. This is a security update.
https://www.libreoffice.org/

LibreOffice Fresh 24.8.0 resolves over 400 bugs. This is a security update. The “Fresh” line is beta software and should be avoided by most people.
https://www.libreoffice.org/

Manager 24.9.9.1845 adds a business template gallery and support for Financial Data Exchange (FDX). This is not a security update.
https://www.manager.io/

Nextcloud Desktop 3.13.3 resolves almost 100 bugs. This is not a security update.
https://nextcloud.com/

PDF-XChange Editor 10.4.0.388 resolves dozens of bugs. This is a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

QuickBooks Pro 2022 20240726-R17_22 doesn’t provide a detailed change log so should be treated as a security update.
https://downloads.quickbooks.com/app/qbdt/products

QuickBooks Pro 2023 20240726-R14_25 doesn’t provide a detailed change log so should be treated as a security update.
https://downloads.quickbooks.com/app/qbdt/products

Scribus 1.6.2 resolves several bugs. This should be treated as a security update.
https://www.scribus.net/

Security Software Updates

One or more of these is likely to be of interest to most people.

Chainsaw 2.10.0 resolves several bugs and adds Key/Value container support.
https://github.com/countercept/chainsaw

FSS 2024.8.15 doesn’t provide a detailed change log so should be treated as a security update.
https://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/

MalwareBytes Anti-Malware 5.1.10.127 resolves several bugs. This is not a security update.
https://www.malwarebytes.org/antimalware/

OpenSSL 3.3.2 is a security update.
https://slproweb.com/products/Win32OpenSSL.html

ProtonVPN (macOS) 4.4.0 resolves several bugs and improves stability. This is not a security update.
https://protonvpn.com/download

RogueKiller 15.18.2 resolves several bugs. This is not a secuirty update.
https://www.adlice.com/download/roguekiller/

SecurityCheck 2024.8.24 doesn’t provide a detailed change log so should be treated as a security update.
https://www.bleepingcomputer.com/download/securitycheck/dl/123/

Stinger 13.0.0.190 adds support for new detections. Thsi is not a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

Tails 6.7 is a security update.
https://tails.net/install/download/index.en.html

VT-CLI 1.0.1 adds support for Chocolatey, updates actions and resolves several bugs. This is not a security update.
https://github.com/VirusTotal/vt-cli/releases/latest

YARA 4.5.2 is a security update.
https://github.com/VirusTotal/yara/

Capture Updates

These are unlikely to be of interest to most people.

Open Broadcaster Software 30.2.3 resolves several bugs. This is a security update.
https://obsproject.com/

ScreenToGif 2.41.1 updates translatons and resolves a couple bugs. This is not a security update.
https://github.com/NickeManarin/ScreenToGif/releases/latest

SnagIt 24.2.2 adds support for HDR image capture and exporting to Camtasia, and resolves a PDF export bug. This is not a security update.
https://www.techsmith.com/screen-capture.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.2.6 adds support for new encodings and resolves compatibility issues with some hardware. This is not a security update.
https://www.dvdfab.cn/download.htm

PDF Creator 5.3.0 adds OneDrive integration, improved sharing support, and updated libraries. This is a security update.
https://www.pdfforge.org/pdfcreator

StreamFab 6.1.9.7 resolves dozens of bugs and adds a couple new sources. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 2.0.3.3 adds GPU support, ability to remove the scene background, and resolves a few bugs. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Education updates

One or more of these are likely to be of interest to most people.

Zotero 7.0.3 adds rich text markup in titles, improves compatibility, and resolves several bugs. This is not a security update.
https://www.zotero.org/

Utility Updates

These are unlikely to be of interest to most people.

1Password for Mac 8.10.44 adds filtering support, visual and accessibility improvements, and resolves several bugs. This is not a security update.
https://1password.com/downloads/mac/

1Password for Windows 8.10.45 adds filtering support, visual and accessibility improvements, improves compatibility, and resolves several bugs. This is not a security update.
https://1password.com/downloads/windows/

AOMEI Partition Assistant 10.4.2 improves reliability and stability, and resolves several bugs. This is not a security update.
https://www.diskpart.com/

balenaEtcher 1.19.22 replaces Flowzone inputs. This is not a security update.
https://etcher.balena.io/

Beyond Compare 5.0.2.30045 resolves over a dozen bugs. This is not a security update.
https://www.scootersoftware.com/download

Bitwarden 2024.8.2 adds support for autofill cards and identities using keyboard shortcuts, biometrics on Linux, and password-protected exports
https://bitwarden.com/

CalyxOS Device Flasher 1.0.10 doesn’t provide a detailed change log so should be treated as a security update.
https://calyxos.org/install/

CCleaner 6.27.11214 resolves several bugs. This is not a security update.
https://www.ccleaner.com/

Cygwin 3.5.4 resolves several bugs. This is a security update.
https://cygwin.com/

Dell Command Update 5.4.0 improves reliability and stability. This is not a security update.
https://www.dell.com/support/article/us/en/04/sln311129/dell-command-update?lang=en

DesktopOK 11.35 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.2.59.0 adds several new display options, improved performance and translations, and updates libraries. This is a security update.
https://dngrep.github.io/

Everything Toolbar 1.4.1 resovles a sort order bug. This is not a security update.
https://github.com/stnkl/EverythingToolbar/

ExplorerPatcher 22621.3880.66.5 resolves adds Windows 10 Taskbar Style support (with extra steps) and Windows 11 24H2 compatibility. This is not a security update.
https://github.com/valinet/ExplorerPatcher/

FolderChangesView 2.37 is a cosmetic update. This is not a security update.
https://www.nirsoft.net/utils/folder_changes_view.html

GoodSync 12.7.5 resolves dozens of bugs. This is not a security update.
https://www.goodsync.com/

HWiNFO 8.10 adds support for newer hardware. This is not a security update.
https://www.hwinfo.com/download/

InstalledAppView 1.09 adds dark mode support. This is not a security update.
https://www.nirsoft.net/utils/installed_app_view.html

Kingston SSD Manager 1.5.4.6 doesn’t provide a detailed change log so should be treated as a security update.
https://www.kingston.com/us/support/technical/ssdmanager

Mac Migration Assistant 3.0.1.0 doesn’t provide a detailed change log so should be treated as a security update.
https://support.apple.com/en-us/HT204087

NConvert 7.192 doesn’t provide a detailed change log so should be treated as a security update.
https://www.xnview.com/en/nconvert/

NTLite 2024.8.10045 adds support to disable MSA and resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

OSForensics 11.0.1010 resolves over a dozen bugs. This is not a security update.
https://www.osforensics.com/download.html

osquery 5.13.1 resolves a bug. This is not a security update.
https://osquery.io/downloads

PowerToys 0.84.1 resolves several bugs and improves behavior of many apps. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

PSAppDeploy 3.10.2 resolves a dozen bugs. This is not a security update.
https://psappdeploytoolkit.com/

ripgrep 14.1.1 resolves a couple bugs. Thsi is not a security update.
https://github.com/BurntSushi/ripgrep/releases/latest

ScreenConnect 24.2.10.8991 resolves several bugs. This is a security update.
https://screenconnect.connectwise.com/download

SearchMyFiles 3.30 adds support to search by owner. This is not a security update.
https://www.nirsoft.net/utils/search_my_files.html

TeamViewer 15.57.5 resolves several bugs. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/

