Updates 2025-05-13

Welcome back, Folks!

Today is Patch Tuesday for May, 2025.

It’s as safe as it’s going to be to upgrade to Windows 11 24H2 or macOS 15/Sequoia.

If your Windows 10 (or older) computer can not be upgraded to Windows 11, or if you used a registry or installation bypass to install an older version of Windows 11 on it that is no longer supported, then it’s time for you to start looking for a replacement computer. Actually, the time was months ago. Pickin’s are thin right now. 🙁

However… if you do need to replace your laptop there’s an awesome Lenovo laptop available at Costco right now for $600 (plus tax & shipping).

There were 495+ major hacks, and over 600 application updates this month. It’s an insanely large month, with about 6 GB of updates for most users.

This Month in Technology

1st Health Inc, 30 London Job Centres, 4chan, 90 Degree Benefits, Inc – MN/WI Office, Abergavenny, Abilene, Texas, Active! Mail, Adelaide’s Women’s and Children’s Hospital, Adobe Acrobat Reader DC, Advanced Simulation Technology, Adyen, Agencia Browne y Espinoza, Ahold Delhaize, Alabama government, Alabama Ophthalmology Associates, Allegra, Allied Telesis, Inc, AllTrust, Alternate Solutions Health Network, Altior Healthcare, Alvin Independent School, Amazon ElastiCache, American Eagle Logistics, American Express Travel Related Services Co, Amethyst Group, Amtech Software, Andy Frain Services, Anfarm Hellas, Apache ActiveMQ, Apache Parquet, Apache Roller, Apache Tomcat, Apple AirPlay, Apple iPhone, Apple iPhone Messages, Apple macOS, Arizona Arthritis and Rheumatology Associates, Arkansas Primary Care, Ascension Health, Associated Wholesale Grocers, Astra Products, ASUS AiCloud, ASUS AMI, ASUS DriverHub, Avast Free Antivirus, Balance Diagnostics, Baltimore City Public Schools, Bangalore Water Supply and Sewerage Board (BWSSB), Barnstable County Sheriff’s Office, Barr Dermatopathology, Bartlesville Public Schools, BayMark Health Services, Bell Ambulance, Berkeley Research Group, Bertie, NC Schools, Bervar and Jones, Bigfork Valley Hospital, Bilbie Faraday Harrison, Bindi SpA, Bio-Clima Service, Bloom Family Eye Surgeons, Blue Shield of California (to Google!), Bluestone Bank, Bolivar Insulation, Boudreaux’s Specialty Compounding Pharmacy, Boulanger, Brainard Surgery Center LLC, British Columbia Health Authority, Broadcom Fabric OS, Brunswick Medical Center, Brydens Lawyers, Business Functions, Cabot Medical Care, California Correctional Health Care Services, Caltrol Inc, Cambridge University Press & Assessment, Canada Revenue Agency, CAPTCHA systems on 400,000+ websites (AkiraBot), Caritas Catholic charities, Carlton County Public Health and Human Services, Carrefour Mobile, Cato Networks Cato Client, Cell C, Central Texas Pediatric Orthopedics, Chang Shen Hospital, Charleston Fire Department, Chepstow, Chicano Federation of San Diego County, Cisco IOS XE, Cisco Webex, City of Bristol, TN, City of Grove, City of Long Beach, CA, Cloudera Hue Ace Editor, CMC Corporation, Co-op Group, Cobb County, GA, Colorado River Adventures, Community Dental Care, Commvault Command Center, Commvault, Complete Payroll SolutionsCompliance Consulting Group, Comport Technology Solutions, Conduent, Conrey Insurance Brokers & Risk Managers, Corporate Flight, Cortez Resources, Cosmos, Couples Learn, CPUs, Craft CMS, Culinary Services of America Inc, Curve Finance, Custom Paper, D’Granel, Dale Partners Architects, Dameron Hospital, Daniels & Taylor, PC, DaVita, six DDoS-for-hire platforms, Dedicated Web Consultants, DermCare Management, Destination Toronto, Diedrich Coffee, Dior, Discord, Disney, Dominion Lending Centres, Drug and Alcohol Treatment Services, Inc, Dutch Ministry of Climate Policy and Green Growth, Dutch Ministry of Economic Affairs, Dutch Ministry of the Interior and Kingdom Relations, DYNAMIS Insurance, East Central Missouri Behavioral Health Services, eCharge Hardy Barth, Eclipse ThreadX NetX Duo, ECOM America, Edinburgh schools, Ehlers Inc, EIZO Rugged Solutions, EMX Enterprises, Endue Software, Enflame Technology, Erlang/OTP SSH, Erlanger Health, ESP Associates, Esse Health, Everest Bank, eXch, Extreme Fire, Family Christian Health Center, Feldman & Lopez, Fleet Canada, Fogelman Management Group, Forsyth County Schools, 16,000 Fortinet devices, FortiSwitch, Fowler Elementary School District, Framlingham College, France’s Municipality of Ardon, Franklin Nursing Home, Frederick Health Medical Group, FreeType 2, Frisco Chamber, Galvatech, Gardena Honda, GeoLogics Corporation, German Association for East European Studies, Gistic Research, Gladinet CentreStack, Gladinet Triofox, Global Media Group, GlobalX, GMA Network, Google Chrome DevTools, Google Sites, Government of Peru, Great Plains Transport, GStreamer, Hacienda La Puente Unified School District, Hamilton County, TN, Hamrah Aval, Harman Becker MGU21, Harrods, Hayward Quartz Technology, HC Sheriff, HealthEquity, IncHeinz Hammer Vertragswerkstatt, Helix Tools, Hertz Corporation, Highland Rivers Behavioral Health, Hitachi Energy MicroSCADA Pro/X SYS600, Hong Kong Science and Technology Parks, HOPI, Horizon Behavioral Health, Hyalogic, Hyundai Motor Group, IBM Cloud, IBM Portal, iClicker, iHeartMedia + Entertainment, IKEA, Impact Canada, Inaba Denki Sangyo CHOCO TEI WATCHER, Independent Financial Services, Independent Title Agency, Indian Air Force (IAF) aircraft, Indian government defence websites, 1.5+ million Indian websites, Inductors Inc, Insight Partners, Insight Pipe Contracting, Interior Health, Internet Initiative Japan, Iowa County, WI, Iris ID, Isle of Man government, Ivanti Endpoint Manager, J. Banks Design, Jackpot Junction, Jacksonville Medical Care, James & Sons Fine Jewelers, Jamjoom Pharma, Janco Steel, Jani-King International, Inc, Jet Ice, Jordan Kuwait Bank, Ju Percussion Group, Julia Evans Accountants, Just Concrete & Masonry, Karachi Port Trust, Kasb Bank, Kaye Lifestyle Homes, Kelly & Associates Insurance Group, Kenworth Del Sur, Khan Academy, Kickidler, KiloEx, King Industries Inc, Kintetsu World Express, Kittrich Corporation, Korea Land and Housing Corporation, KraftKisarna, Kuala Lumpur International Airport, Kyiv Notaries, LabHost, Laboratory Services Cooperative, Lake HVAC, Lake Shore Paving, Lamberti Group, Landmark Admin, Langer & Langer, Langflow, Law Firm of Rochelle McCullough, Law Offices of Chris M. Ingram, Lee Valley Tools, Ltd, Legends International, Lemonade, Lexmark CX331adwe, Limestone District School Board, Lincoln Financial, Lithium Americas, LockBit Ransomware Group, Long Beach Convention and Entertainment Center, Loretto Hospital, Luxion KeyShot, Machu Picchu Foods, Madison School District, Magento, Malaysia Airports Holdings Berhad, Manchester Credit Union, Marc Irwin Sharfman, MD, PA, Marks & Spencer, Marsicovetere & Levine Law Group, Mashburn Construction, Masimo Corporation, Mataró Water Utility Company, MATE Desktop, McElwee Firm, MedDream PACS Server, MedDream WEB DICOM Viewer, MedEx Ambulance, Medical Express Ambulance Service, Megachem Singapore, Mercer County Joint Township Community Hospital, Merri-Makers, Microsoft 365 OAuth, Minyard Morris LLP, Mission Laguna Pathology Medical Group, Monongalia Health System, Mountain View Mushrooms, Movistar Venezuela, Mt. Baker Imaging and Northwest Radiologists, MTN Group, Munich Re, Municipality of Pisa, N8XT, Nagios Log Server, NASCAR, National Social Security Fund (CNSS) of Morocco, Nationwide Recovery Services, Nelson University, Neurological Institute of Savannah & Center for Spine, Nevada Ready Mix, New York Post, Newport Advisory, LLC, Nintendo, Nippon Life Mutual Fund, Nixon, Inc, North Kitsap School District, Northeast Georgia Health System, Northern California Children’s Therapy Center, Nova Scotia Power, Nth Degree, O’Brien & Ryan, OCH Regional Medical Center, Oettinger Brewery, Omni Healthcare Financial Holdings, OnRPG, Onsite Mammography, Oracle, Oracle VirtualBox, Orange County Medical Group Pathology, Oregon Department of Environmental Quality, Orthopaedic Specialists of Connecticut, OttoKit WordPress plugin, Output Messenger, Oversea Casing, Pacific Metallurgical, Palo Verde Hospital, Pawnee Heights Unified School District, Pearson, PESEL, Pharma Force, Pienaar Brothers, Planet Technology Industrial Switches, Planned Parenthood, Plastic Surgery Specialists of Lawrence, PlayStation, Port of Seattle, PR TIMES, Pratt Homes, Premier Meats South Africa, Prestonwood Baptist Church, Inc, Promenade Village Dental, Pryor Morrow, Pulse Urgent Care Center, Qraved, R&N Manufacturing, Radford University, Radware Cloud Web Application Firewall, Raw, Rayle Electric Membership Corporation, Red Chamber, RFID, Richmond СPA, Roblox, Rockwell Automation Industrial Data Center, Rocky View Schools, Roman Catholic Bishop of San Diego, Ruby Servers, Russell Child Development Center, Saint James Hospital Group, Sally B Gold, Salus Group, Samsung phones, Samsung Galaxy S24, Samsung Germany, Samsung MagicINFO 9 Server, San Francisco Campus for Jewish Living, San Francisco crosswalk system, Santa Cruz Properties, SAP NetWeaver, SavantCare, Scharnhorst Ast Kennard Griffin PC, Schultz Industries Inc, Scrubs & Beyond LLC, SeaCMS, Seneca Gaming, Sensata Technologies, Sentara Health, SentinelOne, Setpoint Systems, Seydel Companies, Shinko Shoji, Shopify, Shrader Law, Silgan Containers, SIMCO Electronics, Sinalisa Segurança Viária Ltda, SK Inc, SK Telecom, SogoTrade, Inc, SonicWALL Connect, SonicWall SMA, Sonos Era 300, Sonrisas Dental Health, South African Airways, South African IT, Southern Fidelity, Springer & Steinberg, St Anthony Hospital, St Clair Orthopaedics & Sports Medicine, St James Hospital, Study Hotels, Sunsweet Growers Inc, Sweet Shop USA, Synology BeeStation BST150-4T, Synology DiskStation DS1823xs+, Synology TC500, SysAid, T-Mobile, Takeda, TehetségKapu, TeleMessage, Tenda AC9, Tesla Model 3, Tesla Model S, Texas Health and Human Services Commission, The City of Long Beach, CA, The Fortune Society, The Michelson Organization, Thompson Coburn LLP, Thrive Physical Therapy Partners, TicketToCash, TikTok, TMA Group, Toppan Next, Toronto District School Board, Town of Orangeville, Traefik, Trend Micro Apex Central, Trend Micro Deep Security, Troicare College, True Dental Care for Kids and Adults, TrussWorks International, Tänzer GmbH, Ubiquity UniFi Protect Cameras, UK Department of Work and Pensions, UK Legal Aid Agency, Union Health System, Inc, UniTrak, Universal Window, Urban One, Urban Renewal Authority, US Claims Capital, Inc, US Office of the Comptroller of the Currency (OCC), Vanni and Humphrey, Vastaamo, VeriSource Services, Inc, Verrex, Versa Networks, Via Credit Union, Vicarage Court Solicitors, Victure RX1800, Virtuvian Health, Voigt-Abernathy Company, Wan Hai, Wazuh server, WDEF-TV, Webmin, Weil Construction, Weir Canyon Honda, West Lothian Council, Western New Mexico University, Western Sydney University, Whiteboard Technologies Pvt Ltd, Whitman County Public Hospital District No 3, Wilmington Personal Injury Lawyer – DPLAW, Windows Common Log File System, Windows NTLM hashes, Wisconsin Supreme Court, Wizz Air, Wolters Kluwer, WooCommerce, WordPress AIHub theme, WordPress BuddyBoss Platform Pro plugin, WordPress Flynax Bridge plugin, WordPress InstaWP Connect plugin, WordPress Smart Product Review plugin, WordPress UrbanGo Membership plugin, WorkComposer, WPM Pathology Laboratory, Chartered, XP Investimentos, XRP Ledger NPM Package (xrpl.js), Yale New Haven Health, Yankee Trails, Yodogawa Steel, Yokogawa Recorder, Young Consulting LLC, ZKsync, and Zoom remote control have reported hacking or compromises this month.

4chan, Atlassian Jira, Coinbase 2FA, Exchange Admin Center, Microsoft 365, and pretty much all of Spain (and some neighboring countries) less than a week after bragging about how they were finally able to run on 100% renewable energy, have suffered from outages this month.

By the way, did you know that 4chan was mostly run by the US government? Duh.

Last months updates broke
Broadcom Brocade Fabric OS, Classic Outlook calendar, Classic Outlook typing, Hitachi Vantara, Microsoft 365 “paste special”, Microsoft Entra ID, Microsoft Office, Microsoft Office 2016, Microsoft Outlook online, SAP NetWeaver, SharePoint Online, Windows 10 Start Menu, Windows 11 24H2 upgrades, Windows Domain Controllers, Windows Hello for Business (WHfB) Key Trust, Windows kernel, Windows Remote Desktop, Windows Server 2025, and the Win Recovery Environment (WinRE).

A Florida bill that would have required backdoors to any encryption for social media accounts has failed.

AT&T will be the first of the big telcos to drop their email-to-sms gateway – in only about a month. You’ll still be able to send emails to email addresses and text to and from cell numbers, but their gateway that allows you to send messages between email and text will be disabled in mid June. This should have a massive impact on the amount of spam received by AT&T mobile customers. It will not stop it, of course.

Broadcom is threatening to sue their own customers for installing security updates in VMware.

Your heated car seats (among other features) are exposing you to law enforcement tracking.

IPv6 makes MitM easy.

Kali Linux lost their repo signing key, requiring manual end-user intervention to install security updates.

CISA is “trimming the fat” by removing some of their communication methods (even though I’m sure they were fully automated). This is going to disrupt important intelligence resources for those in the tech industry.

Skype is dead. Microsoft will finally start killing off ActiveX in Office and Microsoft 365. All new Microsoft accounts will now be “passwordless” by default.

I’ve been warning about the Copilot AI storage access risks since they changed their Terms of Service in October. My fears were justified. Microsoft will no longer “accidentally” flag all Gmail messages as spamOr Adobe.

In the wake of a study that demonstrates how easy it was for AI to manipulate Reddit users, Reddit is considering legal action to protect their victims, I mean, users.

Android and Apple both now have auto-reboot to reduce the effectiveness of brute force attacks.

Apple is getting spanked for violating the letter and the intent of the judge’s order following the Apple v Epic Games lawsuit from a couple years ago.

BIG NEWS: US Attorney for the District of Columbia, Ed Martin, calls out Wikimedia Foundation (Wikipedia) for violating 501(c)(3) status by allowing propagandists to flood platform. He gave them until May 15th to turn over documents.

Google is finally consolidating all of it’s country TLDs to use “google.com“. Google will pay $1.4 billion to Texas to settle claims the company collected users’ data without permission. Google’s updated Local Services Ads Terms have sparked privacy fears and threaten confidentiality in medical and legal sectors. Google would never really harvest all of your medical data though, right? LOL.

Now for the good news:

T-Mobile has added satellite-based 5G support to their lineup. While currently in beta, this signals a huge improvement to coast to coast, and in fact world-wide, phone support using Starlink’s satellites to back up your 5G service when no towers are available (like when there’s a power outage or localized service issue or when you live in the middle of nowhere).

I suspect this mean Elon will soon be buying T-Mobile.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is insane this month. The typical computer should see roughly 6 GB in updates today. Let’s get started.

Microsoft released 48 updates to address 83 vulnerabilities in .NET, Active Directory Certificate Services, Azure, Azure Automation, Azure DevOps, Azure File Sync, Azure Storage Resource Provider, Build Tools for Visual Studio, Microsoft Brokering File System, Microsoft Dataverse, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Edge, Microsoft Office, Microsoft Office Excel, Microsoft Office Outlook, Microsoft Office PowerPoint, Microsoft Office SharePoint, Microsoft PC Manager, Microsoft Power Apps, Microsoft Scripting Engine, Remote Desktop Gateway Service, Universal Print Management Service, UrlMon, Visual Studio, Visual Studio Code, Web Threat Defense, Windows Ancillary Function Driver for WinSock, Windows Common Log File System Driver, Windows Deployment Services, Windows Drivers, Windows DWM, Windows File Server, Windows Fundamentals, Windows Hardware Lab Kit, Windows Hyper-V, Windows Installer, Windows Kernel, Windows LDAP, Windows Media, Windows NTFS, Windows Remote Desktop, Windows Routing and Remote Access Service, Windows Secure Kernel Mode, Windows SMB, Windows Trusted Runtime Interface Driver, Windows Virtual Machine Bus, Windows Win32K – GRFX, and MSRT. This includes security updates. A reboot is required.

Oracle released 378 security updates this quarter to address vulnerabilities in 117 products.

Apple released updates for macOS Sequoia 15.4.1, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, Safari 18.5, iOS 18.4.1, iOS 18.5, iPadOS 17.7.7, iPadOS 18.4.1, iPadOS 18.5, tvOS 18.4.1, tvOS 18.5, visionOS 2.4.1, visionOS 2.5, and watchOS 11.5. This includes security updates. Use Apple Software Update to install the most current versions.

iOS 18.4.1 and 18.5 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 17.7.7, 18.4.1 and 18.5 are security updates. Use Settings, General, Software Update to install the most current update.

watchOS 11.5 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 18.4.1 and 18.5 are security updates. Use System, Software Update to install the most current version.

visionOS 2.4.1 and 2.5 are security updates. Use System, Software Update to install the most current version.

Google ChromeOS 134.0.6998.198, ChromeOS 135.0.7049.120, and ChromeOS LTS 132.0.6834.223 are security updates. Use Menu, Help, About to install the most current version. A reboot is required.

Fedora 42.0 is a major update (leaning hard into “42”), with changes to the installer, updates to libraries, defaults and now offering COSMIC. This is not a security update.
https://getfedora.org/en/workstation/download/

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sequoia (15.x) means that macOS Monterey (12.x) and older are no longer supported. If you can not install at least macOS Ventura (13) on your Mac then you should immediately remove your device from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v24H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it. If not, switch to Linux (Mint is nice) or replace your computer.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with a SaferPC Subscription and we will install updates each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 25.5.1 adds support for newer hardware, improves performance and resolves several bugs. This is not a security update.
https://www.amd.com/en/support

Crucial Storage Executive 11.03 doesn’t provide a change log so should be treated as a security update.
https://www.crucial.com/support/storage-executive

Daemon Tools Lite 12.3.0 resolves several bugs. This is not a security update.
https://www.daemon-tools.cc/products/dtLite

GoXLR Utility 1.2.2 resolves several bugs. This is not a security update.
https://github.com/GoXLR-on-Linux/goxlr-utility/

Intel Driver and Support Assistant 25.2.15.9 is a security update.
https://www.intel.com/p/en_US/support/detect

UniFi Network Server 9.1.120 is a security update.
https://www.ui.com/download/releases/network-server

VIISAN OfficeCam 7.2.8.1 doesn’t provide a change log so should be treated as a security update.
https://www.viisan.com/en/download/type1.html

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.78.97 is a security update.
https://brave.com/

Google Chrome 136.0.7103.92 is a security update.
https://www.google.com/chrome/

Firefox 138.0.3 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 128.10.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Vivaldi 7.3.3635.12 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

OutlookAttachView 3.54 adds black background support. This is not a security update.
https://www.nirsoft.net/utils/outlook_attachment.html

Spark 3.22.9.106186 improves Team support and resolves a couple bugs. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.22.9.106183 improves Team support and resolves a couple bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 138.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 9.5.4 resolves several bugs. This should be treated as a security update.
https://anydesk.com/en/downloads

AnyDesk (macOS) 9.0.2 resolves several bugs. This should be treated as a security update.
https://anydesk.com/en/downloads

Discord May 1, 2025 resolves dozens of bugs. This is not a security update.
https://discord.com/download

Dropbox 223.4.4909 resolves several bugs. This is not a security update.
https://www.dropbox.com/

FileZilla Client 3.69.1 resolves several bugs. This is not a security update.
https://filezilla-project.org/

FileZilla Server 1.10.3 resolves several bugs. This is not a security update.
https://filezilla-project.org/

Google Drive 108.0 doesn’t provide a detailed change log so should be treated as a security update.
https://drive.google.com/start

MeshCentral 1.1.44 resolves dozens of bugs. This is not a security update.
https://meshcentral.com/info/downloads.html

Microsoft Teams 1.8.00.9760 improves GUI and resolves several bugs. This is not a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 31.0.4 resolves dozens of bugs. This should be treated as a security update.
https://nextcloud.com/

Nmap 7.97 is a security update.
https://nmap.org/

Npcap 1.82 resolves several bugs. This is not a security update.
https://nmap.org/npcap/

Pocketnet-Core 0.22.17 resolves several bugs. This is not a security update.
https://pocketnet.app/

Pocketnet-GUI 0.9.119 resolves several bugs. This is not a security update.
https://pocketnet.app/

Rclone 1.69.2 is a security update.
https://rclone.org/

Signal 7.53.0 adds new device attachment transfer and resolves several bugs. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.41.3 doesn’t provide a detailed change log so should be treated as a security update.
https://signal.org/android/apk/

Syncthing 1.29.6 resolves several bugs. This is not a security update.
https://syncthing.net/

Technitium DNS Server 13.6 resolves several bugs. This is not a security update.
https://technitium.com/dns/

Telegram 5.14.2 resolves a compatibility bug and adds marketplace sales. This is not a security update.
https://telegram.org/

WinSCP 6.5.1 resolves several bugs. This is not a security update.
https://winscp.net/eng/index.php

Zoom 6.4.6.64360 resolves several bugs. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.17 resolves several bugs. This is not a security update.
https://en.3tene.com/

Bitwig Studio 5.3.8 resolves a series of crash bugs. This is not a security update.
https://www.bitwig.com/download/

Grayjay 306 adds remote sync and resolves several bugs. This is not a security update.
https://grayjay.app/index.html

Plex Media Server 1.41.6.9685 adds DOVI filter and resolves several bugs. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.80.3 should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

Nintendo Switch 20.0.1 improves stability. This is not a security update.
https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/system%20updates/p/989

PS5 2025.429 adds audio focus and new themes. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2025.05.10 resolves several bugs. This is not a security update.
https://store.steampowered.com/news/app/593110

SteamOS SteamDeck Update 2025.05.06 improves compatibility, resolves several bugs, and updates libraries. This is not a security update.
https://store.steampowered.com/news/app/1675200/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Animate 23.0.12 and 24.0.9 are security updates.
https://helpx.adobe.com/security/products/animate/apsb25-42.html

Adobe Bridge 14.1.7 and 15.0.4 are security updates.
https://helpx.adobe.com/security/products/bridge/apsb25-44.html

Adobe ColdFusion 2021.20, 2023.14, and 2025.2 are security updates.
https://helpx.adobe.com/security/products/coldfusion/apsb25-52.html

Adobe Connect 12.9 is a security update.
https://helpx.adobe.com/security/products/connect/apsb25-36.html

Adobe Dimension 4.1.2 is a security update.
https://helpx.adobe.com/security/products/dimension/apsb25-45.html

Adobe Dreamweaver 21.5 is a security update.
https://helpx.adobe.com/security/products/dreamweaver/apsb25-35.html

Adobe Illustrator 28.7.6 and 29.4 are security updates.
https://helpx.adobe.com/security/products/illustrator/apsb25-43.html

Adobe InDesign 19.5.3 and 20.3 are security updates.
https://helpx.adobe.com/security/products/indesign/apsb25-37.html

Adobe Lightroom 8.3 is a security update.
https://helpx.adobe.com/security/products/lightroom/apsb25-29.html

Adobe Photoshop 25.12.3 and 26.6 are security updates.
https://helpx.adobe.com/security/products/photoshop/apsb25-40.html

Adobe Reader DC 25.001.20467 resolves several bugs. This is not a security update.
https://get.adobe.com/reader

Adobe Substance 3D Modeler 1.22.0 is a security update.
https://helpx.adobe.com/security/products/substance3d-modeler/apsb25-51.html

Adobe Substance 3D Painter 11.0.1 is a security update.
https://helpx.adobe.com/security/products/substance3d_painter/apsb25-38.html

Adobe Substance 3D Stager 3.1.2 is a security update.
https://helpx.adobe.com/security/products/substance3d_stager/apsb25-46.html

Artweaver 8.0.4 resolves several bugs. This is not a security update.
https://www.artweaver.de/

Calibre 8.4.0 resolves several bugs and improves compatibility. This is not a security update.
https://calibre-ebook.com/

Ghostscript 10.05.1 is a security update.
https://www.ghostscript.com/releases/gsdnld.html

Inkscape 1.4.2 resolves dozens of bugs. This is not a security update.
https://inkscape.org/release/

LibreOffice 24.8.7 resolves over a dozen bugs. This is not a security update.
https://www.libreoffice.org/

LibreOffice Fresh 25.2.3 resolves over sixty bugs. This is not a security update.
https://www.libreoffice.org/

Manager 25.5.8.2317 does not provide a detailed change log so should be treated as a security update.
https://www.manager.io/

Nextcloud Desktop 3.16.4 resolves several bugs. This is not a security update.
https://nextcloud.com/

Notepad++ 8.8.1 resolves over a dozen bugs and improves colorization. This is not a security update.
https://notepad-plus-plus.org/

PDF-XChange Editor 10.6.0.396 is a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

Scribus 1.6.4 resolves several bugs. This is not a security update.
https://www.scribus.net/

Operating System Updates

These are for specific Linux flavors and alternative operating systems and, sadly, are unlikely to be of interest to most people.

ChromeOS 134.0.6998.198 and ChromeOS 135.0.7049.120 are security updates.

Fedora 42.0 is a major update (leaning hard into “42”), with changes to the installer, updates to libraries, defaults and now offering COSMIC. This is not a security update.
https://getfedora.org/en/workstation/download/

iOS 18.4.1 and 18.5 are security updates.
https://support.apple.com/kb/HT204204

iPadOS 17.7.7, iPadOS 18.4.1, and iPadOS 18.5 are security updates.
https://support.apple.com/kb/HT204204

macOS Sequoia 15.4.1, macOS Sequoia 15.5, macOS Sonoma 14.7.6, and macOS Ventura 13.7.6 are security updates.
https://support.apple.com/kb/HT201541

Tails 6.14.2 and Tails 6.15 are security updates.
https://tails.net/install/download/index.en.html

tvOS 18.4.1 and tvOS 18.5 are security updates.
https://support.apple.com/kb/HT202716

visionOS 2.4.1 and visionOS 2.5 are security updates.
https://support.apple.com/en-us/122721

watchOS 11.5 is a security update.
https://support.apple.com/en-us/122722

Security Software Updates

One or more of these is likely to be of interest to most people.

FRSTx64 2025.5.9 doesn’t provide a detailed change log so should be treated as a security update.
https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/

HTTP Toolkit 1.20.1 doesn’t provide a detailed change log so should be treated as a security update.
https://httptoolkit.tech/

JShelter 0.20.2 improves privacy and resolves several bugs. This is not a security update.
https://jshelter.org/install/

MalwareBytes Desktop Security 5.3.0.186 resolves several bugs. This is not a security update.
https://www.malwarebytes.org/antimalware/

OpenSSL 3.5.0 is a security update.
https://slproweb.com/products/Win32OpenSSL.html

PassRec 3.65 updates included apps. This is not a security update.
https://www.nirsoft.net/password_recovery_tools.html

RogueKiller 16.1.3 resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

Stinger 13.0.0.347 adds and improves detections. This should be treated as a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

uBlock Origin 1.64.0 resolves a couple bugs and adds several new scriptlets and controls. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

WebBrowserPassView 2.15 adds support for app-bound encryption in recent Chrome releases. This is not a security update.
https://www.nirsoft.net/utils/web_browser_password.html

Capture Updates

These are unlikely to be of interest to most people.

Camtasia 25.1.1 resolves a startup crash. This is not a security update.
https://www.techsmith.com/video-editor.html

SnagIt 25.1.1 resolves several bugs and improves compatibility. This is not a security update.
https://www.techsmith.com/screen-capture.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.4.0 adds support for newer encodings and adds an AI upscaler. This is not a security update.
https://www.dvdfab.cn/download.htm

IsoBuster 5.6 adds support for new media formats, a new Preview mode, and resolves several bugs. This is not a security update.
https://www.isobuster.com/download.php

PDF Creator 6.0.0 is a major update, switching to newer libraries, adds document previews, SharePoint integration, and resolves a couple bugs. This is not a security update.
https://www.pdfforge.org/pdfcreator

StreamFab 6.2.3.5 improves compatibility, adds support to download from several new sources, and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 3.0.1.6 adds SDR and new output formats, resolves several bugs and improves subtitle and Face Enhancer. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.10.76 resolves a couple bugs and improves error messages.
https://1password.com/downloads/

Agent Ransack 2022.3517 improves favorites list, cosmetics and resolves several bugs. This is not a security update.
https://www.mythicsoft.com/agentransack/download/

Beyond Compare 5.0.7.30840 improves cosmetics, updates libraries, and resolves several bugs. This is not a security update.
https://www.scootersoftware.com/download

Bitwarden 2025.4.2 resolves several bugs. This is not a security update.
https://bitwarden.com/

CalyxOS Device Flasher 1.1.1 is a security upate.
https://calyxos.org/install/

CrucialScan 20250424 doesn’t provide a change log so should be treated as a security update.
https://www.crucial.com/store/systemscanner

Cygwin 3.6.1 resolves several bugs. This is not a security update.
https://cygwin.com/

DesktopOK 11.81 improves cosmetics. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.5.8.0 updates libraries. This is a security update.
https://dngrep.github.io/

Etcher 2.1.2 removes analytics. This is not a security update.
https://www.balena.io/etcher/

FileLocator Pro 2022.3517 improves favorites list, cosmetics and resolves several bugs. This is not a security update.
https://www.mythicsoft.com/filelocatorpro/download

FoneTool 3.0.0 is a major update that adds a new “My Devices” interface, improves iPhone to PC interface, and resolves a couple bugs. This is not a security update.
https://www.fonetool.com/download.html

Free Virtual Serial Ports 6.22.00.1498 resolves several bugs. This is not a security update.
https://freevirtualserialports.com/

GoodSync 12.8.8 improves compatibility and resolves several bugs. This is not a security update.
https://www.goodsync.com/

HWiNFO 8.26 improves hardware detection and reporting. This is not a security update.
https://www.hwinfo.com/download/

HWMonitor 1.57 adds support for newer hardware and resolves a couple bugs. This is not a security update.
https://www.cpuid.com/softwares/hwmonitor.html

Kingston SSD Manager 1.5.5.3 doesn’t provide a change log so should be treated as a security update.
https://www.kingston.com/us/support/technical/ssdmanager

NTLite 2025.04.10406 adds Power Plan integration support, improves registry writes, updates components and resolves a bug. This is not a security update.
https://www.ntlite.com/download/

OSForensics 11.1.1007 improves performance and resolves a couple bugs. This is not a security update.
https://www.osforensics.com/download.html

osquery 5.17.0 resolves over a dozen bugs and updates libraries. This is not a security update.
https://osquery.io/downloads

Password Security Scanner 1.63 adds support for app-bound passwords in recent Chrome releases. This is not a security update.
https://www.nirsoft.net/utils/password_security_scanner.html

PowerToys 0.90.1 resolves several bugs and updates libraries. This is a security update.
https://github.com/microsoft/PowerToys/releases/latest

RoboForm 9.6.8 improves update process and adds support for Google Workspace SSO. This is not a security update.
https://www.roboform.com/

Rufus 4.7 resolves several bugs and improves UEFI detection and download. This should be treated as a security update.
https://rufus.ie/en_US/

ScreenConnect 25.2.4.9229 is a security update. Updates were released for other “recent” versions as well so you’re not forced to upgrade to the Canary version that breaks several other features.
https://screenconnect.connectwise.com/download

SimpleWMIView 1.56 adds Black Background support. This is not a security update.
https://www.nirsoft.net/utils/simple_wmi_view.html

SmartMonTools 7.5 adds dozens of new diagnostic objects and reporting elements and improves reliability and performance. This is not a security update.
https://smartmontools.org/

Starwind V2V Converter 9.755 adds CLI conversion support. This is not a security update.
https://www.starwindsoftware.com/starwind-v2v-converter

SysinternalsSuite 2025.5.5 updates RDCMan. This is a security update.
https://docs.microsoft.com/en-us/sysinternals/

TeamViewer 15.65.6 resolves a bug. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/

WinGet 1.10.390 improves end-to-end support for Entra ID, configuration file controls, and resolves several bugs. This is a security update.
https://github.com/microsoft/winget-cli/releases/latest

WinScan2PDF 9.33 improves hardware support and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

XnConvert 1.105.0 doesn’t provide a change log so should be treated as a security update.
https://www.xnview.com/en/xnconvert/

ZoomText 2025 2025.2504.25.400 improves performance, multi-monitor support, and resolves several bugs.
https://support.freedomscientific.com/Downloads/ZoomText

Developer Updates

These are unlikely to be of interest to most people.

.NET Runtime 9.0.4 is a security update.
https://dotnet.microsoft.com/en-us/download/dotnet

ADB 36.0.0 resolves several bugs. This is not a security update.
https://developer.android.com/studio/releases/platform-tools

Android Studio 2024.3.2.14 resolves several bugs. This is not a security update.
https://developer.android.com/studio

cx_Freeze 8.3 updates libraries. This is not a security update.
https://cx-freeze.readthedocs.io/en/latest/index.html

GameMaker Studio 2024.13.1.193 resolves several bugs. This is not a security update.
https://www.yoyogames.com/en/gamemaker

GDevelop 5.5.230 resolves several bugs. This is not a security update.
https://gdevelop.io/download

GitHub Desktop 3.4.19 resolves over a dozen bugs. This is not a security update.
https://desktop.github.com/

Go 1.24.3 is a security update.
https://go.dev/

Inno Setup 6.4.3 improves restore operations, resolves seeral bugs, and adds a new tool for ECDSA P-256 support. This is not a security update.
https://www.jrsoftware.org/isdl.php

Java 8u451 is a security update.
https://www.java.com/en/download/manual.jsp

Node.js 20.19.1 updates libraries. This is not a security update.
https://nodejs.org/en/

Node.js 22.15.0 updates libraries and resolves several bugs. This is a security update.
https://nodejs.org/en/

Rustup 1.28.2 improves download stack and management controls. This is not a security update.
https://www.rust-lang.org/

SQLite 3.49.2 resolves several bugs. This should be treated as a security update.
https://www.sqlite.org/download.html

Visual Studio Code 1.100.1 is a security update.
https://code.visualstudio.com/

WinMerge 2.16.48.2 resolves several bugs. This is not a security update.
https://winmerge.org/

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 7.1.8 resolves over a dozen bugs. This is not a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

Adminer 5.3.0 resolves over a dozen bugs and improves compatibility. This is not a security update.
https://www.adminer.org/en/

Joomla 5.3.0 improves email templates, media management, scheduled tasks, read more, accessibility and compatibility. This is not a security update.
https://www.joomla.org/

YOURLS 1.10.1 resolves several bugs. This is not a security update.
https://yourls.org/

WordPress 6.8.1 resolves over a dozen bugs. This is not a security update.
https://wordpress.org/

bbPress 2.6.13 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/bbpress/

Contact Form 7 6.0.6 is a security update.
https://wordpress.org/extend/plugins/contact-form-7/

My Sticky Bar 2.8.1 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/mystickymenu/

Show IDs 1.1.11 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/wpsite-show-ids/

Sucuri Security 2.1 resolves a couple bugs and adds support for several new scanners. This is not a security update.
https://wordpress.org/extend/plugins/sucuri-scanner/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

 

Updates 2025-04-08

Happy Easter, Folks!

Today is Patch Tuesday for April, 2025.

It’s as safe as it’s going to be to upgrade to Windows 11 24H2 or macOS 15/Sequoia.

If your Windows 10 (or older) computer can not be upgraded to Windows 11, or if you used a registry or installation bypass to install an older version of Windows 11 on it that is no longer supported, then it’s time for you to start looking for a replacement computer. Actually, the time was 3 months ago. Pickin’s are thin right now. 🙁

There were 320+ major hacks, and over 360 application updates this month. It’s a relatively small month, with about 2.5 GB of updates for most users.