WifiInfoView 2.94 adds dark mode support. This is not a security update.
https://www.nirsoft.net/utils/wifi_information_view.html

WinScan2PDF 8.93 improves hardware support and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 2024.1.2.12 resolves dozens of bugs. This is not a security update.
https://developer.android.com/studio

GameMaker Studio 2024.8.1.171 adds dozens of features. This is not a security update.
https://www.yoyogames.com/en/gamemaker

GDevelop 5.4.211 improves stability and resolves several bugs. This is not a security update.
https://gdevelop.io/download

GitHub Desktop 3.4.5 adds support for custom editors and shells and resolves several bugs. This is not a security update.
https://desktop.github.com/

Go 1.23.1 is a security update.
https://go.dev/

Godot 4.3 updates libraries, adds thousands of improvements, and resolves hundreds of bugs. This is not a security update.
https://godotengine.org/

Godot 3.6 updates libraries and resolves dozens of bugs. This is not a security update.
https://godotengine.org/

MySQL Server 8.0.39 resolves several bugs. This is not a security update.
https://dev.mysql.com/downloads/installer/

Node.js 20.17.0 resolves dozens of bugs and updates libraries. This is not a security update.
https://nodejs.org/en/

Node.js 22.8.0 resolves dozens of bugs and updates libraries. This is not a security update.
https://nodejs.org/en/

Python 3.12.6 is a security update.
https://www.python.org/downloads/windows/

Unreal Engine 5.4 improves layered control rigs, adds new gizmos, constraints improvements, cosmetic improvements, and resolves several bugs. This is not a security update.
https://unrealengine.com/en-US/

Visual Studio Code 1.93 improves IntelliSense, column resizing, source control, Copilot integration and resolves several bugs. This is not a security update.
https://code.visualstudio.com/

Web Package Updates

These are likely to be of interest only to web developers.

HumHub 1.16.2 resolves dozens of bugs. This is not a security update.
https://www.humhub.com/en

Joomla 5.1.4 is a bug fix release shortly after a security update.
https://www.joomla.org/

MailEnable 10.49 resolves over a dozen bugs. This is a security update.
https://www.mailenable.com/

WordPress 6.6.2 resolves over a dozen bugs. This is not a security update.
https://wordpress.org/

BuddyPress 14.1.0 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/buddypress/

Conditional Widgets 3.2 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/conditional-widgets/

My Sticky Bar 2.7.7 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/mystickymenu/

Sucuri Security 1.9.4 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/sucuri-scanner/

Theme My Login 7.1.9 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/theme-my-login/

WPBakery 7.9 resolves over a dozen bugs and improves compatibility. This is not a security update.
https://wpbakery.com/

WP Cerber Security 9.6.3 adds ability to scan for and resolve third-party plugin issues, and resolves several bugs. This is not a security update.
https://wpcerber.com/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

 

Updates 2021-07-13

Welcome back, Folks!

Today is Patch Tuesday for July, 2021. Bad patches, bad faith, insufferable heat, and a horrific series of holiday events for security professionals has left me in a foul mood. I’ll try to keep my temper.

This Month in Technology

Apex LegendsATMs and PoS platformsBoeingCisco Smart Switchestens of millions of Dell devicesEA (including the source code for dozens of games), IndexsinasiOS activation lock, the IRSKaseya – impacting hundreds of companies and over a million devices, and then, another Linux kernel bugLumaNSW Dept of EducationPlingSolarWinds (again), Southwest AirlinesSwedish Coop supermarkets, VMWare vCenter, Western Digital’s My Book Live devices, and Windows Print Spooler (printnightmare) have been hacked.

Malware was released posing as a Kaseya security update to address their 4th of July horror show, Microsoft signed and published the malware-laden Netfilter rootkit, the Accelion breach keeps getting worse, there’s another strain of ransomware targeting Microsoft Exchange, and 8.4 billion passwords were dumped in a new leak. There has been a 10x increase in businesses targeted by adult phishing messages.

Apple prioritized its own app before competitors in their “fair” app search engine, simply naming a wireless network a certain way can disable iPhone Wi-Fi on devices that connect to it. If it’s an open network, they’ll try to connect to it automatically. Safari broke indexedDB which broke access to almost every web app. Apple uses slave labor while refusing to hire minorities, Siri is still violating your privacy, and if your iPhone is the “key” to your bank or other sensitive information, get a better lock. At least the Woz supports the right-to-repair.

You’re not in charge of your SMART devices. Dell admits to intentionally disabling their hardware. An Australian phone carrier is injecting advertisements into texts. What this says about your use of two-factor authentication (2FA) is that at the very least, your carrier can always access them (and so can any 3-letter agencies). Google has even acknowledged the significance of this risk and is advising developers to stop using texts for 2FA.

Microsoft’s Linux reposMicrosoft Store, and Fastly had major outages. The Fastly CDN outage was caused by “one customer changing a setting.

Microsoft announced the upcoming release of Windows 11, which has only a handful of significant changes (including an uglier user interface and a requirement for home users to use a Microsoft account). This article is a great summary of why forcing a Microsoft account on their users is a bad idea.

If having the Facebook app itself installed weren’t risky enough…they can analyze the photo of a single word to recreate your handwriting, and identify the source of deepfakes, but they can’t bother to follow their own “important rules.” Facebook can be held liable for their facilitation of sex trafficking.

Secretaries of State continue to promote the false “secure election” claims when they, themselves, hold evidence to the contrary. There is now sufficient evidence to demonstrate that election fraud was the norm in 2020. Dominion blames “human error,” and why wouldn’t they? Liberty dies in darkness.

Epic Games is winning appeal in Australia. Robinhood violated the law by getting in bed with Wall Street, and the SEC is targeting independent investors. SpaceX is being investigated for their Starlink expansion (the heat is on). A federal judge has overturned California firearm ban even while California launches a vaccine passport. The Linux Foundation has jumped the shark, by joining the fracas.

The CDC keeps fudging the VAERS numbers so is it any wonder there are bills to ban a federal vaccination database? Why wouldn’t they when there are over 50,000 dead Americans thanks to the CV19 “vaccines,” and the vast majority of “COVID deaths” are to the vaccinated minority? More than half of all (government-funded) COVID “relief” was either stolen or fraudulent. Airlines are banning those who have received the vaccines and Pakistan is banning those who have not from having cell phones. Fauci keeps lying his way around the media, but that’s common when government meets health careProfit-driven labsagenda-driven judges, fake peer reviewand “science” (not to be confused with actual science) have produced defective (unless their intent is to kill) and ineffective vaccines, deadly mask mandates, and insane stay-at-home orders, that have caused irreparable damageJust say no“Voluntary” does not mean “without consent.”

Biden (falsely, in case you weren’t aware) believes “a number of officers” lost their lives during the January 6th “riot“, but is allowing actual murderers go free, even though the capitol staff allowed protesters to enter the magnetically locked doors. This is why Speaker Pelosi refused National Guard assistance. If they were there, their cronies couldn’t have staged this “mostly peaceful” false flag.

The US federal government is researching ways to implement their own version of a social credit system. NCLB=>CRT, and now they’re treating humor as racism. Thanks to interventionalism, gas is going to get much more expensive.

All terrorism is sponsored by the FBI, or concealed by them. That’s not an exaggeration. Anyone that’s turned on a TV knows that there are a lot of pedophiles in government. How many do you think are in the FBI?

Threatening to nuke your citizenry approaches the worst thing any President has ever done. When is revolution justified?