This Month in Technology

13cabs, 9,300 WordPress websites (ClearFake), 150,000 WordPress websites (DollyWay), 70mai A510, Abracadabra, Access TeleCare, Adobe Acrobat Reader, ALN Medical Management, Amazon AWS CloudFormation, AMI MegaRAC, an Asian telecom, Android, Apache Parquet, Apache Pinot, Apache Tomcat, APIsec, Apple macOS, Apple Passwords app, Apple WebKit, Arista NG Firewall, Around the Clock Companies, Arts Council England, Ascoma Group, Association of Superannuation Funds of Australia, Astral Foods, Atlantis Operating LLC, Atlas CPAs & Advisors, Atutech, AustralianSuper, Autodesk AutoCAD, Autodesk Navisworks, Autodesk Payapps, Baidu, Bank of China, Barebox, Baylor Scott & White Texas Spine & Joint Hospital, Bdrive NetDrive, BDSM People, Beacon Health System, BEC Technologies Routers, Bigfork Valley Hospital, Blue Shield of California, Boulanger, Brave browser, Brish, Brocade Fibre Channel switches, BTS member Jungkook, Buckinghamshire Council, Bybit, California Cryobank, Canon printers, Capilano University (CapU), Cardiff City Council Department of Children’s Services, Cargills Bank, CarlinKit CPC200-CCPA, CDHA Management, Center for Digestive Health, CHC Solutions, Inc, Check Point, Check Point ZoneAlarm, Cherokee County School District, Chica, Choco Tei Camera, Chord Specialty Dental Partners, Chrome, Cisco IOS XR, Cisco Smart Licensing Utility, City of Lubbock, Ciuni & Panichi, Clinic’s Patient Management System, Cloudflare WAF, Columbia Eye Clinic, Compumedics, Concord Orthopaedics, Costa Rican President’s YouTube, Cottrill’s Pharmacy, Crossroads Trading Co, CrushFTP, CSG Consultants, D&S Insurance Agency, Dameron Hospital, DBS Signapore, Dell Unity, Dignity Health Lassen Medical Clinic, Dove Healthcare, DrayTek routers, Drugs.com, Dutch Public Prosecution Service, Edimax Cameras, El Camino Real Academy, Eprice, Erickson Companies, ESET security, ESHYFT, Europcar Mobility Group, Everest ransomware gang, Exim, Facebook FreeType 2, FacePass, Fidelity Life, First City Credit Union, Food For The Poor, Fortinet FortiWeb, French Department of Education, Gay Daddy, Georgia Urology, German Doner Kebab, Gilead Sciences, GIMP, GitLab Community Edition, GitLab Enterprise Edition, Google Quick Share, Grede Holdings, Growatt, GRUB2, Guardian Life Insurance, Hamilton County, Hand & Plastic Surgery Centre, Harcourts Prime Properties, Health NZ, HealthEquity, Hellenic Open University, HHH Acquisition, LLC, Highline Public Schools, Hillcrest Convalescent Center, Hokkaido Jalan, Houston Housing Authority, Houston Surgery Center, HTW Dresden, Hydro-Vacuum SA, ImagineX, Infosys McCamish Systems, Insignia, IOU Financial, Iraqi Council of Ministers, Iraqi Ministry of Finance, Islamic Republic of Iran Shipping Company, Ivanti Connect Secure, Jaguar Land Rover, Jira, Junos OS, Karl Malone Auto Group, Keeco Home, Klickitat Valley Health, Korea Aerospace Research Institute, Kronick Moskovitz Tiedemann & Girard, Kuala Lumpur Airport, Kubernetes Ingress Nginx Controller, LA Financial Federal Credit Union, Laborers’ International Union of North America, Local 1184, Lafayette Federal Credit Union, Lake Psychological Services, Lake Washington Vascular, Lee University, Legacy Professionals LLP, Lena Pope Home Inc, LensDeal, Lexipol, Life University, LiUNA, Lloyds Bank, Lukoil, Luxion KeyShot, Lyon Living, Lyon Management Group, M.A.D Mobile, Madison County, Mississippi, Malaysia Airports Holdings Bhd, Marina Bay Sands Singapore, Mark Thomas, Medway Community Healthcare, Meigs County Emergency Medical Services, MercadoLibre, Mercer County Joint Township Community Hospital, Merkur, Microsoft Exchange Online and M365, Microsoft SharePoint, Microsoft’s Trusted Signing platform, Microsoft’s Visual Studio Code Marketplace, Millennium Home Health Care, Mirror Mirror Beauty Boutique, Mission Bell Mfg, Mission, Texas, Monro, Inc, Morton Golf LLC, mySCADA myPRO, NAKIVO Backup & Replication, National Defense Corporation, National Iranian Tanker Company, NetApp SnapCenter, Nevro, New Era Life Insurance Companies, New South Wales Court Registry, New York University (NYU), NewAgeSys, NexOpt, Next.js, NI FlexLogger, NI Vision Builder AI, Nice Healthcare, Northern Ireland Commission, Northwest Retirement Plan Consultants, NTT, Numotion, NVIDIA Riva, OBI Seafoods, Oracle Cloud (from 2017!), Oracle Health, OrthoMinds, Pacific Residential Mortgage, Palmetto Subacute Care Center, Palo Alto Deep Packet Inspection, PAR Rehab, Parascript, Parcel Plus, PDF-XChange Editor, Pennsylvania State Education Association, pgAdmin, Pinehurst Radiology Consultants, Pineland Community Service Board, Pink, Port of Seattle, Presbyterian Health Plan, Progress Software Kemp LoadMaster, PTS News, Rakuten Securities, RansomHub, Red Lion Borough, PA, Rinehart Dentistry, Riverdale Joint Unified School District, Rodl Management, Royal Mail, SAG-AFTRA Health Plan, Sam’s Club, Samsung Germany, Sentara Health, Shopify Collabs, Shopify Pitchfork, Siegel Group, Siemens Simcenter, SimonMed, SIR.trading, SMA, Smart ERP Solutions, SoloPoint Solutions, Southeast Series of Lockton Companies, Spark DSO, SpotBugs, SpyX, St. Joseph’s College of Maine, State Bar of Texas, State of California, Department of Child Support Services, STE Group, STMicroelectronics X-CUBE, Stram Center for Integrative Medicine, StreamElements, Sungrow, Sydney Tools, Tata AIG, Tata Technologies, Tesla, TFE hotels group, Thailand Post, The Junction Casino Hotel, The Pension Specialist, Three Rivers Hospital, Toppan Next Tech, Topy America Inc, Tor Browser, Translove, Trend Micro Cleaner One, Trinity Petroleum Management, Troy Hunt’s Mailchimp List, Twilio SendGrid, Twitter (X), U-Boot, UAE Water & Electric Power, Ubuntu Linux, Ukrzaliznytsia, Ulrich Investment Consultants, Union County, United Domestic Workers of America, United Faith Ministries, United Seating and Mobility, Unitree Go1 robot dogs, University Diagnostic Medical Imaging, University of Notre Dame Fremantle, Urban Dictionary, Verizon Call Filter, VF Outdoor, Virginia Attorney General’s Office, Vista Point Mortgage, Vitenas Cosmetic Surgery, VMware Tools for Windows, Vroom, Watcher Guru, Welts, White, & Fontaine, WEMIX, Wesizwe, Western Alliance Bank, Western Wayne Family Physicians, WhatsApp, Whitman Hospital & Medical Clinics, WideOpenWest, William F Rinehart DMD PA, Windows, Windows Kernel, WinRAR, WK Kellogg Co, Woori Card, Word & Brown Insurance Administrators, WordPress Simple WP Events plugin, WordPress WooCommerce plugin, WordPress WP Ghost plugin, WordPress WP RealEstate plugin, WordPress WP Ultimate CSV Importer plugin, X.Org Server, Xen HVM, YAP Health Services, Yucatán Government, ushin America, zkLend hacker (lol), and Zoth Protocol have reported hacking or compromises this month.

ChatGPT, Cloudflare R2, DrayTek routers, Microsoft Exchange Online, Moscow Metro, and Naval Station Norfolk have suffered from outages this month.

Last months updates broke Microsoft Snipping Tool, Remote Desktop, security services including SenseShield on Windows 11 24H2, the ability to return to Outlook “Classic”, USB printers, Veeam recovery, and VMware Workstation updates.

23andMe has filed for bankruptcy, but not before they created plans to sell off all your DNA details.

Apple broke their N+2 trend and released security updates for much older devices to address critical vulnerabilities.

DoH (DNS over HTTPS) is being used to hijack mail accounts with extremely well-targeted phishing pages. How effective are phishing websites? Effective enough to get even the creator of Have I Beep Pwned to fall for it.

Microsoft has changed their mind on disabling WSUS driver sync. Microsoft is testing a new “quick machine recovery” platform to recover from buggy driver updates preventing the operating system from booting. Microsoft is removing the BypassNRO script from Windows 11 installers, but the underlying registry settings will still be available (for now).

Now for the good news:

Linux is making headway – more than 2% of devices running Steam are now actively using Linux.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is relatively small this month. The typical computer should see roughly 2.5 GB in updates today. Let’s get started.

Microsoft released 78 updates to address 128 vulnerabilities in Active Directory Certificate Services, Active Directory Domain Services, ASP.NET Core, Azure Local, Azure Local Cluster, Azure Portal Windows Admin Center, DirectX Graphics Kernel, HTTP.sys, Kerberos Key Distribution Proxy, Microsoft AutoUpdate (MAU), Microsoft Dynamics Business Central, Microsoft Edge, Microsoft Edge for iOS, Microsoft Excel, Microsoft Message Queuing (MSMQ), Microsoft Office, Microsoft Office Excel, Microsoft Office OneNote, Microsoft Office SharePoint, Microsoft Office Word, Microsoft OneNote, Microsoft SharePoint, Microsoft Streaming Service, Microsoft System Center, Microsoft Virtual Hard Drive, Microsoft Word, OpenSSH for Windows, Outlook for Android, Remote Desktop Client, Remote Desktop Gateway Service, RPC Endpoint Mapper Service, Servicing Stack Updates, Visual Studio, Visual Studio Code, Visual Studio Tools, Windows Active Directory Certificate Services, Windows BitLocker, Windows Bluetooth Service, Windows Common Log File System Driver, Windows Cryptographic Services, Windows Defender Application Control (WDAC), Windows Digital Media, Windows Hello, Windows Hyper-V, Windows Installer, Windows Kerberos, Windows Kernel, Windows Kernel Memory, Windows Kernel-Mode Drivers, Windows Lightweight Directory Access Protocol (LDAP), Windows Local Security Authority (LSA), Windows Local Session Manager (LSM), Windows Mark of the Web (MOTW), Windows Media, Windows Mobile Broadband, Windows NTFS, Windows Power Dependency Coordinator, Windows Process Activation, Windows Remote Desktop Services, Windows Resilient File System (ReFS), Windows Routing and Remote Access Service (RRAS), Windows Secure Channel, Windows Security Zone Mapping, Windows Shell, Windows Standards-Based Storage Management Service, Windows Subsystem for Linux, Windows TCP/IP, Windows Telephony Service, Windows Universal Plug and Play (UPnP) Device Host, Windows Update Stack, Windows upnphost.dll, Windows USB Print Driver, Windows Virtualization-Based Security (VBS) Enclave, Windows Win32K – GRFX, and MSRT. This includes security updates. A reboot is required.

Apple released updates for iOS 15.8.4, iOS 16.7.11, iOS 18.4, iPadOS 15.8.4, iPadOS 16.7.11, iPadOS 17.7.6, iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, Safari 18.4, tvOS 18.4, visionOS 2.4, watchOS 11.4, and Xcode 16.3. This includes security updates. Use Apple Software Update to install the most current versions.

iOS 15.8.4, 16.7.11, and 18.4 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 15.8.4, 16.7.11, 17.7.6, and 18.4 are security updates. Use Settings, General, Software Update to install the most current update.

watchOS 11.4 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 18.4 is a security update. Use System, Software Update to install the most current version.

visionOS 2.4 is a security update. Use System, Software Update to install the most current version.

Google ChromeOS 134.0.6998.183 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sequoia (15.x) means that macOS Monterey (12.x) and older are no longer supported. If you can not install at least macOS Ventura (13) on your Mac then you should immediately remove your device from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v24H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it. If not, switch to Linux (Mint is nice) or replace your computer.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with a SaferPC Subscription and we will install updates each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

GoXLR Utility 1.2.0 resolves several bugs and improves firmware update. This is not a security update.
https://github.com/GoXLR-on-Linux/goxlr-utility/

Logitech Options 10.24.3 improves compatibility with Microsoft Office. This is not a security update.
https://support.logi.com/hc/en-us/articles/360025297893

TP-Link Archer AX73 v2.0 250210 is a security update.
https://www.tp-link.com/us/support/download/archer-ax73/v2.0/#Firmware

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.77.95 is a security update.
https://brave.com/

Firefox 137.0.1 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 128.9.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Google Chrome 135.0.7049.52 is a security update.
https://www.google.com/chrome/

Vivaldi 7.3.3635.7 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Spark 3.22.6.104601 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.22.6.104600 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 137.0.1 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 9.5.0 resolves more than a dozen bugs and improves multiple monitor support and AnyDeskOne compatibility. This is not a security update.
https://anydesk.com/en/downloads

AnyDesk (macOS) 9.0.1 is a security update.
https://anydesk.com/en/downloads

BrowsingHistoryView 2.60 adds black background support. This is not a security update.
https://www.nirsoft.net/utils/browsing_history_view.html

curl 8.13.0 improves debugging and resolves nearly 300 bugs. This should be treated as a security update.
https://curl.haxx.se/windows/

Discord April 3, 2025 resolves dozens of bugs. This is not a security update.
https://discord.com/download

Dropbox 221.4.5365 resolves a cosmetic bug. This is not a security update.
https://www.dropbox.com/

FileZilla Server 1.10.1 resolves several bugs. This is not a security update.
https://filezilla-project.org/

FreeFileSync 14.3 adds IDN support and resolves several bugs. This is not a security update.
https://www.freefilesync.org/download.php

Google Drive 106.0 now officially supports ARM64 on Windows. This is not a security update.
https://drive.google.com/start

Grocy Desktop 2.14.0 improves compatibility. This is not a security update.
https://github.com/grocy/grocy-desktop

MeshCentral 1.1.43 resolves several bugs. This is not a security update.
https://meshcentral.com/info/downloads.html

Microsoft Teams 1.8.00.6262 adds one-time passcode authentication, Storyline integration, chat controls and increases attendees to a max of 50,000 for Premium. This is not a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 31.0.2 updates libraries and resolves dozens of bugs. This is not a security update.
https://nextcloud.com/

Pocketnet-Core 0.22.14  resolves several bugs. This is not a security update.
https://pocketnet.app/

Pocketnet-GUI 0.9.116 is a security update.
https://pocketnet.app/

Signal 7.49.0 now synchronizes recent activity to new devices. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.38.7 now synchronizes recent activity to new devices. This is not a security update.
https://signal.org/android/apk/

Syncthing 1.29.4 resolves a couple bugs. This is not a security update.
https://syncthing.net/

Technitium DNS Server 13.5  resolves several bugs and implements new features. This is not a security update.
https://technitium.com/dns/

Telegram 5.13.1 resolves a crash bug. This is not a security update.
https://telegram.org/

WinSCP 6.5 resolves several bugs. This is not a security update.
https://winscp.net/eng/index.php

Zoom 6.4.3.63669 resolves several bugs. This is not a security update. The recent 6.4 update adds dozens of new features and a new user interface – it is also a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.16 adds several new 3D environments. This is not a security update.
https://en.3tene.com/

Grayjay 291 adds search and sorting to playlists, improves filters and search, and resolves several bugs. This is not a security update.
https://grayjay.app/index.html

iTunes 12.13.7.1 improves compatibility. This is a security update.
https://www.apple.com/itunes/download/

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.72.01 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

Minecraft Server (Java) 1.21.5 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server

PS5 2025.314 improves compatibility and parental controls. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2025.04.01 improves compatibility and resolves several bugs. This is not a security update.
https://store.steampowered.com/news/app/593110

SteamOS SteamDeck Update 2025.03.31 improves compatibility and resolves several bugs. This is not a security update.
https://store.steampowered.com/news/app/1675200/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe AEM Forms 6.5.22.0 is a security update.
https://helpx.adobe.com/security/products/aem-forms/apsb25-27.html

Adobe AEM Screens 6.5 FP11.4 is a security update.
https://helpx.adobe.com/security/products/aem-screens/apsb25-32.html

Adobe After Effects 24.6.5 and 25.2 are security updates.
https://helpx.adobe.com/security/products/after_effects/apsb25-23.html

Adobe Animate 23.0.11 and 24.0.8 are security updates.
https://helpx.adobe.com/security/products/animate/apsb25-31.html

Adobe Bridge 14.1.6 and 15.0.3 are security updates.
https://helpx.adobe.com/security/products/bridge/apsb25-25.html

Adobe ColdFusion 2025.1, 2023.13 and 2021.19 are security updates.
https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html

Adobe Commerce B2B 1.5.2, 1.4.2-p5, 1.3.5-p10, 1.3.4-p12, and 1.3.3-p13 are security updates.
https://helpx.adobe.com/security/products/magento/apsb25-26.html

Adobe Commerce 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, and 2.4.4-p13 are security updates.
https://helpx.adobe.com/security/products/magento/apsb25-26.html

Adobe FrameMaker 2020.8 and 2022.6 are security updates.
https://helpx.adobe.com/security/products/framemaker/apsb25-33.html

Adobe Magento Open Source 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, and 2.4.4-p13 are security updates.
https://helpx.adobe.com/security/products/magento/apsb25-26.html

Adobe Media Encoder 24.6.5 and 25.2 are security updates.
https://helpx.adobe.com/security/products/media-encoder/apsb25-24.html

Adobe Photoshop 26.5 and 25.12.2 are security updates.
https://helpx.adobe.com/security/products/photoshop/apsb25-30.html

Adobe Premiere Pro 25.2 and 24.6.5 are security updates.
https://helpx.adobe.com/security/products/premiere_pro/apsb25-28.html

Adobe XMP Toolkit SDK 2025.03 is a security update.
https://helpx.adobe.com/security/products/xmpcore/apsb25-34.html

Aronium 1.45.0.1 resolves a bug in the Z report. This is not a security update.
https://aronium.com/

Artweaver 7.0.18 is a security update.
https://www.artweaver.de/

Audacity 3.7.3 resolves several bugs. This is not a security update.
https://www.audacityteam.org/download/

Calibre 8.2.1 improves compatibility and resolves a couple bugs. This is not a security update.
https://calibre-ebook.com/

Ghostscript 10.05.0 adds several new syntax controls. This is a security update.
https://www.ghostscript.com/releases/gsdnld.html

GIMP 3.0 is a major update (the first in 7 years!) which adds huge strides in many features and improves compatibility and stability. GIMP 3.0.2 resolves several bugs. This is not a security update.
https://www.gimp.org/

GnuCash 5.11 resolves almost 20 bugs and improves stability. This is not a security update.
https://www.gnucash.org/

LibreOffice 24.8.6 resolves over 30 bugs. This is not a security update.
https://www.libreoffice.org/

LibreOffice Fresh 25.2.2 resolves over 80 bugs. This is a security update.
https://www.libreoffice.org/

Manager 25.4.3.2227 doesn’t provide a detailed change log so should be treated as a security update.
https://www.manager.io/

Nextcloud Desktop 3.16.2 resolves several bugs. This is not a security update.
https://nextcloud.com/

Notepad++ 8.7.9 resolves several bugs. This is not a security update.
https://notepad-plus-plus.org/

Paint.net 5.1.7 resolves a couple bugs. This should be treated as a security update.
https://www.getpaint.net/

Operating System Updates

These are for specific Linux flavors and alternative operating systems and, sadly, are unlikely to be of interest to most people.

ChromeOS 134.0.6998.183 is a security update.
https://chromereleases.googleblog.com/search/label/Stable%20updates+ChromeOS

iOS 18.4 is a security update.
https://support.apple.com/kb/HT204204

iPadOS 18.4 is a security update.
https://support.apple.com/kb/HT204204

macOS Sequoia 15.4, Sonoma 14.7.5 and Ventura 13.7.5 are security updates.
https://support.apple.com/kb/HT201541

Tails 6.14.1 is a security update.
https://tails.net/install/download/index.en.html

tvOS 18.4 is a security update.
https://support.apple.com/kb/HT202716

watchOS 11.4 is a security update.
https://support.apple.com/kb/HT204641

Zorin OS 17.3 is a huge compatibility update, adds improved alternative detections and suggestions, changes the default browser to Brave, and improves the Zorin Connect app to better function as an input device for the latest Zorin OS release. This should be treated as a security update.
https://zorin.com/os/mirrors/

Security Software Updates

One or more of these is likely to be of interest to most people.

Caine 14.0 improves UEFI support and updates kernel. This is a security update.
https://www.caine-live.net/

Chainsaw 2.12.2 is a housekeeping release. This is not a security update.
https://github.com/countercept/chainsaw

MalwareBytes Desktop Security 5.2.10.182 is a security update.
https://www.malwarebytes.org/antimalware/

ProtonVPN 4.1.10 updates the user interface, adds a list of recent connections to quick access, and adds advanced profile settings such as port forwarding and autolaunch behaviors. This is not a security update.
https://github.com/ProtonVPN/win-app/releases/latest

RogueKiller 16.1.2 expands the monitoring capabilities and improves detection logic. This should be treated as a security update.
https://www.adlice.com/download/roguekiller/

Stinger 13.0.0.342 adds support for new detections. This is not a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

SuperAntiSpyware 10.0.1274 resolves several bugs. This is not a security update.
https://www.superantispyware.com/download.html

uBlock Origin 1.63.2 resolves a major stability issue. This should be treated as a security update.
https://github.com/gorhill/uBlock/releases/latest

Velociraptor 0.74.1 improves the Sigma editor and adds new live event sources. This is not a security update.
https://github.com/Velocidex/velociraptor/releases/latest

Capture Updates

These are unlikely to be of interest to most people.

ScreenToGif 2.41.2 adds AVIF support and resolves a couple bugs. This is not a security update.
https://github.com/NickeManarin/ScreenToGif/releases/latest

SnagIt 25.1.0 updates libraries, improves step capture, smart redact, stability and performance, and resolves several bugs. This is a security update.
https://www.techsmith.com/screen-capture.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.3.8 adds support for new encodings and improves OCR detection for subtitles. This is not a security update.
https://www.dvdfab.cn/download.htm

MakeMKV 1.18.1 adds support for new encodings and resolves a couple bugs. This is not a security update.
https://www.makemkv.com/download/

StreamFab 6.2.2.8 improves compatibility, adds support for newer playlist and distribution formats, and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 3.0.1.2 resolves several bugs and adds faster upscaling model. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Education updates

One or more of these are likely to be of interest to most people.

Zotero 7.0.15 resolves several bugs. This is not a security update.
https://www.zotero.org/

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.10.70 adds new internetional keyboard layout support. This is not a security update.
https://1password.com/downloads/

AOMEI Partition Assistant 10.8.0 finally adds a built-in update mechanism, improves Windows-To-Go support, and resolves several bugs. This is not a security update.
https://www.diskpart.com/

Bitcoin 28.1 adds new features, bug fixes and performance improvements. This is not a security update.
https://bitcoin.org/en/download

Bitwarden 2025.3.0 adds 2SL login support to the user interface and resolves several bugs. This is not a security update.
https://bitwarden.com/

CCleaner 6.34.11482 resolves several bugs. This is not a security update.
https://www.ccleaner.com/

CPU-Z Installer 2.15 adds support for newer hardware. This is not a security update.
https://www.cpuid.com/softwares/cpu-z.html

Cygwin 3.6.0-1 adds several new APIs, improves compatibility and resolves several bugs. This is not a security update.
https://cygwin.com/

Dell Command Update 5.5 adds automatic driver downloads to the Advance Driver Restore operation. This is not a security update.
https://www.dell.com/support/article/us/en/04/sln311129/dell-command-update?lang=en

DesktopOK 11.71 resolves a couple bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

DiskCheckup 3.6 doesn’t provide a detailed change log so should be treated as a security update.
https://www.passmark.com/products/diskcheckup/

dnGrep 4.4.9.0 resolves several bugs. This is a security update.
https://dngrep.github.io/

email-oauth2-proxy 2025-03-14 resovles several bugs. This is not a security update.
https://github.com/simonrob/email-oauth2-proxy

Eraser 6.2.0.2996 doesn’t provide a change log so should be treated as a security update.
https://eraser.heidi.ie/download/

ESEDatabaseView 1.78 adds an optional black background. This is not a security update.
https://www.nirsoft.net/utils/ese_database_view.html

Everything Toolbar 1.5.2 improves compatibility and resolves a couple bugs. This is not a security update.
https://github.com/stnkl/EverythingToolbar/

FoneTool 2.10.0 adds support to back up ringtones, improves System Repair and iTunes compatibility and resolves several bugs. This is not a security update.
https://www.fonetool.com/download.html

GoodSync 12.8.7 resolves several bugs. This is not a security update.
https://www.goodsync.com/

HWiNFO 8.24 adds support for newer hardware. This is not a security update.
https://www.hwinfo.com/download/

ImageUSB 1.5.1007 resolves a hardware compatibility bug. This is not a security update.
https://www.osforensics.com/tools/write-usb-images.html

Kingston SSD Manager 1.5.4.9 doesn’t provide a change log so should be treated as a security update.
https://www.kingston.com/us/support/technical/ssdmanager

ManageWirelessNetworks 1.16 adds option to save all items. This is not a security update.
https://www.nirsoft.net/utils/manage_wireless_networks.html

NConvert 7.221 doesn’t provide a change log so should be treated as a security update.
https://www.xnview.com/en/nconvert/

NTLite 2025.03.10351 improves new Windows UEFI build behavior and updates libraries. This is not a security update.
https://www.ntlite.com/download/

OSForensics 11.1.1004 resolves several bugs. This is not a security update.
https://www.osforensics.com/download.html

PowerToys 0.90.0 adds several new features and resolves a bunch of bugs. This is a security update.
https://github.com/microsoft/PowerToys/releases/latest

RoboForm 9.6.6 changes a couple behaviors and resolves several bugs. This is not a security update.
https://www.roboform.com/

ScreenConnect 25.2.3.9216 resolves several bugs and now imposes a hardcoded email limit in the name of security – which means that monitoring events using the email action will no longer be reliable.
https://screenconnect.connectwise.com/download

SSD Life 2.5.82 adds support for newer hardware. This is not a security update.
https://ssd-life.com/eng/download-ssdlife.html

Starwind V2V Converter 9.626 improves conversions from Hyper-V to ESXi. This is not a security update.
https://www.starwindsoftware.com/starwind-v2v-converter

TeamViewer 15.64.3 adds several new management features and resolves a couple bugs. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/

WakeMeOnLan 1.93 adds a black background option. This is not a security update.
https://www.nirsoft.net/utils/wake_on_lan.html

WinRAR 7.11 resolves several bugs. This is not a security update.
https://www.rarlab.com/

WinScan2PDF 9.31 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WizFile 3.12 resolves a bug. This is not a security update.
https://antibody-software.com/wizfile/

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 2024.3.1.14 resolves several bugs. This is not a security update.
https://developer.android.com/studio

cx_Freeze 8.1 updates libraries and resolves several bugs. This should be treated as a security update.
https://cx-freeze.readthedocs.io/en/latest/index.html

GameMaker Studio 2024.13.0.190 resolves over 500 bugs. This should be treated as a security update.
https://www.yoyogames.com/en/gamemaker

GDevelop 5.5.228 resolves a couple cosmetic bugs. This is not a security update.
https://gdevelop.io/download

Go 1.24.2 is a security update.
https://go.dev/

Godot 4.4.1 is a security update.
https://godotengine.org/

Inno Setup 6.4.2 adds a new setup directive. This is not a security update.
https://www.jrsoftware.org/isdl.php

Node.js 18.20.8 is a security update.
https://nodejs.org/en/

Node.js 20.19.0 resolves several bugs. This is not a security update.
https://nodejs.org/en/

Node.js 23.11.0 updates libraries and resolves several bugs. This is not a security update.
https://nodejs.org/en/

Python 3.13.3 resolves dozens of bugs. This is a security update.
https://www.python.org/downloads/windows/

Visual Studio Code 1.99.1 resolves several bugs. This is a security update.
https://code.visualstudio.com/

Web Package Updates

These are likely to be of interest only to web developers.

Adminer 5.2.0 resolves several bugs and adds cosmetic improvements. Adminer has been under very active development the last couple months so expect many more future updates over time.
https://www.adminer.org/en/

Grocy 4.5.0 implements a new barcode reader and resolves a couple bugs. This is not a security update.
https://github.com/grocy/grocy

HumHub 1.17.2 resolves several bugs. This is not a security update.
https://www.humhub.com/en

Joomla 5.2.6 and 4.4.13 are security updates.
https://www.joomla.org/

MailEnable 9.88 and 10.52 are security updates.
https://www.mailenable.com/

OpenCart 4.1.0.3 resolves several bugs. This is not a security update.
https://www.opencart.com/

Piwigo 15.5.0 resolves several bugs. This is not a security update.
https://piwigo.org/

YOURLS 1.10.0 updates requirements, dependences and resolves several bugs. This is not a security update.
https://yourls.org/

BuddyPress 14.3.4 is a security update.
https://wordpress.org/extend/plugins/buddypress/

My Sticky Bar 2.7.8 improves user interface. This is not a security update.
https://wordpress.org/extend/plugins/mystickymenu/

WordPress Importer 0.8.4 resolves a couple bugs. This should be treated as a security update.
https://wordpress.org/extend/plugins/wordpress-importer/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

 

Updates 2025-03-11

Happy St. Patrick’s Day, Folks!

Today is Patch Tuesday for March, 2025.

It’s as safe as it’s going to be to upgrade to Windows 11 24H2 or macOS 15/Sequoia.

If your Windows 10 (or older) computer can not be upgraded to Windows 11, or if you used a registry or installation bypass to install an older version of Windows 11 on it that is no longer supported, then it’s time for you to start looking for a replacement computer. Actually, the time was 6 weeks ago. Pickin’s are thin right now. 🙁

There were 575+ major hacks, and over 300 application updates this month. Even so, it’s a relatively minor month, with about 2.5 GB of updates for most users.

This Month in Technology

1inch, 1X Internet, 365labs, Access2Jobs, 49,000 Access Management Systems AMS), ACDC Express, Acqua Development, ACTi Corporation, Adrenalina, Adval Tech, Advantage Home Construction Insurance, Aeonsparx, AJ Taylor Electrical Contractors, Alabama Ophthalmology Associates, Albion Online, Alf DaFrè, All4Labels, Allied Tenesis, AllTrust, Allworx, Ally Financial, Almost Famous Clothing, Amalgamated Sugar, Amerman Ginder, an American political action committee (PAC), Andover Family Medicine, Android, Angel One, Anne Arundel County, Apache Atlas, Apache EventMesh, Apache Ignite, Apache Pinot, Apache Tomcat, ¡appa!, Apparel Group, Apple Safari, Archie Cochrane Ford, Arcusin, Armed Forces of the Philippines, Artistic Family Dental, Ashlar-Vellum Cobalt, Aspire Rural Health System, Aurora Boardworks, Aurora Public Schools, Australian National University, Autodesk Navisworks, Autohaus Kießling, Autoschade Pippel, Avery Products Corporation, Aya Healthcare, Azamara Cruises, Baltimore Country Club, Bangladesh Navy, Bank of America, Barhite & Holzinger Inc, Bassford Remele PA, Bay Cove Human Services, Belgium State Security Service (VSSE), Bell Ambulance, BeniPlus, Benjamin Consulting Services, Benton Police Department, Berg Engineering Consultants, Berkeley Research Group, Best Collateral, Bethany Lutheran Church, Better Auth, BH Aircraft Company, Biagi Bros, Inc, Bikur Rofeh, Birch Medical LLC, Birdsall Muller LLC, Bis Industries, Black Basta ransomware gang, Black Star, BluAgent Technologies, Blue & Co, Blue Planet, Blue Shield of California, Bosowa Berlian Motor, Boys and Girls Clubs of the Tennessee Valley, British Virgin Islands London Office, Bulgaria’s Supreme Administrative Court, Bulldog Oilfield Services, Bulverde Glass, Burdick Painting, Burlington Hydro, Bybit, Cache Valley ENT, Cafe Zupas, Callico Distributors, Cardiology of Virginia, Carolina Arthritis Associates, Carruth Compliance Consulting, Castle Rock Construction, CCL Products India, CCT Technologies, CDS in Texas, Central District Health Department, Central New York Cardiology, Central Texas Pediatric Orthopedics, Charleston Area Medical Center, Chicago Doorways, Chicago Public Schools, Chimu Agropecuaria, Ciba Cobertura Medica, City of McKinney, City Of Roseburg, City of Tarrant, City of Van, Turkey, City Plumbing & Electric Supply, Claris Vision Holdings, Clawson Honda, Cleveland Municipal Court, Cocospy, Color Dating, Colorado River Adventures, Columbus Division of Fire, Comercializadora S&E Perú, Command & Conquer Generals: Zero Hour, Community Care Alliance, Commvault Webserver, Compound Solutions, Connekted, Consultants in Pain Medicine, Convert Solar, Couri Insurance Agency, CPS Solutions, Craft CMS, Crayfish, Cricadda, Cronos Europa, Crossroads Trading Company, Cyncly Company, Dacas Argentina, Daniels Homes, Datavant Group, Delta Electronics CNCSoft-G2, Delta Electronics ISPSoft, Detroit PBS, Digital Technology Co, Dinizulu Law Group, DISA Global Solutions, Django, DocsGPT, DOGE, Donna G Rogers, CPA, Doxbin, DRClaims FL, Dynamic Closures, DZL, EAC Consulting, Edesur Dominicana, Edimax IC-7100 IP, El Corte Inglés, Elastic Kibana, Elite Advanced Laser Corporation, Endless Mountains Health Systems, Engikam, Erie Management Group, Essex County OB/GYN Associates, Euranova, Ewald Consulting, Executive Agenda, EzyLegal, F&V Capital Management, Fairhaven Shipyard Companies, FANTIN group, Fickling & Company, Fillmore County Hospital, Financial Services of America, Finastra, Finck Cigar, First Defense Fire Protection, First Federal Savings & Loan, Flat Earth Sun, Moon and Zodiac App, Flightsim Studio, FlowiseAI, Fort St. John, Fortinet FortiWeb, Franklin County, Friendship House, FTECH R&D, G&M Direct Hire, G&S Electric LLC, Gala Tech, Garantex, Genea, Georgian Government, GitLab, Goldstein Law Group, Google Chrome, Google Chrome extension platform, Government of Brazil, Government of Pakistan, Grafitec, Greencastle-Antrim Senior High School, Greenwood Village South, Gregory & Appel Insurance, Grubhub, Grupo Baston Aerossol, GS Retail, Haggin Oaks Golf, Hall Law Group, Hammond Trucking & Excavation, Hancock Public School, Hanson Cold Storage, Hatolna, HCRG Care Group, HealthRev Partners, LLC, Heartland Health Center, Help Me Grow Yolo, Heritage South Credit Union, Hewlett Packard, Hewlett Packard Enterprise, Hickory Law, Hillcrest Convalescent Center, Inc, Hipshipper, Hirsch Enterphone MESH, Hisingstads Bleck, Holiday Comfort Inn, Hollandia Dairy, Home Assistant, HomeTeamNS, Houston Symphony, HP LaserJet Pro MFP 3301fdw, Humboldt Independent Practice Association, iCloud, Indian Ministry of Culture, INDIC Electronics, Indonesian Firefighting Services, Infini, InfoReach, Inland Empire Distribution Systems, Innovative Renal Care, Insight Partners, Insyst GmbH, Interjet, INTERLINK Health Services, Internet Corporation for Assigned Names and Numbers (ICANN), 86,000 Internet of Things devices, InternetWay, Inversiones Clinica Del Meta, InvestHK, Investing.com, IRS, Island Realty, IT-IQ Botswana, Italian Government, iTP Partners, Ivanti Connect Secure (ICS), Ivanti Endpoint Manager, Ivanti Policy Secure (IPS), Ivanti Secure Access Client (ISAC), Jaguar Land Rover, Jaime Schwartz MD, Jefferson Elementary School District, Jerue Companies, Jewish Child Care Association of New York, Jildor Shoes, Johnson’s Nursery, JP Express, Juniper Networks Session Smart Router (SSR) devices, Kelsey-Seybold Clinic, Kendall Auto Group, Kensington Glass Arts, Keystone Pacific Property Management, Kings River Union Elementary, Klesk Metal Stamping, Krisala Developer, Krispy Kreme, Kronick Moskovitz Tiedemann & Girard, Kuwaiti Government, Kyocera International, Inc, La Unión, Label Studio, LandAirSea, LANIT, Laravel, Las Cruces, Laurens School District 56, Law Diary, Leadership Strategies, Leading Edge Specialized Dentistry, Leantime, Leeds United, Legacy Professionals, Legal Aid Society of Salt Lake, Lexmark, Lietvaris, Ligentia, LINKGROUP, LINTEC & LINNHOFF Holdings, Linux Kernel, Lost & Found, Loyola University Maryland, LRT, Lucee, Lucent Health Solutions, Lumen Technologies, Luminus Management, M-1 Toolworks, Mac Jee, Mackay Memorial Hospital, Magnolia Manor, Mainline Information Systems, Makai, Manning Publications, Mars Hydro, Martin Energy Group Services, Matagorda County, Medefer, Medusind, Inc, Meet and Chill, Memorial Hospital and Manor, MercadoLibre, Mercury Paper Inc, Mercy Supply, Merkanti Bank, Meta E2 F, Metro Supply Chain Group, Metropolitan Borough of Gateshead, Microsoft Edge, Microsoft Sharepoint, Microsoft Windows Debugger, Microsoft Windows Installer Service, Microsoft Windows KDC Proxy, Microsoft’s partner website, Minaris Medical America, Ministry of Agriculture, Indonesia, Ministry of Defence, India, Ministry of Foreign Affairs, Ukraine, Ministry of Health of Palau, Minnesota Exteriors, Minnesota Orthodontics, Mission, Texas, Missouri Department of Conservation, MITRE Caldera, MNJ Technologies Direct, Monroe Transportation Services, Moodle, Mosley Glick O’Brien, MOVITOOLS MotionStudio, Moxa PT Switches, MTN Group, Muller Insurance, Mundelein Park & Recreation District, My New Jersey Dentist, mySCADA, Naphix, Naples Heritage Golf & Country Club, NASCAR, National AirVibrator, National Presto Industries, Navien, NBA, Neaton Auto Products Manufacturing, Nebraska Irrigation, Nelson & Townsend, CPA’s, Neopoly, Netcom-World, New Era Enterprises, Inc, New Era Life Insurance Companies, Newton & Associates, Next TI, NHS Tayside, NI DAQExpress, Nichino Ryokka Co, NioCorp Developments Ltd, Nippon Steel, Niva Bupa, North American Fire Hose, Northern Management, NorthWest Arkansas Community College, Novi Community School District, NTT Communications Corporation, Numotion, Nuna Baby Essentials, NVIDIA Container Toolkit, NVW Newco, LLC, Oberlin Cable Co-op, Obex Medical, Omni United, Ondunova, Openreso, OpenSSH, Orange Group Romania, Ottawa Family Physicians, Oxidized Web, PACE, Pacific Honda Company, Pacific Rehabilitation Centers, Paddington Bear, PAN-OS firewalls, Paragon Partition Manager, Parallels Desktop, Paratus, Park Place Pediatric Dentistry, payapps.com, Paysera, PDF-XChange Editor, Pebble, Pedensia Graphics Distribution, Penn-Harris-Madison, Perrin Performance, Persante Health Care, Pervedant, Peter Glenn Ski Sport, Petstop, Phoenix Rehabilitation and Nursing Center, Polish Space Agency (POLSA), Portland Schools, PostgreSQL, PostHog ClickHouse, Pound Road Medical Centre, Power Pages, PPS Services Group, Praxis Eins, Precision Orthopedics and Sports Medicine, Primary Health-SMMPP & U.S. HEALTHWORKS-SMMPP, Princeton Hydro, PS, Pump.fun X account, QBurst, Quality Home Health Care, Radco Industries, Rainbow District School Board, Ray Fogg Corporate Properties, Raymond Lifestyle, Raymond Limited, RCDPRO, Reading Cooperative Bank, Reddit, Regency Media, Rennes University, Renton School District, Restorix Health, RFA Decor, Riverdale Country School, Rivers Casino Philadelphia, a prominent Riyadh-based real estate and construction firm, RJ IT Solutions, ROCK SOLID Stabilization & Reclamation, Roswell Park Comprehensive Cancer Center, Rowe Tactical, Rubrik, Ruby on Rails, RxSight, RZD, S3-Proxy, Safe-Strap Company, Saracen Properties, Sault Ste. Marie Tribe of Chippewa Indians, Schmiedetechnik Plettenberg GmbH & Co, SCLARC, Scott County, Iowa, Scottish Qualifications Authority, Seabank Group, Semyonishna, Shetland Islands Council, Shields Facilities Maintenance, Shinn Fu Company of America, Siegel Group, Signal, SimonMed Imaging, Sittab, SMC Corporation of America, Soco Systems, Solar Data Systems, SolarWinds, Somnia, SonicWall firewalls, Sorare, Sorbonne University, South African Weather Service, SPEED Co, Spring Management OK, LLC, Spyic, Spyzie, SSK Plastic Surgery, St. Andrew’s Resources for Seniors System, Star Solution Services, State Bar of Texas, Stateside Seattle, Sterling BMW, Storenvy, Story Environmental, Stram Center for Integrative Medicine, StubHub, Sublette County, WY, Summit Home Health, Sunflower Medical Group, PA, Sunnking Sustainable Solutions, SushiCo, Synelixis Solutions, System Pavers, T J Machine & Tool, T-Mobile, TensorFlow, Thai Metal Aluminium, The Agency, The Grove at Valhalla Rehabilitation and Nursing Center, The Northwestern Illinois Association, The Pension Specialist, The Phoenix Rehabilitation and Nursing Center, The Siegel Group, The Smeg Group, The Townsley Law Firm, Therma Seal Insulation Systems, Thong Sia, Thornton Engineering, Tie Down Engineering, TikTok, Title 9 Sports, Inc, TOT Mobile, Town Counsel Law & Litigation, TP-Link routers, Transak, Transkid, Trident Maritime Systems LLC, Trimble SketchUp, Tugwell Pump & Supply, Turning Point of Central California, UFCW Local 135, Unimicron, United Community Health Center, US Coast Guard, US Dept Of Defense, US Dept of Housing and Urban Development (HUD), Utsunomiya Central Clinic, Vector Engineering, VectraRx Mail Pharmacy Services, Vela Server, Vermeer Mexico, Versant Technologies, Via Credit Union, Vicky Foods, Virginia Attorney General’s office, Vičiūnai Group, VMware ESX, Volt, Vue, Wayne County, Michigan, WDNA, Webex for BroadWorks, Weed Man Canada, Wendy Wu Tours, Whitman Hospital & Medical Clinics, Wilkinson Rogers, Williamsburg-James City Schools, Window World of Raleigh, WJCC Public Schools, Woman’s Athletic Club of Chicago, WordPress Chaty Pro plugin, WordPress Essential Addons for Elementor plugin, WordPress Jupiter X Core plugin, Workforce Group, Wylie Steel Fabricators, Xactus, Xen hypervisor, Xerox VersaLink C7025, XWiki, Yahoo, Yorke & Curtis, YouTube, Zacks Investment Research, Zimbra, ZITADEL, zkLend, and Zurich Insurance have reported hacking or compromises this month.

Flight Radar 24,Mastercard, Microsoft 365, Outlook.com, X/Twitter, and ZServers/XHost (yay!) have suffered from outages this month.

Last months updates broke AutoCAD 2022, Classic Outlook (again), Microsoft 365, Outlook Drag & Drop, Windows 11 SSH, and Windows Server 2025. Microsoft did release an out-of-cycle BIOS update to fix crash bugs in ASUS devices that has persisted since October.