Now for the good news:

This heat wave is finally subsiding.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday this month is very large. The typical computer should see roughly 2.5 GB in updates today. Let’s get started.

Before I begin I should point out that Microsoft released an out-of-band (OOB) security update last week. For the vast majority of users, the “fix” caused more damage than the risk of compromise. Printers, card readers, even disk drives, suffered problems after installing the update, and in some cases Windows was broken as a result. Instead of tying it to the previously (and well-tested) June patch cycle update, they released the OOB update based on the beta version of the July update. I spent most of this week dealing with the fallout from this very poorly tested patch. Grrr.

Microsoft released updates for Windows, Edge, .NET, Servicing Stack, Internet Explorer, and MSRT (~1.2 GB). This includes security updates. A reboot is required.

Apple released updates for iOS 12.5.4 and iMovie 10.2.4. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

iOS 12.5.4 is a security update. Use Settings, General, Software Update to install the most current update.

Google Chrome OS 91.0.4472.147 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Big Sur (11.x) means that macOS High Sierra (10.13) and older are no longer supported. If you can not install at least macOS Mojave (10.14) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (v21H1) is very large, for the first time it’s actually smaller than the previous release, but it will take a long time to download on slower connections. Windows 10 pushes you to get the latest Windows 10 release every 6 months and only supports any consumer builds for 18 months. If you don’t let it finish and you’re on a slow connection, this process kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Display Driver Uninstaller 18.0.4.2 improves cleanup. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

Logitech Options 8.54.161 resolves several bugs. This is not a security update.
https://www.logitech.com/en-us/product/options

Nvidia 471.11 resolves several bugs. This is a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.26.74 is a security update.
https://brave.com/

Google Chrome 91.0.4472.124 is a security update.
https://www.google.com/chrome/

Microsoft Edge 91.0.864.67 is a security update.
https://www.microsoft.com/en-us/edge/business/download

Firefox 90.0 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 78.12.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Iridium 2021.06.91 is a security update.
https://iridiumbrowser.de/

SeaMonkey 2.53.8 is a security update.
https://www.seamonkey-project.org/

Vivaldi 4.0.2312.38 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

NK2Edit 3.42 improves high-DPI support. This is not a security update.
https://www.nirsoft.net/utils/outlook_nk2_edit.html

Thunderbird 78.12.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

Telegram 2.8.4 improves stability. This is not a security update.
https://telegram.org/

AnyDesk 6.3.2 resolves several bugs. This is not a security update.
https://anydesk.com/en/downloads

Dropbox 125.4.3474 doesn’t provide a detailed changelog so should be treated as a security update.
https://www.dropbox.com/

FileZilla Client 3.55.0 improves SFTP and ALPN support, and resolves several bugs. This is not a security update.
https://filezilla-project.org/

FreeFileSync 11.11 resolves several bugs. This is not a security update.
https://www.freefilesync.org/download.php

Npcap 1.50 resolves several bugs and improves compatibility. This is not a security update.
https://nmap.org/npcap/

Omada Software Controller 4.4.3 resolves dozens of bugs and improves reliability. This should be treated as a security update.
https://www.tp-link.com/us/support/download/omada-software-controller/

WinSCP 5.19.1 resolves several bugs. This is not a security update.
https://winscp.net/eng/index.php

Zoom 5.7.1.543 resolves several bugs. This is a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 2.0.16 adds snow, rain and fire effects, resolves several bugs. This is not a security update.
https://en.3tene.com/

darktable 3.6.0 adds several new features, resolves dozens of bugs and updates hardware support. This is not a security update.
https://www.darktable.org/install/

Flickr Downloadr 3.4.0.1 resolves several bugs and removes defunct platforms. This is not a security update.
https://flickrdownloadr.com/downloads/

Plex Media Server 1.23.4.4805 improves AAC encoding quality, hardware compatibility, play queueing specials and resolves several bugs. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

VLC Media Player 3.0.16 is a security update.
https://www.videolan.org/vlc/

Game Updates

These are unlikely to be of interest to most people.

PlayStation PS5 21.01-03.21.00 improves performance. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2021.07.13 resolves dozens of bugs. This is not a security update.
https://www.steampowered.com/platform/update_history/index.php?skin=0&id=0

Office Updates

One or more of these are likely to be of interest to most people.

Krita 4.4.5 resolves dozens of bugs. This should be treated as a security update.
https://krita.org/en/download/krita-desktop/

LibreOffice Fresh 7.1.4 resolves 80 bugs. This is a security update.
https://www.libreoffice.org/

Nextcloud Desktop 3.2.4 resolves several bugs. This is not a security update.
https://nextcloud.com/

Notepad++ 8.1.1 adds/improves dark mode, resolves performance and stability bugs. This is not a security update.
https://notepad-plus-plus.org/

Adobe Dimension 3.4.3 is a security update.
https://www.adobe.com/products/dimension.html

Adobe Illustrator 25.3 is a security update.
https://www.adobe.com/creativecloud/catalog/desktop.html

Adobe Framemaker 2019.8 and 2020.2 are security updates.
https://helpx.adobe.com/framemaker/kb/framemaker-downloads.html

Adobe Acrobat and Reader 2021.005.20058, 2020.004.30006, and 2017.011.30199 are security updates. Use Help, Check for Updates to install the most current version.

Adobe Bridge 11.1 is a security update.
https://www.adobe.com/in/products/bridge.html

Security Software Updates

One or more of these is likely to be of interest to most people.

Gpg4win 3.1.16 updates libraries and resolves several bugs. This is a security update.
https://www.gpg4win.org/download.html

Hashcat 6.2.2 improves automation, adds new hash-modes and resolves several bugs. This is not a security update.
https://hashcat.net/hashcat/#downloadlatest

RogueKiller 15.0.8 updates engine and resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

Tails 4.20 is a security update.
https://tails.boum.org/install/dvd-download/index.en.html

uBlock Origin 1.36.2 is a security update.
https://github.com/gorhill/uBlock/releases/latest

Capture Updates

These are unlikely to be of interest to most people.

ScreenToGif 2.32.1 resolves several bugs. This is not a security update.
https://github.com/NickeManarin/ScreenToGif/releases/latest

SnagIt 2021.4.2 resolves several bugs. This is not a security update.
https://download.techsmith.com/snagit/enu/snagit.exe

VideoCacheView 3.07 improves Firefox compatibility. This is not a security update.
https://www.nirsoft.net/utils/video_cache_view.html

Converter Updates

These are unlikely to be of interest to most people.

IsoBuster 4.8 adds ReFS support, dmg, adf, and hdf file support, metadata parsing, Amiga partitions, block range addressing and search support. This is not a security update.
https://www.isobuster.com/download.php

MakeMKV 1.16.4 improves decoding, compatibility, and resolves several bugs. This is not a security update.
https://www.makemkv.com/download/

Utility Updates

These are unlikely to be of interest to most people.

1Password for Mac 7.8.6 resolves several bugs. This is not a security update.
https://1password.com/downloads/mac/

1Password for Windows 7.7.810
https://1password.com/downloads/windows/

8GadgetPack 34.0 resolves several bugs and improves compatibility. This is not a security update.
https://8gadgetpack.net/

AccessChk 6.14 adds support for NULL DACL reporting. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/accesschk

Aomei Partition Assistant 9.3 adds option to create portable version, resolves an app mover bug. This is not a security update.
https://www.diskpart.com/

Bitwarden 1.27.1 resolves several bugs. This is not a security update.
https://bitwarden.com/

Dell Command Update 4.2.1 doesn’t provide a changelog. This should be treated as a security update.
https://www.dell.com/support/article/us/en/04/sln311129/dell-command-update?lang=en

DesktopOK 9.11 adds support for Windows 11. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

DevManView 1.75 adds support for sorting by menu. This is not a security update.
https://www.nirsoft.net/utils/device_manager_view.html

Everything Toolbar 0.7.1 improves keyboard support, added options and integration, and resolves several bugs. This is not a security update.
https://github.com/stnkl/EverythingToolbar/

Fido 1.20 adds Windows 7 ISO downloads. This is not a security update.
https://github.com/pbatard/Fido/releases

GoodSync 11.7.6 resolves several bugs. This is not a security update.
https://www.goodsync.com/

Homedale 1.97 resolves a bug. This is not a security update.
https://www.the-sz.com/products/homedale/

NetworkTrafficView 2.41 adds support for sorting by menu. This is not a security update.
https://www.nirsoft.net/utils/network_traffic_view.html

NTLite 2.1.2.8074 adds Windows 11 support and updates components. This is not a security update.
https://www.ntlite.com/download/

osquery 4.9.0 updates libraries, adds log rotation, improves table options, startup and shutdown time, and resolves other bugs. This is not a security update.
https://osquery.io/downloads

PointerStick 5.33 adds support for Windows 11. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

PowerToys 0.41.3 resolves stability issues. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

Process Monitor 3.83 resolves several bugs. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/procmon

RoboForm 9.1.5 resolves several bugs. This is not a security update.
https://www.roboform.com/

Strings 2.54 improves handling of files containing long strings. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/strings

Sysmon 13.22 improves performance and resolves a sub-rule bug. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon

TCPView 4.13 fixes a bug with connection state filtering. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/tcpview

TraceRouteOK 2.55 updates signature and languages. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/TraceRouteOK

USBDeview 3.02 improves high-DPI support and adds support for sorting by menu. This is not a security update.
https://www.nirsoft.net/utils/usb_devices_view.html

WinRAR 6.02 is a security update.
https://www.rarlab.com/

WinScan2PDF 7.22 adds Windows 11 support. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WizTree 4.01 adds several new filter features, multiple simultaneous drive support, performance improvements, and adds cosmetic options. This is not a security update.
https://wiztreefree.com/

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 4.2.2.0 resolves several bugs. This is not a security update.
https://developer.android.com/studio

Node.js 16.4.2 is a security update.
https://nodejs.org/en/

Node.js 12.22.3 is a security update.
https://nodejs.org/en/

Node.js 14.17.3 is a security update.
https://nodejs.org/en/

SQLite 3.36.0 improves EXPLAIN, BOM skipping, and resolves several bugs. This is not a security update.
https://www.sqlite.org/download.html

Visual Studio Code 1.58 resolves several bugs. This is not a security update.
https://code.visualstudio.com/

Web Package Updates

These are likely to be of interest only to web developers.

Dada Mail 11.14.1 updates libraries, adds limits to Forward to a Friend, and resolves several bugs. This is not a security update.
https://dadamailproject.com/

Docker Desktop 3.5.2 resolves several bugs. This is not a security update.
https://www.docker.com/products/docker-desktop

Drupal 9.2.1 resolves several bugs. This is not a security update.
https://drupal.org/download

MailEnable 10.35 is a security update.
https://www.mailenable.com/

Nextcloud Server 22.0.0 adds Circles support, integrates chat and tasks, approval workflows, PDF signing, and resolves over 600 bugs. This is not a security update.
https://nextcloud.com/

ScreenConnect 21.9.4007.7863 resolves several bugs. This is not a security update.
https://www.connectwise.com/software/control/download

Akismet 4.1.10 resolves several bugs and improve API requests. This is not a security update.

Conditional Widgets 3.1 announced their native incompatibility with WP 5.8+ and how to continue to use it. This is not a security update.

Duplicator 1.4.2 resolves several bugs and updates package diagnostics. This is not a security update.

myStickymenu 2.5.3 resolves several bugs. This is not a security update.

Visual Composer 37.0 resolves several bugs, improves compatibility, and adds user interface improvements. This is not a security update.

W3 Total Cache 2.1.5 is a security update.

WooCommerce 5.5.0 resolves dozens of bugs. This is not a security update.

WP Mail SMTP 2.9.0 adds scheduler, improved notifications, and resolves several bugs. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2021-03-09

Welcome back, Folks!

Today is Patch Tuesday for March, 2021.

This Month in Technology

Gab has been hacked at least a couple more times. (Would you trust the security of a Gab-owned bank?)

A new form of “supply-chain” attack demonstrating dependency vulnerabilities has been used against many major vendors, including Microsoft, Apple, Tesla, and dozens more.

32redAccellionAllergy PartnersAppleBombardierCA DMVClubhouse ChatsCovenant HealthCareCSXD-Link devices, Ecuador’s Ministry of Finance and Banco Pichincha, the European Banking AuthorityEXMOExperian (again), France’s Ministry of HealthGeorgetown County (SC), Hipcam (and other baby monitors), HumanaIBM, over a hundred Italian banksKeepChangeKiaKrogerLakehead UniversityMalaysia AirlinesNess Digital EngineeringNinja FormsNgrokNurseryCam, Oxford University, RealPage, RIPE NCC accountsRockwell Automation PLCsMaza, a Russian Cybercrime forum, SingtelSITA (an airline service provider), SolarCityPayPalQualysSendgrid accounts (to send spam – how could anyone tell the difference?!), Sequoia CapitalSignalT-Mobile, TMS, 15 UK schoolsUnderwriters LaboratoriesUniversal Health ServicesVMWare vCenter ServerWashington State Unemployment DepartmentWawa, Apple’s WebKit, and Yandex have been hacked.

According to a study by Bridewell Consulting, 86% of UK critical national infrastructure organizations have experienced cyber-attacks. I think it would be more accurate to present these numbers as, “14% of UKs critical national infrastructure doesn’t have the technology in place to know they were hacked.”

Even more malware related to the SolarWinds hack has been discovered. Since AWS was used for the SolarWinds hack, shouldn’t Amazon shut AWS down, too?

Microsoft is now admitting that Azure and Exchange source code has been compromised by the SolarWinds attackers.

The big news this month is that a vulnerability in Microsoft Exchange (coincidence?) has resulted in over thirty thousand servers being hackedThis is huge. So what did Microsoft do? Microsoft has announced it has changed their policy to crack down on hosted email accounts that receive a lot of email. Sigh.

Another interesting new tactic, bitsquatting, has proved far more effective than one would think. The demonstration allowed them to hijack thousands of requests intended for Microsoft. Used maliciously, this method will cause serious damage.

Censorship has finally made it before the Supreme Court, but Dr. Suess is only the latest target, while Facebook allowed actual genocide, but forbade discussion about news articles, Google acknowledges their efforts to perform censorship “better,” and Firefox has released a new extension to aid in censorship, while Streamlabs waited for the payment to clear before censoring one paid user. The Beverly Hills Police Department is using the novel approach of playing copyrighted music to prevent their actions from being observed, and Congress is now violating federal law by demanding censorship of media.

It amazes me that people actually trust “fact checkers.” Censorship doesn’t work!

Poland isn’t taking it anymore. Italy is fining Facebook, too.