In other news…

Apple’s AI sucks at transcription. And they’ve disabled end-to-end encryption for users in the UK.

Microsoft is never going to give up trying to get your files into OneDrive so they can use them to feed their AI. After this, their next step will be to “accidentally” turn it on in a month or two then apologize for it later. “Oops.” Microsoft has announced they’re killing off Skype in only a couple months. An ad-supported version of Microsoft Office/365 is currently in beta.

Microsoft accounts are being targeted by an insane “password spraying” attack over the last month or so. Due to the way their authentication works, where all it takes is your email address to send you an email or text with a passcode to log you in, it’s resulting in hundreds or even thousands of messages to Microsoft account holders with these one time pin numbers.

As Microsoft launches their new 24/7 screen capture and content collection service, Recall, they are removing the Location History feature in Windows.

Many websites are now “fingerprinting” your browser to uniquely identify “you” – and the net effect is that it actually allows malicious actors to impersonate you really well.

ReliaQuest has released information about how a “tsunami of phishing messages” followed by a massive deluge of spam in order to allow hackers the cover they needed to hijack their network. It’s a great birds-eye view of how this kind of thing works. The lesson here: Don’t simply ignore a massive uptick in phishing messages or spam.

A series of vulnerabilities exist in undocumented functions in the Espressif bluetooth chips used in over a billion devices.

YouTubers are being targeted with threats of copyright strikes if they don’t spread malware. And you thought the content was bad already.

Now for the good news:

The EFF has released a tool to detect cellular spying.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is relatively minor this month. The typical computer should see roughly 2.5 GB in updates today. Let’s get started.

Microsoft released 39 updates to address 72 vulnerabilities in .NET, ASP.NET Core & Visual Studio, Azure Agent Installer, Azure Arc, Azure CLI, Azure PromptFlow, Kernel Streaming WOW Thunk Service Driver, Microsoft Edge, Microsoft Local Security Authority Server (lsasrv), Microsoft Management Console, Microsoft Office, Microsoft Office Access, Microsoft Office Excel, Microsoft Office Word, Microsoft Streaming Service, Microsoft Windows, Remote Desktop Client, Synaptics, Inc., Visual Studio, Visual Studio Code, Windows Common Log File System Driver, Windows Cross Device Service, Windows DNS Server, Windows exFAT File System, Windows Fast FAT Driver, Windows File Explorer, Windows Hyper-V, Windows Kernel Memory, Windows Kernel-Mode Drivers, Windows MapUrlToZone, Windows Mark of the Web (MOTW), Windows NTFS, Windows NTLM, Windows Remote Desktop Services, Windows Routing and Remote Access Service (RRAS), Windows Subsystem for Linux, Windows Telephony Server, Windows USB Video Driver, Windows Win32 Kernel Subsystem, and MSRT. This includes security updates. A reboot is required.

Apple released updates for iOS 18.3.2, iPadOS 18.3.2, macOS Sequoia 15.3.2, Safari 18.3.1, tvOS 18.3.1, and visionOS 2.3.2. This includes security updates. Use Apple Software Update to install the most current versions.

iOS 18.3.2 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 18.3.2 are security updates. Use Settings, General, Software Update to install the most current update.

tvOS 18.3.1 is a security update. Use System, Software Update to install the most current version.

visionOS 2.3.2 is a security update. Use System, Software Update to install the most current version.

Google ChromeOS 133.0.6943.146 and Google ChromeOS LTS 126.0.6478.265 and 132.0.6834.211 are security updates. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sequoia (15.x) means that macOS Monterey (12.x) and older are no longer supported. If you can not install at least macOS Ventura (13) on your Mac then you should immediately remove your device from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v24H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it. If not, switch to Linux (Mint is nice) or replace your computer.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with a SaferPC Subscription and we will install updates each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 25.3.1 adds support for new hardware, feature and performance improvements, and resolves several bugs. This is not a security update.
https://www.amd.com/en/support

Crucial Storage Executive 11.01 does not provide a change log so should be treated as a security update.
https://www.crucial.com/support/storage-executive

Intel Driver and Support Assistant 25.1.9.6 is a security update.
https://www.intel.com/p/en_US/support/detect

VIISAN OfficeCam 7.2.7.0 doesn’t provide a change log so should be treated as a security update.
https://www.viisan.com/en/download/type1.html

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.76.74 is a security update.
https://brave.com/

Google Chrome 134.0.6998.88 is a security update.
https://www.google.com/chrome/

Firefox 136.0.1 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 128.8.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Vivaldi 7.1.3570.60 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

DavMail Gateway 6.3.0 improves compatibility and resolves several bugs. This is a security update.
https://davmail.sourceforge.net/

Spark 3.21.3.100475 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.21.3.100474 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 136.0.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 9.0.4 resolves several crash bugs. This is not a security update.
https://anydesk.com/en/downloads

AnyDesk (macOS) 9.0.0 is a major update adding several new features and resolves compatibility and stability bugs. This is not a security update.
https://anydesk.com/en/downloads

curl 8.12.1 improves tests and resolves several bugs. This is not a security update.
https://curl.haxx.se/windows/

Dropbox 219.4.4463 resolves several stability bugs. This is not a security update.
https://www.dropbox.com/

FreeFileSync 14.2 resolves a crash bug. This is not a security update.
https://www.freefilesync.org/download.php

Google Drive 105.0 resolves several bugs. This is not a security update.
https://drive.google.com/start

Grocy Desktop 2.13.0 improves compatibility. This is not a security update.
https://github.com/grocy/grocy-desktop

MeshCentral 1.1.42 resolves several bugs. Note that this version has conflicts with Windows 7 and 2008R2 so do not enable update on these platforms. This is not a security update.
https://meshcentral.com/info/downloads.html

Microsoft Teams 1.8.00.4966 enables AI by default, feature improvements and now consumes Skype links. Skype is dead. This is not a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 31.0.0 updates libraries and resolves dozens of bugs. This should be treated as a security update.
https://nextcloud.com/

Npcap 1.81 adds several new features and performance improvements. This is not a security update.
https://nmap.org/npcap/

Rclone 1.69.1 improves compatibility and resolves several bugs. This is not a security update.
https://rclone.org/

Signal 7.45.1 resolves several bugs. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.36.2 adds chat history migration support. This is not a security update.
https://signal.org/android/apk/

Technitium DNS Server 13.4.3 improves reliability and performance. This is not a security update.
https://technitium.com/dns/

Telegram 5.12.3 resolves several bugs. This is not a security update.
https://telegram.org/

WinSCP 6.3.7 is a security update.
https://winscp.net/eng/index.php

Zoom 6.3.11.60501 resolves several bugs. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.15 improves clothing and other interactions. This is not a security update.
https://en.3tene.com/

Bitwig Studio 5.3.2 resolves several bugs. This should be treated as a security update.
https://www.bitwig.com/download/

darktable 5.0.1 resolves dozens of bugs. This is not a security update.
https://www.darktable.org/

Grayjay 285 improves sync and resolves several bugs. This is not a security update.
https://grayjay.app/index.html

iTunes 12.13.6.1 adds support for new iOS and iPadOS versions. This does not provide a detailed change log so should be treated as a security update.
https://www.apple.com/itunes/download/

KaraFun Player 3.5.3 improves offline mode and remote. This is not a security update.
https://www.karafun.com/karaoke-windows/

Plex Desktop 1.108.1.307 doesn’t provide a change log so should be treated as a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Media Server 1.41.5.9522 improves ad detection feature, performance and resolves a bunch of bugs. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.62.01 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

PS5 2025.225 improves performance and stability. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2025.03.10 resolves several bugs and improves stability. This is not a security update.
https://store.steampowered.com/news/app/593110

SteamOS SteamDeck Update 2025.03.04 is a security update.
https://store.steampowered.com/news/app/1675200/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Illustrator 28.7.5 and 29.3 are security updates.
https://helpx.adobe.com/security/products/illustrator/apsb25-17.html

Adobe InDesign 19.5.3 and 20.2 are security updates.
https://helpx.adobe.com/security/products/indesign/apsb25-19.html

Adobe Reader DC 25.001.20432, 24.001.30235 and 20.005.30763 are security updates.
https://get.adobe.com/reader

Adobe Substance 3D Designer 14.1.1 is a security update.
https://helpx.adobe.com/security/products/substance3d_designer/apsb25-22.html

Adobe Substance 3D Modeler 1.20.10 is a security update.
https://helpx.adobe.com/security/products/substance3d-modeler/apsb25-21.html

Adobe Substance 3D Painter 11.0 is a security update.
https://helpx.adobe.com/security/products/substance3d_painter/apsb25-18.html

Adobe Substance 3D Sampler 5.0 is a security update.
https://helpx.adobe.com/security/products/substance3d-sampler/apsb25-16.html

Aronium 1.45 resolves several bugs. This is not a security update.
https://aronium.com/

Artweaver 8.0.3 resolves several bugs. This is not a security update.
https://www.artweaver.de/

Audacity 3.7.2 resolves over a dozen bugs. This is not a security update.
https://www.audacityteam.org/download/

Calibre 7.26.0 resolves several bugs. This is not a security update.
https://calibre-ebook.com/

Columns++ 1.2 improves parsing and adds additional escapes and search options. This is not a security update.
https://github.com/Coises/ColumnsPlusPlus

Kdenlive 24.12.3 resolves over a dozen bugs. This is not a security update.
https://kdenlive.org/

Kindle for PC 2.7.70978 doesn’t provide a change log so should be treated as a security update.
https://www.amazon.com/kindleforpc

LibreOffice 24.8.5 resolves over 60 bugs. This is a security update.
https://www.libreoffice.org/

LibreOffice Fresh 25.2.1 resolves over 75 bugs. This is a security update. The “Fresh” line is beta software and should be avoided in favor of the standard release.
https://www.libreoffice.org/

Manager 25.3.11.2151 improves inventory feature. This is not a security update.
https://www.manager.io/

Nextcloud Desktop 3.16.0 resolves dozens of bugs. This is not a security update.
https://nextcloud.com/

Notepad++ 8.7.8 resolves several bugs. This is not a security update.
https://notepad-plus-plus.org/

Paint.net 5.1.5 adds JPEG XL support, updates libraries and resolves several bugs. This is not a security update.
https://www.getpaint.net/

PDF-XChange Editor 10.5.2.395 is a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

Operating System Updates

These are for specific Linux flavors and alternative operating systems and, sadly, are unlikely to be of interest to most people.

Tails 6.13 is a security update.
https://tails.net/install/download/index.en.html

Security Software Updates

One or more of these is likely to be of interest to most people.

IISCrypto 4.0.18 adds support for Windows Server 2025, improved logging, controls, profiles and resolves a couple bugs. This is not a security update.
https://www.nartac.com/Products/IISCrypto/Download

JShelter 0.20 resolves several bugs. This is not a security update.
https://jshelter.org/install/

KeePass 2.58 improves cosmetics, controls and adds several new import and export capabilities. This is not a security update.
https://keepass.info/

MalwareBytes Desktop Security 5.2.7.167 resolves several bugs. This is not a security update.
https://www.malwarebytes.org/antimalware/

OnionShare 2.6.3 updates libraries, resolves several bugs, improves compatibility, and log capability. This is not a security update.
https://onionshare.org/

OpenSSL 3.4.1 is a security update.
https://slproweb.com/products/Win32OpenSSL.html

ProtonVPN 3.5.3 improves stability. This is not a security update.
https://github.com/ProtonVPN/win-app/releases/latest

RogueKiller 16.1.1 resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

Stinger 13.0.0.300 adds new detections. This should be treated as a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

Capture Updates

These are unlikely to be of interest to most people.

Open Broadcaster Software 31.0.2 resolves several crash and stability bugs. This is not a security update.
https://obsproject.com/

SnagIt 25.0.0 updates libraries, adds “step capture”, smart redaction, removal of background noise and customizable sharing. Unfortunately, it also now attempts to install SQL Server Compact Edition which has been unsupported for over three years with outstanding security vulnerabilities. It also introduced a crash bug when exporting to PNG format. This is a security update. Kinda sad isn’t it: Fix a few vulnerabilities and intentionally add even more? Sigh.
https://www.techsmith.com/screen-capture.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.3.7 adds support for new hardware and improves stability. This is not a security update.
https://www.dvdfab.cn/download.htm

HandBrake 1.9.2 resolves a couple bugs. This is not a security update.
https://handbrake.fr/

StreamFab 6.2.2.5 resolves several bugs and improves compatibility. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 3.0.1.0 resolves several bugs and adds support for newer hardware. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Education updates

One or more of these are likely to be of interest to most people.

Zotero 7.0.13 resolves a couple bugs. This is not a security update.
https://www.zotero.org/

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.10.64 resolves several bugs and improves default behaviors. This is not a security update.
https://1password.com/downloads/

balenaEtcher 2.1.0 adds support for new platforms and ability to disable analytics. This is not a security update.
https://etcher.balena.io/

Beyond Compare 5.0.6.30713 resolves several bugs. This is not a security update.
https://www.scootersoftware.com/download

BgInfo 4.33 doesn’t provide a change log so should be treated as a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/bginfo

Bitwarden 2025.2.1 improves user interface and adds 2FA for unrecognized devices. This is not a security update.
https://bitwarden.com/

Carbonite 6.5.1 improves compatibility. This is not a security update.
https://account.carbonite.com/

CCleaner 6.33.11465 resolves a couple bugs. This is not a security update.
https://www.ccleaner.com/

DesktopOK 11.63 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.4.2.0 resolves several bugs and improves console support. This is not a security update.
https://dngrep.github.io/

ESEDatabaseView 1.77 improves database reading. This is not a security update.
https://www.nirsoft.net/utils/ese_database_view.html

Fing 3.8.1 resolves several bugs. This is not a security update.
https://www.fing.com/products/fing-desktop-download-windows

GoodSync 12.8.5 resolves several bugs and improves compatibility. This is not a security update.
https://www.goodsync.com/

grepWin 2.1.8 resolves a couple bugs. This is not a security update.
https://github.com/stefankueng/grepWin/releases/latest

GSmartControl 2.0.2 resolves several bugs. This is not a security update.
https://gsmartcontrol.shaduri.dev/

Homedale 2.18 adds Thai language support. This is not a security update.
https://www.the-sz.com/products/homedale/

HWiNFO 8.22 adds support for newer hardware. This is not a security update.
https://www.hwinfo.com/download/

IsMyHdOK 4.21 improves hardware detection and compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

LessMSI 2.7.0 adds several new translations. This is not a security update.
https://lessmsi.activescott.com/

MultiMonitorTool 2.20 adds scaling capabilities. This is not a security update.
https://www.nirsoft.net/utils/multi_monitor_tool.html

NTLite 2025.03.10344 improves component selection and resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

OSForensics 11.1.1003 improves triage, hash sets, and other improvements. This is not a security update.
https://www.osforensics.com/download.html

osquery 5.16.0 resolves a couple bugs and improves python, deb and rpm package support. This is not a security update.
https://osquery.io/downloads

PowerToys 0.89.0 adds transcoding to advanced paste, improves stability and resolves over a dozen bugs. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

PSAppDeploy 4.0.6 resolves dozens of bugs. This is not a security update.
https://psappdeploytoolkit.com/

RoboForm 9.6.5 removes Security Center from installed app and resolves several bugs. This is not a security update.
https://www.roboform.com/

Starwind V2V Converter 9.623 improves compatibility and resolves several bugs. This is not a security update.
https://www.starwindsoftware.com/starwind-v2v-converter

TeamViewer 15.63.5 resolves several bugs and improves logging. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/

Ventoy 1.1.05 improves compatibility and resolves a couple bugs. This is not a security update.
https://www.ventoy.net/en/index.html

WinGet 1.10.340 improves stability. This is not a security update.
https://github.com/microsoft/winget-cli/releases/latest

WinRAR 7.10 resolves over a dozen bugs and improves MOTW propagation. This should be treated as a security update.
https://www.rarlab.com/

WizFile 3.11 improves threading, user interface and resolves several bugs. This is not a security update.
https://antibody-software.com/wizfile/

WizTree 4.25 improves CSV import and export and resolves a 32-bit compatibility bug. This is not a security update.
https://www.diskanalyzer.com/

XnConvert 1.104.0 adds command line file and list options. This is not a security update.
https://www.xnview.com/en/xnconvert/

ZoomText 2025.2502.63.400 adds ARM64 support and live text view. This is not a security update.
https://support.freedomscientific.com/Downloads/ZoomText

Developer Updates

These are unlikely to be of interest to most people.

.NET Runtime 9.0.3 is a security update.
https://dotnet.microsoft.com/en-us/download/dotnet

Android Studio 2024.3.1.13 resolves dozens of bugs. This is not a security update.
https://developer.android.com/studio

GDevelop 5.5.226 updates libraries and resolves several bugs. This is not a security update.
https://gdevelop.io/download

GitHub Desktop 3.4.18 updates libraries and resolves several bugs. This is not a security update.
https://desktop.github.com/

Go 1.24.1 is a security update.
https://go.dev/

Godot 4.4 adds dozens of new features and improvements. This is not a security update.
https://godotengine.org/

Inno Setup 6.4.1 improves autocompletion and tooltips, and resolves several bugs. This is not a security update.
https://www.jrsoftware.org/isdl.php

Microsoft Visual C++ 2022 Redistributable 14.42.34438.0 is a security update.
https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist

Node.js 18.20.7 resolves over a dozen bugs. This is not a security update.
https://nodejs.org/en/

Node.js 23.9.0 updates dependencies and resolves dozens of bugs. This is not a security update.
https://nodejs.org/en/

Rustup 1.28.1 resolves several bugs. This is not a security update.
https://www.rust-lang.org/

SQLite 3.49.1 resolves several bugs. This should be treated as a security update.
https://www.sqlite.org/download.html

Visual Studio Code 1.98.1 resolves several bugs. This is not a security update.
https://code.visualstudio.com/

Web Package Updates

These are likely to be of interest only to web developers.

Adminer 5.0.4 resolves dozens of bugs and improves various language integrations. This is not a security update.
https://www.adminer.org/en/

Grocy 4.4.2 improves Open Food Facts integration and resolves several bugs. This is not a security update.
https://github.com/grocy/grocy

HumHub 1.17.1 improves registration controls and resolves several bugs. This is not a security update.
https://www.humhub.com/en

Joomla 4.4.12 is a security update.
https://www.joomla.org/

Joomla 5.2.5 is a security update.
https://www.joomla.org/

Piwigo 15.4.0 resolves over a dozen bugs. This is not a security update.
https://piwigo.org/

bbPress 2.6.12 is a security update.
https://wordpress.org/extend/plugins/bbpress/

Conditional Widgets 3.3 updates documentation and improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/conditional-widgets/

Contact Form 7 6.0.5 resolves a couple bugs. This is not a security update.
https://wordpress.org/extend/plugins/contact-form-7/

Duplicator 1.5.12 improves compatibility and resolves several bugs. This is not a security update.
https://wordpress.org/plugins/duplicator/#developers

Redirection 5.5.2 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/redirection/

Sucuri Security 1.9.9 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/sucuri-scanner/

WP Cerber Security 9.6.7.3 resolves several bugs and improves performance. This is not a security update.
https://wpcerber.com/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2025-02-11

Happy Valentines, Folks!

Today is Patch Tuesday for February, 2025.

It’s as safe as it’s going to be to upgrade to Windows 11 24H2 or macOS 15/Sequoia.

If your Windows 10 (or older) computer can not be upgraded to Windows 11, or if you used a registry or installation bypass to install an older version of Windows 11 on it that is no longer supported, then it’s time for you to start looking for a replacement computer. Actually, that time was about 5 weeks ago. Pickin’s are thin right now. 🙁

There were 275+ major hacks, and over 640 application updates this month. It shouldn’t be that bad though, with about 3.5 GB of updates for most users.