Tor was hacked years ago, but new implementations (like that in Brave) are still popping up with their own problems.

Another 21 million VPN users were taught the lesson about the difference between customers and products. If you’re not the customer, you’re the product.

Instagram (like parent Facebook) is sharing everything you do with law enforcement. So is Apple’s iCloud.

The Windows 10 implementation of web fonts can be used to hack you. Apple M1 chips (less than 6 months old) have been targeted with several pieces of malware, but we should trust the MORPHEUS chip, right? BTW, M1 Macs are eating their (soldered in) SSDs, too.

It’s not just Google. Apple can disable all of your accounts and services on a whim, too. Or for your name.

Amazon has been caught duplicating products, can they be trusted to sell your products or host your content?

Is half a billion dollars enough to get you to rethink a bad user interface?

The whole point of unified interfaces and consistent logins is to ensure a familiar experience so you know whether you’re visiting the real site. Attackers take advantage of this to build their own imagekits and forms, even using their own fake security measures to convince you you’re on the “real” site since they are forced to validate that *you* are really you.

The malicious Gootkit Trojan can help the SEO of your websites. Just not for you.

Never reuse passwords. Or hard-code them. And don’t use obvious passwords either. But if you do, don’t blame a fabricated intern.

Apple claims that a new (available since 2019, but only recently launched on iOS) application execution technique will make it more difficult for iPhones to be hacked,
while yet another iPhone bug has demonstrated to successfully jailbreak every active iOS/iPhone line.

North Dakota and Arizona may save the Internet by forbidding the ability for vendors to force the use of their own app stores.

While many treat Google’s lockdown of their data APIs in Chromium as a bad thing, I see it as getting Google further out of Chromium – which can only be a net positive.

AT&T and Frontier have consistently abandoned phone networks in California, but we knew that: AT&T said they were going to do this when Title II passed. Sometimes the only thing to make a company following through is enough bad press.

Deepfakes for everyone! While most focus on Deepfakes are about their potential for evil, they can be used for good.

On patents: Intel owes $2.2 billion for saving power, and Apple has violated several biometric patents.

Dr. Fauci has known all along that the PCR test was useless. The WHO has launched their own COVID-specific version of “we investigated ourselves and found we did nothing wrong.” The dystopian concept of vaccine passports has been struck down by the Council of Europe. Unfortunately their power is mostly cosmetic.

The CDC inflated “COVID deaths” over 1600% in violation of multiple federal laws. CDS is real though. COVID has been “really good for CNN ratings,” though. Thousands of people have died in the US from the experimental COVID “vaccines,” (and elsewhere) or suffered from other harm. Many more internationally. Quarantine internment camps are a real thing. People are being harmed from the tests (or forcefully vaccinated), too. You can do something about it. (They sure won’t.) BTW, the CDC has had to remove their claim that vaccines don’t cause Autism.

Pennsylvania, New Mexico, and Texas have joined in on efforts to end lockdown insanity.

Don’t be selfishMasks still don’t work, but masks can kill you. (At least they won’t rape you.)

Keep the pedophile, but ban the words.

Green Energy killed Texas. It shouldn’t have been allowed to happen.

Governors Cuomo and Whitmer are finally being taken to task on their “accidental” murder of thousands of nursing home residents. Don’t expect the President to get involved. Genocide is just “different norms” to him. Instead of those in “National Security” investigating this, they’re convinced their time is better used calling half the population terrorists.

Facebook has had more than 20 million child sex abuse incidents, more than 20x greater than any other website, including Google. Nevertheless, the masses aren’t calling for cancelling Facebook. It’s tolerance when “they” do it.

Speaker Pelosi (who is responsible for security at the House) refused National Guard assistance, supposedly over “optics“, before the staged January 6riot“. Chris Wray lied to Congress about Antifa dressing as Trump supporters. So did former Deputy Attorney General Rod Rosenstein. They’ve knowingly falsified FISA warrants. So is it really any surprise there are calls to shut down the FBI?

Some states are finally allowing election audits, with evidence of 6% discrepancies in every single race, others as much as 78%, and other serious math problems, while others refuse to release ballots for inspection, purge election data, or allow the FBI to shred ballots without oversight or inspection. Then they poison the people they are forcing to guard them.

Is it any surprise that their Section 230 “reforms” are designed to completely silence online discourse? After all, the President doesn’t understand what “clandestine” means. (Quick tip: If you announce your intentions on the MSM, it’s not clandestine!)

The Babylon Bee is probably the best news site on the Internet, not because they actually have any news, but because they shine a light on the fraud that passes for news today.

Now for the good news:

California has finally been allowed to implement their own brand of Net Neutrality. I strongly oppose Net Neutrality, as getting government involved in something (even under the auspices of protection) always results in unintended consequences. This is, fortunately, no exception. CA Net Neutrality can now be used by myself and others to target Big Tech to penalize them for their continuous acts of censorship.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday this month is huge. The typical computer should see roughly 3 GB in updates today. Let’s get started.

Microsoft released updates for Windows, Edge, .NET, Servicing Stack, Internet Explorer, and MSRT (~2 GB). This includes security updates. A reboot is required.

Apple released updates for macOS Big Sur 11.2.3, watchOS 7.3.2, Safari 14.0.3, iOS 14.4.1 and iPadOS 14.4.1. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

iOS 14.4.1 is a security update. Use Settings, General, Software Update to install the most current update.

iPadOS 14.4.1 is a security update. Use Settings, General, Software Update to install the most current update.

watchOS 7.3.2 is a security update. Use the Watch app on your iPhone to install the most current version.

Google Chrome OS 88.0.4324.186 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Big Sur (11.0) means that macOS High Sierra (10.13) and older are no longer supported. If you can not install at least macOS Mojave (10.14) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (v2009) is huge (about 18% larger than v2004, which was 25% larger than any prior build) so will take a long time to download on slower connections. Windows 10 pushes you to get the latest Windows 10 release every 6 months and only supports any consumer builds for 18 months. If you don’t let it finish and you’re on a slow connection, this process kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

BullZip PDF Printer 12.2.0.2902 resolves several bugs. This is not a security update.
https://www.bullzip.com/products/pdf/info.php#download

Display Driver Uninstaller 18.0.3.7 improves cleanup and adds network path support. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

DirectX 9.29.1974.1 doesn’t provide a changelog, so should be treated as a security update.

nVidia 461.72 adds support for newer hardware and resolves several bugs. This is not a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.21.74 resolved several bugs. This is a security update.
https://brave.com/

Google Chrome 89.0.4389.82 is a security update.
https://www.google.com/chrome/

Microsoft Edge 89.0.774.48 is a security update.
https://www.microsoft.com/en-us/edge/business/download

Firefox 86.0 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 78.8.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Vivaldi 3.6.2165.40 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 78.8.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

Mumble 1.2.19 is a security update.
http://wiki.mumble.info/wiki/Main_Page

Prosody 0.11.8 is a security update.
https://prosody.im/download/start

Trillian 6.4.0.5 resolves a settings bug. This is not a security update.
https://www.trillian.im/

Dropbox 117.4.378 does not provide a changelog so should be treated like a security update.
https://www.dropbox.com/

FreeFileSync 11.8 resolves several bugs. This is not a security update.
https://www.freefilesync.org/download.php

Zoom 5.5.13142.0301 resolves several bugs, improves grid view, and better indicates when content is being shared. This is a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 2.0.12 adds 3 new types of motion, show/hide shortcut, and resolves several bugs. This is not a security update.
https://en.3tene.com/

Flickr Downloadr 3.3.4.1 updates the Docker image. This is not a security update.
https://flickrdownloadr.com/downloads/

Office Updates

One or more of these are likely to be of interest to most people.

Atom 1.55.0 allows git configuration without a repository. This is not a security update.
https://atom.io/

IcoFX 3.5.1 resolves several bugs. This is not a security update.
https://icofx.ro/

LibreOffice Fresh 7.1.1 resolves almost a hundred bugs. Remember that this is beta software, so should be avoided for the stable version whenever possible. This should be treated as a security update.
https://www.libreoffice.org/

Nextcloud Desktop 3.1.3 is a security update.
https://nextcloud.com/

Notepad++ 7.9.3 adds new folder features that now prevent it working on Windows XP. If you are still running XP you should really consider switching to Linux, but if you must continue to use XP then use Notepad++ 7.9.2. This is not a security update.
https://12pd.com/click?npp32

VideoCleaner 5.8 improves Matrix, Sharpening and Mask features. This is not a security update.
https://videocleaner.com/download.html

Adobe Connect 11.2 is a security update.
https://helpx.adobe.com/security/products/connect/apsb21-19.html

Adobe Creative Cloud Desktop Application 5.4 is a security update.
https://helpx.adobe.com/security/products/creative-cloud/apsb21-18.html

Adobe Framemaker 2020.0.2 is a security update.
https://helpx.adobe.com/security/products/framemaker/apsb21-14.html

Security Software Updates

One or more of these is likely to be of interest to most people.

Tails 4.16 is a security update.
https://tails.boum.org/install/dvd-download/index.en.html

OpenSSL 1.1.1j is a security update.
https://www.openssl.org/source/

RogueKiller 14.8.5 updates core and resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

Wireless Network Watcher 2.25 improved compatibility with high-DPI. This is not a security update.
https://www.nirsoft.net/utils/wireless_network_watcher.html

Capture Updates

These are unlikely to be of interest to most people.

VideoCacheView 3.06 adds support for the new cache partitioning structure in chromium-based browsers. This is not a security update.
https://www.nirsoft.net/utils/video_cache_view.html

Converter Updates

These are unlikely to be of interest to most people.

MakeMKV 1.16.1 resolves several bugs and adds ARM support. This is not a security update.
https://12pd.com/click?makemkv

Utility Updates

These are unlikely to be of interest to most people.

1Password for Mac 7.8 adds native M1 support and resolves dozens of bugs. This is a security update.
https://1password.com/downloads/mac/

1Password for Windows 7.6.793 improves performance and resolves several bugs. This is not a security update.
https://1password.com/downloads/windows/

CCleaner 5.77.8521 improves cleaning and resolves several bugs. This is a security update.
https://www.ccleaner.com/

ControlMyMonitor 1.28 improves compatibility with high DPI. This is not a security update.
https://www.nirsoft.net/utils/control_my_monitor.html

Coreinfo 3.52 adds reporting for CET (shadow stack). This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/coreinfo

Cygwin 3.1.7 resolves several bugs. This is not a security update.
https://cygwin.com/

Dell Command Update 4.1 is a security update.
https://www.dell.com/support/article/us/en/04/sln311129/dell-command-update?lang=en

DesktopOK 8.66 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

Eraser 6.2.0.2992 doesn’t provide a changelog so should be treated as a security update.
https://eraser.heidi.ie/download/

Everything Toolbar 0.6.2 adds an installer, drag & drop support, elevation support, and more. This is not a security update.
https://github.com/stnkl/EverythingToolbar/

Homedale 1.93 adds an option to set the gps baud rate from the command line. This is not a security update.
https://www.the-sz.com/products/homedale/

IsMyHdOK 3.01 resolves a bug in screenshot generation. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

NTLite 2.0.0.7820 resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

OSFMount 3.1.1000 updates drivers and improves CLI support. This is not a security update.
https://www.osforensics.com/tools/mount-disk-images.html

PointerStick 5.05 updates language files. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

QuickSetDNS 1.31 adds option to start hidden. This is not a security update.
https://www.nirsoft.net/utils/quick_set_dns.html

TeamViewer 15.15.5 was released. The TeamViewer release notes have been unavailable for months now, so while it might be a security update, it would be safer to remove TeamViewer until these issues are resolved.
https://www.teamviewer.com/en/download/windows/

TraceRouteOK 2.42 updates language files. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/TraceRouteOK

WinScan2PDF 6.91 adds support for multi-page TIF and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WizTree 3.37 improves compatibility, refresh behavior, and resolves several bugs. This is not a security update.
https://wiztreefree.com/

Developer Updates

These are unlikely to be of interest to most people.

AutoHotkey 1.1.33.05 resolves several bugs and improves compatibility. This is not a security update.
https://www.autohotkey.com/download/

Node.js 12.21.0 is a security update.
https://nodejs.org/en/

Node.js 14.16.0 is a security update.
https://nodejs.org/en/

Node.js 15.11.0 resolves dozens of bugs. This is a security update.
https://nodejs.org/en/

TortoiseSVN 1.14.1 resolves several bugs. This is not a security update.
https://tortoisesvn.net/downloads.html

Visual Studio Code 1.54 resolves an extension dependency bug. This is not a security update.
https://code.visualstudio.com/

Virtual Machine Updates

These are unlikely to be of interest to most people.

PPSSPP 1.11.3 resolves several bugs. This is not a security update.
https://ppsspp.org/downloads.html

Web Package Updates

These are likely to be of interest only to web developers.

Adminer 4.8.0 adds several new features and improves compatibility. This is not a security update.
https://www.adminer.org/en/

Docker Desktop 3.2.1 updates the Docker Engine. This is not a security update.
https://www.docker.com/products/docker-desktop

Drupal 9.1.5 resolves dozens of bugs. This is not a security update.
https://drupal.org/download

HumHub 1.8.0 adds a bunch of new features, improves permissions, brute force delays, style and administration improvements, and resolves several bugs. This is not a security update.
https://www.humhub.com/en/download

Joomla 3.9.25 is a security update.
https://www.joomla.org/

MailEnable 10.32 resolves several bugs and adds LDAP support. This is not a security update.
https://www.mailenable.com/

Nextcloud Server 21.0.0 improves performance (up to 10x!), collaboration, groupware and more. This is not a security update.
https://nextcloud.com/

OpenPetra 2021.02 adds several new features, improvements, and resolves bugs. This is not a security update.
https://www.openpetra.org/

phpList 3.6.1 improves short URLs, PHP8 support, and security improvements. This is a security update.
https://www.phplist.org/

phpMyAdmin 5.1.0 resolves several bugs, improves compatibility, and adds several new options. This is not a security update.
https://www.phpmyadmin.net/

ScreenConnect 21.3.2160.7699 resolves several bugs, renamed End to Delete, and improves compatibility. This is not a security update.
https://www.connectwise.com/software/control/download

YOURLS 1.8.1 improves IDN, UTF8, time zone, and PHP8 support, removes support for PHP 7.2, and resolves several bugs. This is not a security update.
https://yourls.org/

WordPress 5.7 resolves several bugs and adds a few new features, improving accessibility, and (finally) adding a feature to update HTTP to HTTPS links throughout your site when you switch to HTTPS. This is not a security update.
https://wordpress.org/

Akismet 4.1.9 improves handling of pingbacks in XML-RPC calls. This is not a security update.