This Month in Technology

1win, 9Lives, Addison Northwest School District, Adobe Photoshop, Adopt Me Trading Values, an airline travel integration service, Allegheny Health Network, Alltours, Alpine iLX-507, Alpine IVI, AMD CPUs, American National Insurance Company, Android, AngelSense, Aoki Holdings, Apex Custom Software, Apple Core Media, Apple CPUs, Apple iPad, Apple iPhone, Apple macOS, Apple WebKit, Aprendamos Intervention Team, Arab Civil Aviation Organization, Arlington Westend Dental, Ascension Health, Asheville Eye Associates, AT&T, Autel MaxiCharger, AuthoraCare Collective, Automotive Grade Linux, Avery Products Corporation, AVTECH cameras, Bank Central Asia, Bankers Cooperative Group, Bayhealth Medical Center, BCP Council, Behavioral Health Resources, Benefits Management Group, Berman & Rabin, PA, Big Cheese Studio, Biomedical Caledonia Medical Laboratory Limited, Bitbucket Server, Blacon High School, Cabrillo College, Cacti, Canon imageCLASS MF656Cdw, Casio UK, Catholic Charities of Southern Nevada, ChargePoint EV charger, ChargePoint HomeFlex, Chicago Department of Public Health, Christian Community Aid, Circle K, Cisco, Cisco Identity Services Engine (ISE), City of Hayward, City of McKinney, City of Tarrant, City of Ulster, Cityworks, ClamAV, ClearML, Cleo, Comhairle nan Eilean Siar, Communicare, Community Health Center, Conduent, CR&R Incorporated, Cracked.io, Craft CMS, Crayfish, Crunchyroll, Daytrip, DeepSeek, Delaware Valley School District, Delta County Memorial Hospital District, Dignity Health Lassen Medical Clinic, Django, DogWifTools, Doxbin, DragonNest, E-Benefit Solution, Econet Wireless, Endo Group, ENGlobal, Ethereum, FC Barcelona, FortiOS and FortiProxy, Fota Wildlife Park, Frame & Optic, Frederick Health, Garden of Life, LLC, GeoTools, GitHub Copilot, Globe Life, Google Chrome, Google Gemini AI, Google’s OAuth, Gravy Analytics, GrubHub, H&M, Hakko Corporation, Han Van Duong, MD, Hanover County Public Schools, Harmonyland, Harrison County Schools, Harvard Pilgrim Health Care, HCF Management, Heart Centre, HeatGames, Hewlett Packard Enterprise (HPE), Hikari Seiko, Holdrege Memorial Homes, Hospital El Cruce, Hospital Sisters Health System, Huawei HG532 routers, Iannuzzi Manetta & Co, IMI plc, InterCon Construction, International AIDS Vaccine Initiative, IntraSystems, IPany VPN, Israel Police Systems, Ivanti Avalanche, Ivanti Endpoint Manager, Jefferson School District, Juniper VPN gateways, Kafene, Inc, Kenwood DMX958XR, Kenwood IVI, Kenya’s Business Registration Service, 12,000+ KerioControl firewalls, KraftCPAs, LandAirSea, Laravel Voyager, LCPtracker, Inc, Le Coq Sportif Columbia, Let’s Secure Insurance Brokers Pvt Ltd, LifeBridge Health, Lightning AI, Logsign Unified SecOps, Lucent Health, Magento, Malaysia’s National Tuberculosis Registry, Marina Family Medical, Matagorda County, MedSave Health Insurance, Microsoft Edge, Microsoft Office Word, Microsoft Outlook, Microsoft Windows Installer Service, 13,000 MikroTik routers, Mintty Sixel, Mission Bank, Mity, Inc, Mizuno USA, Mongoose, Moniepoint, Mortgage Investors Group, MSI, NASAMS, Nash County Public Schools, Netgear WiFi routers, New York Blood Center, NI Vision Builder, NoMachine, NorthBay Health, Nulled.to, OneBlood, OnePoint Patient Care, OpenAI ChatGPT, OpenMRS, Oppo, OrthoMinds, Otelier, OU Medicine, over 660,000 Rsync servers, Oxfam Hong Kong, O’Connor Corporation, Palo Alto firewalls, Parallels Desktop, PDF-XChange Editor, PFS Investments, Phemex, Philippines National Bureau of Investigation, Phoenix Contact CHARX SEC-3150, Planet Technology WGS-804HPT, PoinCampus, Portola Valley School District, PowerSchool Group LLC, Puroland, QNAP NAS, Ramona Unified School District, Rebound Orthopedics & Neurosurgery, Regence BlueShield, Republic of Georgia, Rhode Island Health Information Exchange, River Region Cardiology, RM Group of Education, Rochester City School District, Salinas City Elementary School District, San Francisco-Marin Food Bank, Sanrio Entertainment, Sante PACS Server, Santee School District, SAP NetWeaver, Scholastic, Self Esteem Brands, LLC, Siemens Tecnomatix, SimpleHelp RMM, SkilloVilla, Smiths Group, SonicWall SMA1000, Sony IVI, Sony XAV-AX8500, South African Weather Service, Speedio, Spring River Mental Health & Wellness, Square Medical Group, Stark AeroSpace, Sterling Bank, Subaru’s Starlink service, SuperDraft, the Taliban, TalkTalk, Tata Technologies, TD Bank, TeamViewer, Telefónica, Tesla Wall Connector, Texas Health and Human Services, Texas Tech University Health Sciences Center, The O’farrell Charter School, The Reshaping and Nutritional Company LLC, Thermomix Recipe World Forum, Tokio Marine HCC, Tornillo Independent School District, Trump Hotels, Tycon Medical Systems, Ubiquiti charger, UEFI, UFCW Local 135, University Diagnostic Medical Imaging, University of Notre Dame, Upper Canada District School Board, Valio, Valley News Live, Veeam, VMware Avi Load Balancer, VSCode SSH Agent, W3 Total Cache, Wacom, Wavlink AC3000, Welhof, Westend Dental, Wetaskiwin Regional Public Schools, WhoDB, Willow Pays, WinZip, Wolf Haldenstein, WOLFBOX EV charger, WOLFBOX Level 2 EV Charger, WordPress ASE Plugin, Ya-Moon, Yazoo Valley Electric Power Association, YesWiki, York Region District School Board, Young Consulting LLC, Youthmanual, Yubico pam-u2f, ZAR rehab clinics, Zendesk, Zimbra, Zyxel CPE routers, and Zyxel USG Flex and ATP firewalls, have reported hacking or compromises this month.

Bitbucket, Bohemia Interactive (DayZ and Arma Reforger), Cloudflare’s R2 object storage, Conduent, Garmin GPS watches, GitHub, Lee Enterprises, Microsoft 365, and PlayStation Network have suffered from outages this month.

Last months updates broke Microsoft 365 on Windows Server OS, “New” Outlook, Outlook email composition, Outlook search, USB audio drivers, Windows Activation, and Windows Server 2022.

Microsoft is now force-installing “new” Outlook (“Outlook Fred” for those in the know). Recently, Microsoft has been changing the management methods to prevent installation faster than they release updates to the software or tell their customers of the new policy changes, making it an administrative nightmare. I figure it will be either a class-action lawsuit, a federal (or EU) racketeering case, or an enterprise-wide wake-up to switch to Thunderbird that will finally get Microsoft to (briefly) start respecting their customers that have (oft repeatedly) expressly signalled their desire to opt out of this crap.

Microsoft is saying they’re going to stop supporting installing updates for Office apps on Windows 10 after it reaches end-of-life in October. This is probably BS, since they’ve never prevented installing Office updates on previous operating systems when they reached end-of-life, but you should switch from Windows 10 by then for other reasons anyway.

This doesn’t bode well for Let’s Secure Insurance. Ouch.

A year after announcing that it would be imposing a new UEFI signature and mere months before mandatory enforcement, Microsoft has finally released a script to create media that can boot using the new requirements.

Amazon has (finally) improved the default settings for Redshift to reduce the number of data leaks using their platforms.

The FTC has ordered GM to stop selling OnStar customer data (such as precise geolocation and driving behavior) without obtaining express consent.

In a surprise to literally nobody, security researchers learned that if you install bad things on your device, bad things can happen!

Now for the good news:

A lawsuit against automatic license plate readers is allowed to proceed.

Brave now allows you to inject custom JavaScript to tweak websites without an extension. 🙂  This comes only weeks after adding the ability to Rerank websites in the Brave Search engine.

Most importantly: Ross Ulbricht is free.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is not that bad this month. The typical computer should see roughly 3.5 GB in updates today. Let’s get started.

Microsoft released 41 updates to address 67 vulnerabilities in Active Directory Domain Services, Azure Network Watcher, Microsoft AutoUpdate (MAU), Microsoft Digest Authentication, Microsoft Dynamics 365 Sales, Microsoft Edge (Chromium-based), Microsoft Edge for iOS and Android, Microsoft High Performance Compute Pack (HPC) Linux Node Agent, Microsoft Office, Microsoft Office Excel, Microsoft Office SharePoint, Microsoft PC Manager, Microsoft Streaming Service, Microsoft Surface, Microsoft Windows, Open Source Software, Outlook for Android, Visual Studio, Visual Studio Code, Windows Ancillary Function Driver for WinSock, Windows CoreMessaging, Windows DHCP Client, Windows DHCP Server, Windows Disk Cleanup Tool, Windows DWM Core Library, Windows Installer, Windows Internet Connection Sharing (ICS), Windows Kerberos, Windows Kernel, Windows LDAP, Windows Message Queuing, Windows NTLM, Windows Remote Desktop Services, Windows Resilient File System (ReFS) Deduplication Service, Windows Routing and Remote Access Service (RRAS), Windows Setup Files Cleanup, Windows Storage, Windows Telephony Server, Windows Telephony Service, Windows Update Stack, Windows Win32 Kernel Subsystem, and MSRT. This includes security updates. A reboot is required.

Oracle released 301 security updates this quarter to address vulnerabilities in 109 applications.

Apple released updates for GarageBand 10.4.12, iOS 18.3, iOS 18.3.1, iPadOS 17.7.4, iPadOS 17.7.5, iPadOS 18.3, iPadOS 18.3.1, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, Safari 18.3, tvOS 18.3, visionOS 2.3, and watchOS 11.3. This includes security updates. Use Apple Software Update to install the most current versions.

iOS 18.3 and 18.3.1 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 17.7.4, 17.7.5, 18.3 and 18.3.1 are security updates. Use Settings, General, Software Update to install the most current update.

watchOS 11.3.1 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 18.3 is a security update. Use System, Software Update to install the most current version.

visionOS 2.3.1 is a security update. Use System, Software Update to install the most current version.

Google ChromeOS 132.0.6834.98 and Google ChromeOS LTS 126.0.6478.264 are security updates. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sequoia (15.x) means that macOS Monterey (12.x) and older are no longer supported. If you can not install at least macOS Ventura (13) on your Mac then you should immediately remove your device from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v24H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it. If not, switch to Linux (Mint is nice) or replace your computer.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with a SaferPC Subscription and we will install updates each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Epson ET-2750 2.71.00 doesn’t provide a change log so should be treated as a security update.
https://epson.com/Support/Printers/All-In-Ones/ET-Series/Epson-ET-2750/s/SPT_C11CG22201

Epson ET-3760 2.68.02 doesn’t provide a change log so should be treated as a security update.
https://epson.com/Support/Printers/All-In-Ones/ET-Series/Epson-ET-3760/s/SPT_C11CG20203

Epson ET-3850 3.01 doesn’t provide a change log so should be treated as a security update.
https://epson.com/Support/Printers/All-In-Ones/ET-Series/Epson-ET-3850/s/SPT_C11CJ61201

Epson ET-4800 3.05 doesn’t provide a change log so should be treated as a security update.
https://epson.com/Support/Printers/All-In-Ones/ET-Series/Epson-ET-4800/s/SPT_C11CJ65201

Epson ET-5880 3.04.00 doesn’t provide a change log so should be treated as a security update.
https://epson.com/Support/Printers/All-In-Ones/ET-Series/Epson-ET-5880/s/SPT_C11CJ28201

UniFi Network Server 9.0.114 resolves over a dozen bugs and improves Zone controls. This is not a security update.
https://www.ui.com/download/releases/network-server

VIISAN OfficeCam 7.2.6.0 doesn’t provide a change log so should be treated as a security update.
https://www.viisan.com/en/download/type1.html

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.75.175 is a security update.
https://brave.com/

Google Chrome 133.0.6943.53 is a security update.
https://www.google.com/chrome/

Firefox 135.0 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 128.7.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Vivaldi 7.1.3570.48 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Mailspring 1.15.1 resolves several bugs. This is not a security update.
https://getmailspring.com/

Spark 3.20.4 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 128.7.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 9.0.2 resolves several bugs. This is not a security update.
https://anydesk.com/en/downloads

curl 8.12.0 is a security update.
https://curl.haxx.se/windows/

Discord February 3, 2025 adds several new performance improvements and privacy controls, as well as cosmetic and stability improvements. This is not a security update.
https://discord.com/download

Dropbox 217.4.4417 doesn’t provide a detailed change log so should be treated as a security update.
https://www.dropbox.com/

FreeFileSync 14.0 adds dark mode support, improves cosmetics and resolves several bugs. This is not a security update.
https://www.freefilesync.org/download.php

Google Drive 104.0 is a security update.
https://drive.google.com/start

Grocy Desktop 2.12.1 updates the Grocy release and fixes dependencies. This is not a security update.
https://github.com/grocy/grocy-desktop

Microsoft Teams 1.8.00.1362 adds several new management and organizational features. This is not a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 30.0.5 resolves dozens of bugs. This should be treated as a security update.
https://nextcloud.com/

PuTTY 0.83 resolves several bugs. This is not a security update.
https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html

Signal 7.41.0 resolves several bugs. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.32.3 improves organization. This is not a security update.
https://signal.org/android/apk/

Technitium DNS Server 13.4.1 should be treated as a security update.
https://technitium.com/dns/

Telegram 5.10.7 resolves several bugs. This is not a security update.
https://telegram.org/

Zoom 6.3.6.56144 adds a “new and improved” sidebar and resolves several bugs. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.13 improves rigging motions. This is not a security update.
https://en.3tene.com/

Grayjay 281 resolves compatibility issues. This is not a security update.
https://grayjay.app/index.html

KaraFun Player 3.4.6 improves stability and performance, ARM compatibility, and resolves several bugs. This is not a security update.
https://www.karafun.com/karaoke-windows/

Kodi 21.2 resolves dozens of bugs. This is a security update.
https://kodi.tv/

Plex Desktop 1.107.2.300 resolves a compatibility bug. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Home Theater 1.70.1.303 updates libraries and now improves privacy on Linux. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.60.10 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

PS5 2025.115 improves performance and usability. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2025.01.28 resolves several bugs. This is not a security update.
https://store.steampowered.com/news/app/593110

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Commerce 2.4.8-beta2, 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 1.5.1, 1.4.2-p4, 1.3.5-p9, 1.3.4-p11, 1.3.3-p12, 2.4.8-beta2, 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12 are security updates.
https://helpx.adobe.com/security/products/magento/apsb25-08.html

Adobe Illustrator 28.7.4 and 29.2.1 are security updates.
https://helpx.adobe.com/security/products/illustrator/apsb25-11.html

Adobe InCopy 19.5.2 and 20.1 are security updates.
https://helpx.adobe.com/security/products/incopy/apsb25-10.html

Adobe InDesign 19.5.2 and 20.1 are security updates.
https://helpx.adobe.com/security/products/indesign/apsb25-01.html

Adobe Photoshop Elements 2025.1 is a security update.
https://helpx.adobe.com/security/products/photoshop_elements/apsb25-13.html

Adobe Substance 3D Designer 14.1 is a security update.
https://helpx.adobe.com/security/products/substance3d_designer/apsb25-12.html

Adobe Reader DC 24.005.20399 resolves several crash bugs. This is not a security update.
https://get.adobe.com/reader

Adobe Substance 3D Stager 3.1.1 is a security update.
https://helpx.adobe.com/security/products/substance3d_stager/apsb25-09.html

Artweaver 8.0.2 resolves several bugs. This is not a security update.
https://www.artweaver.de/

Calibre 7.25.0 resolves several bugs and improves compatibility. This is not a security update.
https://calibre-ebook.com/

Columns++ 1.1.5 improves compatibility. This is not a security update.
https://github.com/Coises/ColumnsPlusPlus

Krita 5.2.9 massively improves text support. This is not a security update.
https://krita.org/en/download/

LibreOffice Fresh 25.2.0 resolves almost 300 bugs. This is a security update. Please do not use the “Fresh” line – use the stable release instead.
https://www.libreoffice.org/

Manager 25.2.9.2075 improves inventory controls. This is not a security update.
https://www.manager.io/

Notepad++ 8.7.7 resolves several bugs. This is not a security update.
https://notepad-plus-plus.org/

Paint.net 5.1.3 resolves over a dozen bugs. This is not a security update.
https://www.getpaint.net/

PDF-XChange Editor 10.5.1.394 improves cosmetics and resolves over a dozen bugs. This is not a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

Operating System Updates

These are for specific Linux flavors and alternative operating systems and, sadly, are unlikely to be of interest to most people.

iOS 18.3.1 is a security update. Use Settings, General, Software Update to get the most current version.

iPadOS 17.7.5 and iPadOS 18.3.1 are security updates. Use Settings, General, Software Update to get the most current version.

macOS 15.3.1 is a security update. Use Settings, General, Software Update to get the most current version.

Tails 6.12 is a security update.
https://tails.net/install/download/index.en.html

tvOS 18.2.1 and tvOS 18.3 are security updates. Use Settings, General, Software Update to get the most current version.

watchOS 11.3.1 is a security update. Use the Watch app from your iPhone to install the current version.

Security Software Updates

One or more of these is likely to be of interest to most people.

.NET Runtime 9.0.1 is a security update.
https://dotnet.microsoft.com/en-us/download/dotnet

Java 8u441 is a security update.
https://www.java.com/en/download/manual.jsp

MalwareBytes Desktop Security 5.2.6.163 resolves a quarantine bug. This should be treated as a security update.
https://www.malwarebytes.org/antimalware/

ProtonVPN 3.5.1 improves stability and performance. This is not a security update.
https://github.com/ProtonVPN/win-app/releases/latest

RogueKiller 16.0.2 resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

Stinger 13.0.0.283 adds support for new detections. This is not a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

SuperAntiSpyware 10.0.1272 adds a new Browser Protection feature and resolves several bugs. This should be treated as a security update.
https://www.superantispyware.com/download.html

Windows Defender Offline 20250119 doesn’t provide a change log so should be treated as a security update.
https://windows.microsoft.com/en-us/windows/what-is-windows-defender-offline

Wireless Network Watcher 2.42 updates the internal MAC addresses database. This is not a security update.
https://www.nirsoft.net/utils/wireless_network_watcher.html

Capture Updates

These are unlikely to be of interest to most people.

Open Broadcaster Software 31.0.1 resolves several crash and stability bugs. This is not a security update.
https://obsproject.com/

SnagIt 24.3.2 is a security update.
https://www.techsmith.com/screen-capture.html

VideoCacheView 3.11 improves support for newer Chrome (v132+) cache structure. This is not a security update.
https://www.nirsoft.net/utils/video_cache_view.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.3.5 adds support for MP4/MKV AV1 output, improved hardware acceleration and resolves an audio quality bug. This is not a security update.
https://www.dvdfab.cn/download.htm

FFmpeg 20250204 resolves an SVT-AV1 API compatibility issue. This is not a security update.
https://ffmpeg.org/ffmpeg.html

IsoBuster 5.5.2 resolves compatibility issues with CD-i and macOS generated media, and special characters in file and folder names. This is not a security update.
https://www.isobuster.com/download.php

MakeMKV 1.17.9 changes only the version number. This is not a security update.
https://www.makemkv.com/download/

PDF Creator 5.3.3 resolves several bugs. This is not a security update.
https://www.pdfforge.org/pdfcreator

StreamFab 6.2.2.0 improves compatibility. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 3.0.0.5 adds Colorizer support and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.10.60 resolves several bugs. This is not a security update.
https://1password.com/downloads/

Beyond Compare 5.0.5.30614 updates libraries and resolves several bugs. This is not a security update.
https://www.scootersoftware.com/download

Bitwarden 2025.1.4 now imposes 2FA for new sessions and unknown locations, adds ability to generate SSH keys, and resolves several bugs. This is not a security update.
https://bitwarden.com/

CCleaner 6.32.11432 resolves several bugs. This is not a security update.
https://www.ccleaner.com/

CPU-Z Installer 2.14 adds support for newer hardware and resolves a cosmetic bug. This is not a security update.
https://www.cpuid.com/softwares/cpu-z.html

Cygwin 3.5.7 resolves several bugs. This is not a security update.
https://cygwin.com/

Dell OS Recovery Tool 2.4.2.2193 doesn’t provide a change log so should be treated as a security update.
https://www.dell.com/support/home/uk/en/ukbsdt1/drivers/osiso/recoverytool

DesktopOK 11.57 improves uninstall and automatic update. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.3.3.0 updates libraries, adds several new features (Show Replacements, Minimize & Restore, Replace dialog layout) and updates translations. This is a security update.
https://dngrep.github.io/

GoodSync 12.8.2 adds a new @file filter, improves compatibility and rearranges job options. This is not a security update.
https://www.goodsync.com/

GUIPropView 1.31 adds several new columns to the display. This is not a security update.
https://www.nirsoft.net/utils/gui_prop_view.html

Homedale 2.16 adds a Japanese translation. This is not a security update.
https://www.the-sz.com/products/homedale/

HWMonitor 1.56 adds support for newer hardware. This is not a security update.
https://www.cpuid.com/softwares/hwmonitor.html

LessMSI 2.5.0 adds ability to change languages in the GUI. This is not a security update.
https://lessmsi.activescott.com/

ManageWirelessNetworks 1.15 adds dark mode support. This is not a security update.
https://www.nirsoft.net/utils/manage_wireless_networks.html

NTLite 2025.01.10293 modifies more than a dozen Components features and resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

OSForensics 11.1.1001 resolves several bugs. This should be treated as a security update.
https://www.osforensics.com/download.html

osquery 5.15.0 resolves several bugs and improves data collection and display. This is not a security update.
https://osquery.io/downloads

PowerToys 0.88.0 updates libraries and resolves several bugs. This is a security update.
https://github.com/microsoft/PowerToys/releases/latest

PSAppDeploy 4.0.5 resolves dozens of bugs. This is not a security update.
https://psappdeploytoolkit.com/

TeamViewer 15.62.4 is a security update.
https://www.teamviewer.com/en-us/download/windows/

TraceRouteOK 3.46 improves uninstall and automatic update. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/TraceRouteOK

Ventoy 1.1.01 adds native remounting capability to support all Linux distros and resolves a couple bugs. This is not a security update.
https://www.ventoy.net/en/index.html

WakeMeOnLan 1.92 updates the internal MAC addresses database. This is not a security update.
https://www.nirsoft.net/utils/wake_on_lan.html

WinScan2PDF 9.25 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WizTree 4.24 adds several administrative features and cosmetic improvements. This is not a security update.
https://www.diskanalyzer.com/

Developer Updates

These are unlikely to be of interest to most people.