BuddyPress 7.2.0 resolves several bugs. This is not a security update.

Conditional Widgets 3 improves translation support. This is not a security update.

Contact Form 7 5.4 adds Sendinblue support, updates libraries and improves reliability and compatibility. This is not a security update.

Social Post Feed 2.19 improves error handling and reporting, cleanup, resolves several bugs and updates libraries. This is not a security update.

myStickymenu 2.5.1 improves instructions and compatibility. This is not a security update.

Postie 1.9.55 improves compatibility and removes legacy image sizing feature. This is not a security update.

Really Simple CAPTCHA 2.1 improves hash comparison. This is not a security update.

W3 Total Cache 2.1.1 resolves several bugs and adds information links and ogg caching support. This is not a security update.

WooCommerce 5.1.0 is a major update. This version improves compatibility, localization, and resolves dozens of bugs. This is not a security update.

WordPress Zero Spam 5.0.9 resolves several bugs and improves spam detection. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2015-05-12

Hi, Folks!

It’s Patch Tuesday! It’s a pretty heavy load today, with several updates that require direct interaction. The typical computer should see roughly 400mb in updates. Let’s get started.

Microsoft released 24 updates to address issues in Windows, Internet Explorer, Microsoft Security Essentials, Silverlight, .NET, and Microsoft Office (~250mb). This includes security updates. A reboot is required.
http://update.microsoft.com/

Apple released updates for OS X, OS X Server, Safari, iCloud, RAW compatibility, and several drivers. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

Adobe Reader and Acrobat 11.0.11 are security updates. Since Adobe has released Adobe Acrobat DC the native update engine has become unreliable for 11.x versions. You may need to either switch to Adobe Acrobat DC or have significant patience to download the 11.0.11 update.

Adobe AIR 17.0.0.172 is a security update.
Win: https://12pd.com/click?air
Mac: https://12pd.com/click?airmac

Adobe Flash Player 17.0.0.188 is a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Display Driver Uninstaller 15.1.0.2 improves cleanup. This is not a security update.
http://www.wagnardmobile.com/DDU/

Browser Updates

One or more of these are likely to be of interest to everyone.

Google Chrome 42.0.2311.152 is a security update.

Firefox 38.0 is a security update. Use Help, About to install the most current version.

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 31.7.0 is a security update. Use Help, About to install the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

Dropbox 3.4.6 provides several bug fixes. This is not a security update.
https://12pd.com/click?dropbox

Evernote 5.8.6.7519 fixes several bugs, including crash and reliability. This is not a security update.

BrowsingHistoryView 1.69 corrects a bug parsing IE data on some platforms. This is not a security update.
http://www.nirsoft.net/utils/browsing_history_view.html

IPInfoOffline 1.41 corrects IP parsing issue. This is not a security update.
http://www.nirsoft.net/utils/ip_country_info_offline.html

Adobe Shockwave 12.1.8.158 is a security update. If you do not have Shockwave DO NOT install it now!
https://12pd.com/click?shockwave

Media Updates

These are unlikely to be of interest to most people.

CDBurnerXP 4.5.5.5571 is a security update.
https://12pd.com/click?cdbxp

Plex Media Server 0.9.12.1.1079 corrects several stability bugs. This is not a security update.
https://plex.tv/downloads/1/archive

VLC Media Player 2.2.1 is a security update.

Unreal Media Server 11.0 adds Live Channel a/v switching, rebroadcasting, and improved stability. This is not a security update.
http://www.umediaserver.net/umediaserver/download.html

Unreal Streaming Media Player 7.0 adds support for Live Channels, time-shifting, improves UMS over HTTPS, and improved buffering. This is not a security update.
http://www.umediaserver.net/umediaserver/download.html

Game Updates

These are unlikely to be of interest to most people.

PlayStation 2.51 is a stability update. This is not a security update.

Office Updates

One or more of these are likely to be of interest to most people.

Notepad++ 6.7.7 fixes a minor bug. This is not a security update.
https://12pd.com/click?npp

Security Software Updates

One or more of these is likely to be of interest to most people.

OpenSSL 1.0.2a is a security update.

Windows Defender Offline 20150430 is a security update.
http://windows.microsoft.com/en-us/windows/what-is-windows-defender-offline

DrWeb CureIt! 10.0.5 is a security update.
https://www.freedrweb.com/download+cureit+free/?lng=en

Avast! Home Edition 10.2.2218 improves stability and performance. This is not a security update.
http://www.avast.com/free-antivirus-download

MalwareBytes’ Anti-Malware 2.1.6 is a security update.
http://www.malwarebytes.org/products/malwarebytes_free

DNSQuerySniffer 1.45 adds the ability to capture queries from loopback address. This is not a security update.
http://www.nirsoft.net/utils/dns_query_sniffer.html

SmartSniff 2.17 added “Find in Upper Pane” option. This is not a security update.
http://www.nirsoft.net/utils/smsniff.html

Wireless Network Watcher 1.79 updates internal MAC address database. This is not a security update.
http://www.nirsoft.net/utils/wireless_network_watcher.html

RogueKiller 10.6.3 adds detections, fixes search bug, improves UI and other bug fixes. This is not a security update.
http://www.adlice.com/softwares/roguekiller/

MSRT 5.24 is a security update.
http://www.microsoft.com/en-us/download/malicious-software-removal-tool-details.aspx

Capture Updates

These are unlikely to be of interest to most people.

Greenshot 1.2.6.7 updates Picasa support and improves editor. This is not a security update.
http://sourceforge.net/projects/greenshot/

VideoCacheView 2.85 added the ability to scan only files within a configurable recent period. This is not a security update.
http://www.nirsoft.net/utils/video_cache_view.html

XSplit Gamecaster 2.2.1502.1751 improves YouTube Live support. This is not a security update.
http://www.xsplit.com/get/

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 9.1.9.9 updates encryption support, corrects more than 20 bugs. This is not a security update.
http://www.dvdfab.cn/download.htm

TEncoder 4.5.7 does not provide a changelog, so should be treated as a security update.
http://tencoder.sourceforge.net/

Utility Updates

These are unlikely to be of interest to most people.

GoodSync 9.9.20 improves performance and stability. This is not a security update.
https://12pd.com/click?goodsync

Bitcoin 0.10.1 is a bug fix. This is not a security update.
http://bitcoin.org/en/download

CintaNotes 2.8.6 fixes several bugs, including stability and sync issues. This is not a security update.
http://cintanotes.com/download

Cygwin 2.0.0 is a major update and bugfix release. This should be treated as a security update.
http://cygwin.com/

CrucialScanner 20150506 does not provide a changelog, so should be treated as a security update.
http://www.crucial.com/systemscanner/index.aspx

Process Hacker 2.34 provides several cosmetic and stability updates. This is not a security update.
http://processhacker.sourceforge.net/

TeamViewer 10.0.41459 provides several bug fixes. This is not a security update.
http://www.teamviewer.com/en/download/windows.aspx

FileLocator Pro 7.5.2092 corrects several bugs. This is not a security update.
http://www.mythicsoft.com/filelocatorpro/download

DiskSmartView 1.10 fixes a reliability bug. This is not a security update.
http://www.nirsoft.net/utils/disk_smart_view.html

FolderChangesView 1.71 corrects a deleted file bug. This is not a security update.
http://www.nirsoft.net/utils/folder_changes_view.html

Password Security Scanner 1.33 adds portable Firefox support. This is not a security update.
http://www.nirsoft.net/utils/password_security_scanner.html

USBDeview 2.42 adds the ability to view device capabilities. This is not a security update.
http://www.nirsoft.net/utils/usb_devices_view.html

WakeMeOnLan 1.71 updates the internal MAC address database. This is not a security update.
http://www.nirsoft.net/utils/wake_on_lan.html

WifiInfoView 1.80 adds the ability to determine maximum supported speed of 802.11ac networks. This is not a security update.
http://www.nirsoft.net/utils/wifi_information_view.html

CCleaner 5.05.5176 improves cleanup. This is not a security update.
https://12pd.com/click?ccleaner

Sysmon 3.0 improves process tracking and filters. This is not a security update.
http://sysinternals.com/

Autoruns 13.3 adds reporting of GP extension DLLs and adds target processes tracking. This is a security update.
http://sysinternals.com/

RegJump 1.1 adds the -c option to jump to the path stored in the copy/paste clipboard.
http://sysinternals.com/

WuInstall 2.3.5 fixes a cache reporting bug and improves inline documentation. This is not a security update.

Seagate HDD Diagnostics 1.4.0.2 does not provide a changelog, so should be treated as a security update.
http://knowledge.seagate.com/articles/en_US/FAQ/202435en

Web Package Updates

These are likely to be of interest only to web developers.

Coppermine Gallery 1.5.36 is a security update.
http://coppermine-gallery.net/

Dada Mail 8.0.2 is a bugfix release. This is not a security update.
http://dadamailproject.com/

ownCloud Client 1.8.1 provides a number of performance and reliability updates. This is a security update.
https://owncloud.org/install/

phpMyAdmin 4.4.6 corrects several bugs. This is not a security update.
http://www.phpmyadmin.net/home_page/news.php

Plupload 2.1.3 does not provide a changelog, so should be treated as a security update.
http://www.plupload.com/

TinyMCE 4.1.10 is a bugfix release. This is not a security update.
http://www.tinymce.com/download/download.php

Drupal 7.37 fixes several bugs. This is not a security update.
http://drupal.org/download

jQuery 1.11.3 and 2.1.4 fixes several bugs. This is not a security update.
http://jquery.com/download/

SMF 2.0.10 fixes several bugs. This is not a security update.
http://download.simplemachines.org/

WordPress 4.1.2 is the 4th security update in the last month. Update ASAP!

Autoptimize 1.9.4 is a compatibility bug fix. This is not a security update.

bbPress 2.5.7 improves URL output. This is not a security update.

BuddyPress 2.2.3.1 does not provide a changelog, so should be treated as a security update.

Conditional Widgets 2.2 fixes a number of bugs and adds hide on desktop/mobile support. This is not a security update.

Contact Form 7 4.1.2 adds div and quiz wrapper elements. This is not a security update.

Easy Bootstrap Shortcode 4.4.0 is a security update.

FV Top Level Categories 1.7 adds new translations. This is not a security update.

Postie 1.6.19 adds support for future posting and improves DAP LiveLinks compatibility. This is not a security update.

Raw HTML 1.4.15 fixes a minor bug. This is not a security update.

Redirection 2.3.15 fixes an admin bug. This is not a security update.

Theme My Login 6.3.12 is a security update.

WooCommerce 2.3.8 provides dozens of fixes, including style, hook and API updates. This is not a security update.

WPtouch 3.7.8 updates translations, fixes several bugs. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2014-09-16

Hi, Folks!

It’s catch-up Tuesday! A few vendors were not ready for updates last week, so delayed their security releases until today.

Apple released a security update for iTunes. This update will also be required to use iOS 8 which will be released later this week. Use Apple Software Update to install these updates. A reboot is required.

Adobe Reader 11.0.09 is a security update. Use Help, Check for Updates to install the latest version.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Display Driver Uninstaller 13.1.0.0 improves cleanup routine. This is not a security update.
http://www.wagnardmobile.com/DDU/

Browser Updates

One or more of these are likely to be of interest to everyone.

Firefox 32.0.1 is a security update. Use Help, About to install the most current version.

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 31.1.1 is a security update. Use Help, About to install the most current version.

OutlookAttachView 2.71 fixes a stability bug and adds new filename export variables. This is not a security update.
http://www.nirsoft.net/utils/outlook_attachment.html

Media Updates

These are unlikely to be of interest to most people.

CDBurnerXP 4.5.4.5067 improves disk detection and suggestions, fixes several bugs. Ths is not a security update.
http://cdburnerxp.se/

iTunes 11.4 is a security update. Use Apple Software Updater to install the most current version.

Game Updates

These are unlikely to be of interest to most people.

SteamOS 10-Sep-2014 is a security update.
http://store.steampowered.com/steamos/download/?ver=custom

Converter Updates

These are unlikely to be of interest to most people.

FFmpeg 2.4 updates libraries and fixes bugs. This is not a security update.
http://ffmpeg.org/download.html

DVDFab 9.1.6.8 adds support for new protections, new device output formats, improved hardware support and several other bugs. This is not a security update.
http://www.dvdfab.cn/download.htm

Utility Updates

These are unlikely to be of interest to most people.

GoodSync 9.9.7.8 improves performance, and fixes several crash bugs. This is not a security update.
https://12pd.com/click?goodsync

CintaNotes 2.7.2 simplifies sidebar, improves preferences, defaults and editor behavior. Fixes several bugs. This is not a security update.
http://cintanotes.com/download

TeamViewer 9.0.32494 simplifies interface, improves reboot behavior, and other bug fixes. This is not a security update.
http://www.teamviewer.com/en/download/windows.aspx

UpdateChecker 1.041 updates the icons and fixes several bugs. This is not a security update.
http://www.filehippo.com/updatechecker

Agent Ransack 2014.825 fixes a single-quote bug in XML UTF. This is not a security update.
http://mythicsoft.com/agentransack/download

Autoruns 12.03 fixes several bugs. This is not a security update.
http://sysinternals.com/

Process Explorer 16.04 fixes a bug in Virus Total submission and adds Windows Store package names. This is not a security update.
http://sysinternals.com/

Handle 4 now works with standard-user rights. This is not a security update.
http://sysinternals.com/

ProcDump 7.01 fixes several bugs. This is not a security update.
http://sysinternals.com/

RegJump 1.02 now works on 64-bit Windows. This is not a security update.
http://sysinternals.com/

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 4.3.16-95972 fixes a couple dozen bugs, including reliability, stability and performance issues. This is not a security update.
http://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

phpMyAdmin 4.0.10.3, 4.1.14.4 and 4.2.8.1 are security updates.
http://www.phpmyadmin.net/home_page/news.php

Dada Mail 7.2.1 improves message archives. This is not a security update.
http://dadamailproject.com/download/

Helicon Ape 3.1.0.139 fixes a wildcard warning bug. This is not a security update.
http://www.helicontech.com/ape/download.html

Autoptimize 1.9.1 fixes two bugs. This is not a security update.

BuddyPress 2.0.3 is a security update.

Conditional Widgets 2.0.5 works toward fixing strict warnings. DOES NOT update its own settings properly on multisite networks! This is not a security update.

Easy Bootstrap Shortcode 4.3.4 adds a shortcode for jumbotron. This is not a security update.

Multisite Enhancements 1.0.6 adds child theme display. This is not a security update.

WooCommerce 2.2.3 fixes over a dozen bugs and improves reliability for refunds. This is a security update.
That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/