AutoHotkey 2.0.19 resolves several bugs. This is a security update.
https://www.autohotkey.com/download/

GDevelop 5.5.224 improves cosmetics and resolves several bugs. This is not a security update.
https://gdevelop.io/download

GitHub Desktop 3.4.16 resolves several bugs. This is not a security update.
https://desktop.github.com/

Go 1.23.6 is a security update.
https://go.dev/

MySQL ConnectorNet 9.2.0 resolves several bugs. This should be treated as a security update.
https://dev.mysql.com/downloads/connector/net/

Node.js 18.20.6 is a security update.
https://nodejs.org/en/

Node.js 20.18.3 is a security update.
https://nodejs.org/en/

Node.js 22.14.0 is a security update.
https://nodejs.org/en/

Node.js 23.7.0 is a security update.
https://nodejs.org/en/

Python 3.13.2 is a security update.
https://www.python.org/downloads/windows/

SQLite 3.49.0 resolves several bugs and improves performance. This is not a security update.
https://www.sqlite.org/download.html

Visual Studio Code 1.97.1 is a security update.
https://code.visualstudio.com/

WinMerge 2.16.46 resolves several bugs. This is not a security update.
https://winmerge.org/

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 7.1.6 adds support for Linux kernel 6.13 and resolves dozens of bugs. This is not a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

Invision Community 4.7.20 adds Postmark, Bluesky and Backblaze B2 support. This is not a security update.
https://invisioncommunity.com/

Grocy 4.4.1 adds support for Open Food Facts barcode lookup and resolves several bugs. This is not a security update.
https://github.com/grocy/grocy

MailEnable 10.51 is a security update.
https://www.mailenable.com/

ownCloud Client 5.3.2.15463 is a security update.
https://owncloud.com/desktop-app/

phpMyAdmin 5.2.2 is a security update.
https://www.phpmyadmin.net/

WordPress 6.7.2 resolves 35 bugs. This is not a security update.
https://wordpress.org/

Really Simple CAPTCHA 2.4 improves hash strength and compatibility. This is not a security update.
https://wordpress.org/extend/plugins/really-simple-captcha/

Sucuri Security 1.9.8 adds CORS configuration. This is not a security update.
https://wordpress.org/extend/plugins/sucuri-scanner/

WP Cerber Security 9.6.6 resolves several bugs. This is not a security update.
https://wpcerber.com/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2024-12-10

Merry Christmas, Folks!

Today is Patch Tuesday for December, 2024.

I recommend waiting one more month before upgrading to Windows 11 24H2 or macOS 15/Sequoia.

Windows 10 will be end-of-life in only 10 months. If your Windows 10 (or older) computer can not be upgraded to Windows 11, or if you used a registry or installation bypass to install an older version of Windows 11 on it that is no longer supported, then it’s time for you to start looking for a replacement computer. Windows 10 now has only 10 months of support left and by April it will be challenging to find a good and inexpensive replacement computer that will be supported for Windows 11. Christmas sales are on now. There’s not going to be any better time in the next year.

There were 730+ major hacks, and over 270 application updates this month. It’s a small month with about 2.0 GB of updates for most users.

This Month in Technology

.NET, 1547 Critical Systems Realty, 2014-2021 Mazda infotainment system, 3M, 4QuartersIT, 7-Zip, A & L Auto Recyclers, A&O IT Group, A-1 Mobile Lock & Key, ABC Group, Aberdeen, Acadia Pharmaceuticals Inc, ACao.org, Ace Laboratories Limited, Adams Homes, Adobe InDesign, ADT Freight Services Australia Pty Lt, Advanced Chemical Industries, Advantech’s EKI-6333AC series wireless access points, AdventHealth, AEAT, Aeris Energy, AHN, Ahold Delhaize, Airbnb, Albazaar, Albertsons, Alder Hey Children’s Hospital, All Construction Group WV, Allegheny Contract, Allegheny Millwork & Lumber, Alliance Industries, LLC, Alliance Sports Group, ALLTUB Group, Alna-Bioscience, Alpine Ear Nose & Throat, Amazon, American Addiction Centers, Inc, American Associated Pharmacies, AMGtime, Amherstburg Family Health, Anderson Miller LTD, Andrew Tate’s The Real World, Anex Baby, Anna Jacques Hospital, AnnieMac Home Mortgage, Apache ActiveMQ, Apache Tomcat, Aperion Care Marseilles, LLC, Apple iOS, Apple iPadOS, Apple macOS, Apple Pay, Apple Safari, Apple visionOS, Applied Materials, Arc Community Services Inc, Ardon Health, LLC, Array Networks SSL VPN, Arrowe Park Hospital, Artistic Family Dental, Artivion, Asaro Dental Aesthetics, Ascend Packaging Systems, ASM Global, Aspen Healthcare Services, AT&T, ATD-American, Athens County Bd of Dev Disabilities, Atlantic Orthopaedic Specialists, Atrium Health, Auchan, Automation Tool & Die, Avast Anti-Rootkit, Avico Spice, Axpr Valve Science, BackChecked, LLC, Barneek Safety Consultancies, BBS Financial Services, LLC, BBVA Bank, Beach Guide, Bedminster School, Bells Tax Service, Bendheim, Berexco LLC, Bergeron LLC, Berkshire Nursing & Rehab Center, LLC, BIC, Billaud Segeba, Bio-Clima Service Srl, Birdair, Bishop Ireton High School, BJ’s Wholesale Club, Black Creek Community Health Centre, Blue Yonder, BluMed Health, BMW Chile, Bob’s Discount Furniture, Boksha, Bologna Football Club 1909, Bolton Walk-In Clinic, Bonpoint, Borah, Goldstein, Altschuler, Nahins & Goidel, PC, Boston Chinatown Neighborhood Center, Brazilian databases, Bridge Valley Community & Technical College, Bristol-Myers Squibb, British Army, Brodsky Renehan Pearlstein & Bouquet, Brueck Golosow Kim & Associates, BT Group, Buddy Loan, Bulbrite Industries, Burkburnett Independent School District, Burmeister & Wain Scandinavian Contractor, Business Systems House FZ-LLC, Buyoplace, Cabot Financial, Calgary’s Fueling Brains Academy, Calibrated Healthcare, LLC, CalSTRS, Campinas City Government, Canada Post, Cardinal Health, Cardiology Associates of Mobile, Cargill, Carnegie Hill Imaging for Women, Carnegie Women’s Health, CarSwitch.com, Cate Equipment, CC Senior Services, CelPlan Technologies, Central Bank of Uganda, Central Group, Centrex, Chanas Assurances SA, Charles Schwab, ChatGPT, Chema Per, Chemonics, Cherry Hill School District, CHS Plumbing, Cian.ru, Cipla, Cisco, Citadel of Northbrook, Citrix’s Session Recording Manager, City National Bank, City of Coppell, CK Power Public Manufacturing, Claro, Clipper DEX, Closelly, Club Fit Software, CMC Construction Material, CNHW Landscape Design, Ltd, CO-VER Power Technology SpA, Colombian Government, Colonial Behavioral Health, Colwell Colour, Complete Control, Complete Recycling Services, Compra LTD Aruba, Concord Orthopaedics, Conlin’s Pharmacy, Connecticut GI, Consumers Builders Supply, Contrack Facilities Management, Coppell, TX, Corman Leigh, Costa Rica’s RECOPE, Cottles Asphalt Maintenance Inc, CP Construplan, CPanel, Crate & Barrel, Cundinamarca Colombia, CURVC Corp, Dairy Farmers of Canada, Darlington EMS, Dassault Systèmes eDrawings Viewer, Data Campos Sistemas, Datamaxx Applied Technologies, Datron World Communications, David’s Bridal, Dell India, Delmar International, Deloitte UK, Delta Air Lines, Delta Dental, DeltaPrime, DemandScience, Dennis Kirk, Destatis, Deutsche Industrie VideoSystem, Dewan Farooque Motors Limited, DFA NY, Diamond Brand Gear, DieTech North America, Dillons, DIRSAPOL, Django, DMF Lighting, DMM Bitcoin, DocuSign, Dohman, Akerlund & Eddy, Dolton Nursing & Rehab, LLC, Dome Construction Corporation, Dominican Republic, Don’s Mobile Glass, Dorner Law & Title Services, Down East Granite, Dragon Capital, Drupal, Dumont Printing, Eagle Bank, Eassy Life, East Central Missouri Behavioral Health Services, Inc, East Paris Internal Medicine Associates, Eastgate Auto, EazyDiner, ECBM, Ecobank Ghana, Edizionidottrinari.it, Edwardsburg Schools Foundation, El Dorado Stores and Supermarkets, El Dorado Union High School District, Electrica, Empower Settlement Services, Empowerers, Emserpa, ENGlobal, Enso Counseling Group, PLLC, EP:Schuller, Epic Games Launcher, Equentis Wealth, Equinox Inc, ESHA, Inc, Evening Post Publishing Inc, Everything Breaks, Express Employment Professionals, Familylinks Inc, Fancy Foods, Farmers Insurance, Feronow, FF Steel, Fidelity Investments, Financial Business and Consumer Solutions, Finastra, Find Great People1, Finsure, Firmenich, Fleet Equipment Center, FlipaClip, Followup CRM, Ford, Fortinet VPN servers, Fortinet’s FortiClient Windows VPN, Fred Meyer, Fuji Electric Monitouch V-SFT, Fujian Provincial Government, Fuju Electric Tellus Lite V-Simulator, FunkLocker, Fylde Coast Academy Trust, G Adventures Inc, G DATA Total Security, Gallos MetalSolutions Inc, Gastroenterology Associates of Fairfield, Gazprombank, GC Custom Metal Fabrication, GeoVision devices, Giggle Finance, Globe Telecom, GMG, GoCast, GoCloud Router, Godot game engine, Goethe University Frankfurt, GoFormz, Goldsmith & Hull, Goodwill North Central Texas, Google Pay, Gough Construction, Grand Forks Public Schools, Grandview School District, Great Plains Regional Medical Center, Great Star Tools USA, Gregory Poole, Gruber Tool & Die, Guard1, Gulf Energy Maritime, Gulf Petrochemical Services & Trading, H2OBX Waterpark, Hackus Mail Checker, Hadwins Volkswagen, Hager Group, Harel Insurance, HDFC Life Insurance, HealthFund Solutions, Henderson Stamping & Production, Highland Park ISD, Hillandale Farms, Hive Power Engineering, HM Environmental Services, Hoboken, NJ, Hogan Mfg, Holstrom, Block & Parke APLC, Horsa, Hosting.co.uk, Hotels.co.il, Houston Housing Authority, HP, HPE Insight, HSBC, Hugging Face Transformers, Hypertype, I-O Data routers, IAС, IFA Paris, IGT, iLearningEngines, Immobilière Essaouira, Indian Government Volunteer Database, IndicaOnline, Instinct Pet Food, Intel Computing Improvement Program, Intel Driver & Support Assistant, InterCon Construction, IPE Engwicht, IrfanView, Irr Supply Centers, Island Photo, Israel’s Ministry of National Security, IT Networks, ITO EN, Ivanhoe Club, Ivanti Avalanche, Ivanti Endpoint Manager, Ivanti Secure Access Client Pulse Secure, IVC Technologies, James H Maloy, Jefferson Dental Center, Inc, Jergens Piping, Jewel-Osco, JF Zengyoren, Jones & Mayer, Jones Lang LaSalle, JTEKT North America, Jupyter servers, K-State College of Veterinary Medicine, Karl Malone Toyota, Kash Patel’s Emails, Kashin App, KCI Aviation, Keable & Brown, Keesal, Young & Logan, Keizer’s Collision CSN & Automotive, Kela Health, Kellerhals Ferguson Kroblin PLLC, Kelowna Springs, Kenmore, Kennedy Funding, Kenwood DMX958XR, Kingswood Park, Kmart Australia, Kroger, KTBS Law LLP, Kulicke and Soffa Industries, LA Financial Federal Credit Union, LA LUCKY Brand, Laboratory Services Cooperative, Ladies.com, Lazz Hotel, LBCO Contracting LTD, LCPtracker, Inc, Lebak Regency, Leidos, LenelS2, Lenovo, LePoint.fr, LevelOne WBR-6012, Levicoff Law Firm, PC, Liberty Endo, Liberty First Credit Union, Lima Puluh Kota Regency, LINDOSTAR, LinkedIn, Linux nftables, LiquiTech, Live Aquaria, Liverpool Heart and Chest Hospital, LIXIL, LLama Factory, Lottie-Player, Lotus Concepts Management, LTI Trucking Services, Lubbock County Hospital District, Lucid Corp, Luka Rijeka, Luxion KeyShot, macOS, Madison Home, Magguilli Law Firm, Mantinga, Marine Stores Guide, Marketing Incentives, Massachusetts Department of Developmental Services, Maternal Fetal Medicine Associates, Matlock Security Services, MATRIX, Max Trans, Maxar Space Systems, Maxeon, Maxus Group, MC Technologies MC LR Router, McDonald’s, McKibbin, McLean Mortgage, McLeod Russel India, MDLand International, MediBoard, Medical Board of California, Medical Technology Industries, Inc, Members Trust Company, MetLife, Metroline, Mexican Government, Microlise, Microsoft 365 Admin Portal, Microsoft Office PowerPoint, Microsoft Power Pages, Microsoft SharePoint Server, Microsoft Windows, Mid-Ohio Psychological Services, Midland Tool, Miller & Smith, Minneapolis Parks, Minuteman Press, Misionero Vegetables, Mitel MiCollab, Mizuno USA, Mobigator Technology Group, Monster Electrical, Moodle, Morehead State University, Morrisons, Mullen Wylie, LLC, Nanosoft, NatAlliance Securities, Nationwide Legal, NCISM NEET, New Age Micro, Newpark Resources, Nicholsons Solicitors, Nokia, Norauto.fr, Northeast Spine and Sports Medicine, Northern Schools and Academy, NTrust, Numocity, NVIDIA UFM, Ocean Beauty Seafoods, Ocean Park Mechanical, OfficeZilla, Oklahoma Medical Center, Omnicom Group, OnePoint Patient Care, OpenWrt, Optical Cable Corporation, Option Care Health, Oracle Agile Product Lifecycle Management, Orange County Pathology Medical Group, Orshan, Spann & Fernandez-Mesa, Orthopedics Rhode Island, Otsego Public Schools, over 2,000 Palo Alto Networks firewalls, Overseas Shipholding Group, Inc, Oxford Auto Insurance, Pacific Pulmonary Medical Group, Pallet Logistics of America, Palm Facility Services, Pan Gulf Holding, Panda Security Dome, Panzer Solutions LLC, Pastor Real Estate, Patrick Sanders and Company, PC, Pavilion of Bridgeview, PC AfterHours, Pemberton Fabricators, Inc, Pensacola, Perfection Plus Services Inc, Performance Health & Fitness, Peruvian Army Military School, Philippines GCash, Physicians’ Primary Care of Southwest Florida, PIH Health, Pincu Barkan, Law Office and Notary, Pine Belt Cars, Pinnacle Claims Management, Pinnacle Plastic Products, Pioneer Urban Land & Infrastructure, PK Mulyo, Planned Parenthood of Montana, PoinCampus, PointClickCare, Polter Finance, Popular Life Insurance, Port of Rijeka, PostgreSQL, Precision Walls, Premier Packaging, Premier Tax Services, Privat Spitex, Programs Improving Public Safety, Progress Kemp LoadMaster, ProjectSend, QNAP, Quality Billing Service, Radiologic Medical Services, PC, Ralphs, RBN Insurance Services, Rclone, RDC, RDS Electric, Refinadora Costarricense de Petróleo, RemoteStaff.com.au, Rengo Packaging, REV Engineering, Rex Signature Services, LLC, RiverRestHome, RJM Marketing, Roblox, Rockford Gastroenterology Associates, Rocky Mountain Gastroenterology, Romanian Permanent Electoral Authority, Royal Liverpool University Hospital, Royce Corporation, RRCA Accounts Management, RSA Security SecureID, Rush University, S-Zdorovie, Safaricom, Safeway, SAG-AFTRA Health Plan, SailPoint IdentityIQ, Sainsbury’s, Saint Andrews Bureau, SalonBiz, San Francisco Ballet, Sanford Behavioral Health, Sango Family Dentistry, 240,000 satellite receivers, Schneider Electric, Schuck-Gruppe, SCM GROUP, Sea Level Inc, SEAT SA, SelectBlinds, Senior Dating, Sercomm, Shaw’s, Sheboygan, WI, Ship Services, Siemens Tecnomatix Plant Simulation, Signal Health Washington, Signzy, SILKNET COMPANY, Silver Springs, Silverback Exploration, SK Gas, SKS Bottle & Packaging, SL Data Services, SmartDimensions, Smith’s, Snelling Paper & Sanitation, Solana JavaScript SDK, South Africa’s CSIR, South West Family Medicine Associates, Southern Oregon Veterinary Specialty Center, Specialty Bolt And Screw, Spotify, Spring EQ LLC, Sri Lanka Meteorological Department, SRP Federal Credit Union, SSGMCE, SSV Blockchain Network, Stalcop Metal Forming LLC, Standard Bank, Standard Calibrations, Star Shuttle Inc, Starbucks, Start-Rite, State of Arizona, Stauberstahl, STIIIZY, Surgical Associates, Symantric IT, Sécurité Nationale Systems, T&M Equipment, T-Mobile, Tacoma Engineers, Tamil Nadu GovMail, Tampa State Bank, Targus, TBM Consulting Group, TEAM Software, Tech Electronics, TechGuard, Tennis Canada, Terra Energy, Terrace of Hialeah, Texanscan, Texas Tech, Thala, Thames Water, The 1 Co, The Arbors Operator, LLC, The Mitchell Partnership, The PHOENIX, The Recycler Core, The Tech Interactive, Think Simple, Thunderbird Country Club, TIAA, Tillamook Country Smoker, Tinxy App, Toshiba Global Commerce Solutions, Total Patient Care LLC, Totally Promotional, TourPay App, Town of Whitestown NY Highway Department, Trace3, TravelSale, Travis Pruitt & Associates, Trell.co, Tribelsky, TriHealth Physician Partners, Trimble SketchUp, Trinity Petroleum Management, LLC, Tripura Gramin Bank, True World Holdings LLC, TrueNAS, Trust Seeds, Tully’s Coffee Japan, Turf Paradise, TWRU CPAs & Financial Advisors, U.S. Bank, U.S. Department of Veterans Affairs, U.S. Library of Congress, UATF, UBS, Ubuntu Linux, UCC Retrievals, UK England and Wales prisons, Ultralytics YOLO11, UMC Health System, Unilever Brazil, United Bakery Equipment, United Seating and Mobility, UniversalPegasus International, Universidad Peruana de Ciencias Aplicadas, URBN, URL-Log-Pass, Uruguay’s Partido Nacional, USA Network, USA2ME, USAID, Valley Planing Mill, Value Dental Center, VBÜ, Veeam Backup Enterprise Manager, Ventana Micro Systems, Verizon, Vermilion Parish School System, Veterans Health Administration, VIA Health Partners, Village Pharmacy Group, ViralPitch, Visiting Physician Services of Michigan, Vista Point Mortgage, LLC, VMware vCenter Server, Vogue Homes, Volgograd State Medical University, Vox Printing, VozoHealth, VPS of MI PLLC, VRSEC, VTB Bank, vTech Solution, Walae Cristal, Walsworth Publishing Company, Washington State Court systems, Waters Truck and Tractor, Watsonville Community Hospital, Weld Racing, Wellfleet Group, LLC, West Bank Corp, Western Montana Mental Health Center, Westinghouse, WhatsUp Gold, Wheeler Associates, White Lake Township Hall, Wiley Metal Fabricating, WIN Empresas, Windows Server 2012, Wirral University Teaching Hospital, WolfBox E40, Word Check Sanctions, 500,000 WordPress sites,WordPress CleanTalk plugin, WordPress Really Simple Security/SSL plugin, WordPress WPLMS Learning Management System theme, WPM Pathology Laboratory, Wright Engineers, WTI, X-Cart Automotive, XnView, Xobin, Yakuza Helpline, Yazoo Valley Electric Power Association, York County, Yorozu Corporation, Zabbix, Zane Benefits, Zello, zero5, Zillertal Bier, Zimmerei Buder, Zimmerman & Frachtman PA Law Firm, and Zyloware have reported hacking or compromises this month.

itch.io (blame AI), PopeyeTools, Blue Yonder, Cloudflare, and Microsoft 365 have suffered from outages this month.

Last months updates broke Microsoft Exchange, TLS/SSL, Google Chrome, Windows Store apps, and Excel Add-ins, and force-installed Copilot.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is pretty small this month. The typical computer should see roughly 2.0 GB in updates today. Let’s get started.

Microsoft released 33 updates to address 73 vulnerabilities in GitHub, Microsoft Defender for Endpoint, Microsoft Edge, Microsoft Office, Microsoft Office Access, Microsoft Office Excel, Microsoft Office Publisher, Microsoft Office SharePoint, Microsoft Office Word, Remote Desktop Client, DNS Server, Windows Hyper-V, System Center Operations Manager, Windows Cloud Files Mini Filter Driver, Windows Common Log File System Driver, Windows File Explorer, Windows IP Routing Management Snapin, Windows Kernel, Windows Kernel-Mode Drivers, Windows LDAP – Lightweight Directory Access Protocol, Windows Local Security Authority Subsystem Service (LSASS), Windows Message Queuing, Windows Mobile Broadband, Windows PrintWorkflowUserSvc, Windows Remote Desktop, Windows Remote Desktop Services, Windows Resilient File System (ReFS), Windows Routing and Remote Access Service (RRAS), Windows Task Scheduler, Windows Virtualization-Based Security (VBS) Enclave, Windows Wireless Wide Area Network Service, WmsRepair Service, and MSRT. This includes security updates. A reboot is required.

Apple released updates for iOS 17.7.2, iOS 18.1.1, iPadOS 17.7.2, iPadOS 18.1.1, macOS Sequoia 15.1.1, Safari 18.1.1, and visionOS 2.1.1. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

iOS 17.7.2 and 18.1.1 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 17.7.2 and iPadOS 18.1.1 are security updates. Use Settings, General, Software Update to install the most current update.

visionOS 2.1.1 is a security update. Use System, Software Update to install the most current version.

Google Chrome OS LTS 126.0.6478.258 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sequoia (15.x) means that macOS Monterey (12.x) and older are no longer supported. If you can not install at least macOS Ventura (13) on your Mac then you should immediately remove your device from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v24H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it, but I recommend you continue to use Windows 10 until early 2025 before you consider switching to it.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with a SaferPC Subscription and we will install updates each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 24.12.1 improves compatibility and resolves several bugs. This is not a security update.
https://www.amd.com/en/support

Intel Driver and Support Assistant 24.6.49.8 is a security update.
https://www.intel.com/p/en_US/support/detect

Samsung DeX 2.4.1.27 doesn’t provide a change log so should be treated as a security update.
https://www.samsung.com/us/apps/dex/

TP-Link Archer A8 v2.26 230824 resolves several bugs. This is not a security update.
https://www.tp-link.com/us/support/download/archer-a8/v2.26/#Firmware

Wacom Driver 6.4.8-2 is a security update.
https://www.wacom.com/en-us/support/product-support/drivers

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.73.97 is a security update.
https://brave.com/

Firefox 133.0 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 128.5.1 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Google Chrome 131.0.6778.108 is a security update.
https://www.google.com/chrome/

Vivaldi 7.0.3495.23 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Spark 3.18.2.93439 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.18.2.93438 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 128.5.1 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 9.0.1 improves stability and resolves several bugs. This is not a security update.
https://anydesk.com/en/downloads

Dropbox 211.4.6008 resolves several bugs. This is not a security update.
https://www.dropbox.com/

FileZilla Server 1.9.4 resolves a configuration bug and improves compatibility. This is not a security update.
https://filezilla-project.org/

FreeFileSync 13.9 resolves several bugs. This is not a security update.
https://www.freefilesync.org/download.php

Google Drive 100.0 improves performance on macOS and resolves several bugs. This is not a security update.
https://drive.google.com/start

MeshCentral 1.1.35 improves compatibility and resolves dozens of bugs. This is not a security update.
https://meshcentral.com/info/downloads.html

Microsoft Teams 1.7.00.30955 improves export and data recall. This is not a security update.
https://teams.microsoft.com/downloads

Mumble 1.5.735 resolves over a dozen bugs. This is not a security update.
https://www.mumble.info/

Pocketnet-Core 0.22.8 is a security update.
https://pocketnet.app/

Pocketnet-GUI 0.9.103 resolves several bugs. This is not a security update.
https://pocketnet.app/

PuTTY 0.82 resolves several bugs. This is not a security update.
https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html

Rclone 1.68.2 is a security update.
https://rclone.org/

Signal 7.35.1 improves hardware compatibility and resolves several bugs. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.26.1 adds folders to improve organization. This is not a security update.
https://signal.org/android/apk/

Syncthing 1.28.1 resolves several bugs. This is not a security update.
https://syncthing.net/

Technitium DNS Server 13.2.2 resolves several bugs. This is not a security update.
https://technitium.com/dns/

Telegram 5.9.0 resolves several bugs including stability and display issues, and adds an affiliate program for bots.
https://telegram.org/

Telegram (Android) 11.4.2 doesn’t provide a detailed change log so should be treated as a security update.
https://telegram.org/apps

WinSCP 6.3.6 resolves several bugs. This is not a security update.
https://winscp.net/eng/index.php

Zoom 6.2.11.50939 resolves several bugs. This is a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.12 resolves a couple bugs. This is not a security update.
https://en.3tene.com/

Bitwig Studio 5.2.7 resolves a crash bug. This is not a security update.
https://www.bitwig.com/download/

Grayjay 269 adds landscape support, network sync, and resolves dozens of bugs. Thsi is not a security update.
https://grayjay.app/index.html

KaraFun Player 3.3.6.72 improves upgrade and import behaviors, support for CDG and community media, and resolves several bugs. This is not a security update.
https://www.karafun.com/karaoke-windows/

Plex Desktop 1.105.1.257 does not provide a detailed change log so should be treated as a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Home Theater 1.68.2.259 does not provide a detailed change log so should be treated as a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Media Server 1.41.2.9200 resolves several bugs. This is not a security update, but the next build is.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.50.10 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

Minecraft Server (Java) 1.21.4 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server

PS5 2024.111 improves upgrade and migration. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2024.12.04 resolves dozens of bugs. This is not a security update.
https://store.steampowered.com/news/app/593110

Office Updates

One or more of these are likely to be of interest to most people.

Aronium 1.44.0.1 resolves several bugs and improves internationalization. This is not a security update.
https://aronium.com/

Adobe Acrobat 24.005.20320, 24.001.30225 and 20.005.30748 are security updates.
https://helpx.adobe.com/security/products/acrobat/apsb24-92.html

Adobe Acrobat Reader 24.005.20320 and 20.005.30748 are security updates.
https://helpx.adobe.com/security/products/acrobat/apsb24-92.html

Adobe After Effects 24.6.3 and 25.1 are security updates.
https://helpx.adobe.com/security/products/after_effects/apsb24-95.html

Adobe Animate 23.0.9 and 24.0.6 are security updates.
https://helpx.adobe.com/security/products/animate/apsb24-96.html

Adobe Bridge 14.1.4 and 15.0.1 are security updates.
https://helpx.adobe.com/security/products/bridge/apsb24-103.html

Adobe Connect 11.4.9 and 12.7 are security updates.
https://helpx.adobe.com/security/products/connect/apsb24-99.html

Adobe Experience Manager 6.5.22 and 2024.11 are security updates.
https://helpx.adobe.com/security/products/experience-manager/apsb24-69.html

Adobe FrameMaker 2020.7 and 2022.5 are security updates.
https://helpx.adobe.com/security/products/framemaker/apsb24-106.html

Adobe Illustrator 28.7.3 and 29.1 are security updates.
https://helpx.adobe.com/security/products/illustrator/apsb24-94.html

Adobe InDesign 19.5.1 and 20.0 are security updates.
https://helpx.adobe.com/security/products/indesign/apsb24-97.html

Adobe Media Encoder 24.6.4 and 25.1 are security updates.
https://helpx.adobe.com/security/products/media-encoder/apsb24-93.html

Adobe PDFL SDK 21.0.0.7 is a security update.
https://helpx.adobe.com/security/products/pdfl-sdk1/apsb24-98.html

Adobe Photoshop 26.1 is a security update.
https://helpx.adobe.com/security/products/photoshop/apsb24-101.html

Adobe Premiere Pro 24.6.3 and 25.0 are security updates.
https://helpx.adobe.com/security/products/premiere_pro/apsb24-104.html

Adobe Substance 3D Modeler 1.15.0 is a security update.
https://helpx.adobe.com/security/products/substance3d-modeler/apsb24-102.html

Adobe Substance 3D Painter 10.1.2 is a security update.
https://helpx.adobe.com/security/products/substance3d_painter/apsb24-105.html

Adobe Substance 3D Sampler 4.5.2 is a security update.
https://helpx.adobe.com/security/products/substance3d-sampler/apsb24-100.html

Blender 4.3 resolves hundreds of bugs and improves hardware performance and compatibility. This is not a security update.
https://www.blender.org/download/

Calibre 7.22.0 resolves several bugs. This is not a security update.
https://calibre-ebook.com/

InDesign 19.5.1 and 20.0.1 are security updates.
https://helpx.adobe.com/security/products/indesign/apsb24-91.html

Kindle for PC 2.6.70964 doesn’t provide a change log so should be treated as a security update.
https://www.amazon.com/kindleforpc

LibreOffice Fresh 24.8.3 resolves over 80 bugs. This is not a security update.
https://www.libreoffice.org/

Manager 24.12.9.1973 doesn’t provide a detailed change log so should be treated as a security update.
https://www.manager.io/

Nextcloud Desktop 3.15.0 resolves dozens of bugs. This should be treated as a security update.
https://nextcloud.com/

Notepad++ 8.7.4 adds tab pinning and resolves several bugs. This is not a security update.
https://notepad-plus-plus.org/

Paint.net 5.1.1 resolves dozens of bugs and updates libraries. This a security update.
https://www.getpaint.net/

PDF-XChange Editor 10.4.4.392 is a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

QuickBooks Pro 2022 R18_32.1 adds filtering by prepayments in customer report. This is not a security update.
https://downloads.quickbooks.com/app/qbdt/products

QuickBooks Pro 2023 R14_60 doesn’t provide a change log so should be treated as a security update.
https://downloads.quickbooks.com/app/qbdt/products

Operating System Updates

These are for specific Linux flavors and alternative operating systems and, sadly, are unlikely to be of interest to most people.

ChromeOS 130.0.6723.126 is a security update.
https://chromereleases.googleblog.com/search/label/Stable%20updates+ChromeOS

elementary OS 8.0 is a major update adding session management containers, improved permission controls, Flatpack support out of the box, and expanded hardware support. This is not a security update.
https://elementary.io/

iOS 18.1.1 is a security update.
https://support.apple.com/kb/HT204204

iPadOS 18.1.1 is a security update.
https://support.apple.com/kb/HT204204

macOS 15.1.1 is a security update.
https://support.apple.com/kb/HT201541

Tails 6.10 is a security update.
https://tails.net/install/download/index.en.html

Security Software Updates

One or more of these is likely to be of interest to most people.

.NET Runtime 9.0.0 is a major update. This is a security update.
https://dotnet.microsoft.com/en-us/download/dotnet

FSS 2024.11.26 doesn’t provide a change log so should be treated as a security update.
https://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/

Gpg4win 4.4.0 resolves dozens of bugs. This should be treated as a security update.
https://www.gpg4win.org/download.html

MalwareBytes Anti-Malware 5.2.3.156 resolves several bugs. This is not a security update.
https://www.malwarebytes.org/antimalware/

ProtonVPN 3.4.3 updates libraries and resolves several bugs. This should be treated as a security update.
https://github.com/ProtonVPN/win-app/releases/latest

SanDisk PrivateAccess 6.4.12.0 doesn’t provide a change log so should be treated as a security update.
https://support-en.wd.com/app/answers/detailweb/a_id/48025

Stinger 13.0.0.234 is a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

SuperAntiSpyware 10.0.1270 adds support for several new browsers and resolves several bugs. This is not a security update.
https://www.superantispyware.com/download.html

uBlock Origin 1.61.2 resolves a couple bugs. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

Capture Updates

These are unlikely to be of interest to most people.

Open Broadcaster Software 31.0.0 is a major update. This version adds several integrations, updates libraries and resolves over a dozen bugs. This is not a security update.
https://obsproject.com/

SnagIt 24.3.0 adds rounded corners, improves PDF export support, and resolves a couple bugs. This is not a security update.
https://www.techsmith.com/screen-capture.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.3.1 improves compatibility and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/download.htm

HandBrake 1.9.0 improves hardware support and new encoding capabilities. This is not a security update.
https://handbrake.fr/

IsoBuster 5.5 adds support for new formats, new extension behavior, and resolves several bugs. This is not a security update.
https://www.isobuster.com/download.php

StreamFab 6.2.0.8 adds support for several new sources and resolves compatibility issues with a dozen others. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 2.0.3.8 improves stabilization, upscaling and performance. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Education updates

One or more of these are likely to be of interest to most people.

Zotero 7.0.11 resolves several bugs. This is not a security update.
https://www.zotero.org/

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.10.54 resolves a dozen bugs. This is not a security update.
https://1password.com/downloads/windows/

7-Zip 24.09 increases default dictionary sizes and resolves several bugs. This is not a security update.
https://www.7-zip.org/

Agent Ransack 2022.3499 resolves several bugs. This is not a security update.
https://www.mythicsoft.com/agentransack/download/

BatteryInfoView 1.26 adds option to sort log on each update and a 64-bit version. This is not a security update.
https://www.nirsoft.net/utils/battery_information_view.html

Beyond Compare 5.0.4.30422 resolves several bugs and improves skew and other controls. This is not a security update.
https://www.scootersoftware.com/download

Bitwarden 2024.11.2 doesn’t provide a detailed change log for this versions so should be treated as a security update.
https://bitwarden.com/

CCleaner 6.30.11385 improves cleaning of cloud services and some browsers and resolves several bugs. This is not a security update.
https://www.ccleaner.com/

DesktopOK 11.47 is a cosmetic change. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.2.113.0 updates libraries and resolves several bugs. This is a security update.
https://dngrep.github.io/

email-oauth2-proxy 2024-11-11 adds support for OAuth 2.0 Device Authorization Grant and improves compatibility. This is not a security update.
https://github.com/simonrob/email-oauth2-proxy

Fido 1.64 adds support for UEFI Shell 24H2 and a PlatformArch switch. This is not a security update.
https://github.com/pbatard/Fido/releases

FileLocator Pro 2022.3499 resolves several bugs. This is not a security update.
https://www.mythicsoft.com/filelocatorpro/download

FoneTool 2.9.3 resolves a couple bugs. This is not a security update.
https://www.fonetool.com/download.html

GoodSync 12.7.9 improves OAuth2 support and resolves several bugs. This is not a security update.
https://www.goodsync.com/

grepWin 2.1.7 resolves a couple bugs. This is not a security update.
https://github.com/stefankueng/grepWin/releases/latest

GSmartControl 2.0.1 resolves a crash bug. This is not a security update.
https://gsmartcontrol.shaduri.dev/

Homedale 2.14 changes cosmetics. This is not a security update.
https://www.the-sz.com/products/homedale/

IsMyHdOK 4.14 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

HWiNFO 8.16 improves hardware detection and support for newer hardware. This is not a security update.
https://www.hwinfo.com/download/

Memtest86+ 7.20 adds support for newer hardware and resolves several bugs. This is not a security update.
https://www.memtest.org/

NTLite 2024.12.10210 resolves a couple bugs. This is not a security update.
https://www.ntlite.com/download/

PropertySystemView 1.21 adds an always on top option. This is not a security update.
https://www.nirsoft.net/utils/windows_property_system_view.html

PSAppDeploy 4.0.3 resolves dozens of bugs. This is not a security update.
https://psappdeploytoolkit.com/

SearchMyFiles 3.31 resolves a crash bug. This is not a security update.
https://www.nirsoft.net/utils/search_my_files.html

TeamViewer 15.60.3 improves display, device and user filtering, and resolves several bugs. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/

WinGet 1.9.25200 adds Sixel support, self-elevation, and resolves a compatibility bug. This is not a security update.
https://github.com/microsoft/winget-cli/releases/latest

WinScan2PDF 9.13 adds alternate page rotation support. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WizTree 4.23 resolves several bugs. This is not a security update.
https://www.diskanalyzer.com/

XnConvert 1.102.0 adds filelist support. This is a security update.
https://www.xnview.com/en/xnconvert/

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 2024.2.1.12 resolves several bugs. This is not a security update.
https://developer.android.com/studio

GDevelop 5.4.219 improves layer support, project templates, and resolves over a dozen bugs. This is not a security update.
https://gdevelop.io/download

Go 1.23.4 resolves several bugs. This is not a security update.
https://go.dev/

Microsoft Visual C++ 2022 Redistributable 14.42.34433.0 is a security update.
https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist

Node.js 18.20.5 updates libraries and resolves dozens of bugs. This is not a security update.
https://nodejs.org/en/

Node.js 20.18.1 updates libraries and resolves dozens of bugs. This is not a security update.
https://nodejs.org/en/

Node.js 22.12.0 updates root certificates and libraries, and resolves dozens of bugs. This is not a security update.
https://nodejs.org/en/

Node.js 23.4.0 updates root certificates and libraries, and resolves dozens of bugs. This is not a security update.
https://nodejs.org/en/

Python 3.13.1 is a security update.
https://www.python.org/downloads/windows/

SQLite 3.47.2 resolves several bugs. This is not a security update.
https://www.sqlite.org/download.html

TortoiseSVN 1.14.9 resolves several bugs. This is not a security update.
https://tortoisesvn.net/downloads.html

Web Package Updates

These are likely to be of interest only to web developers.

Invision Community 4.7.19 is a security update.
https://invisioncommunity.com/

Joomla 5.2.2 is a security update.
https://www.joomla.org/

Piwigo 15.1.0 is a security update.
https://piwigo.org/

WP Update Server 2.0.2 adds a self-identifying version number. This is not a security update.
https://github.com/YahnisElsts/wp-update-server

WordPress 6.7.1 adds a new primary theme, the ability to add blocks and custom fields, improved style controls, and resolves over a dozen bugs. This is not a security update.
https://wordpress.org/

Antispam Bee 2.11.7 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/antispam-bee/

BuddyPress 14.3.3 resolves several bugs. Thsi is not a security update.
https://wordpress.org/extend/plugins/buddypress/

Contact Form 7 6.0.1 is a major update, adding several new features and bug fixes. This is not a security update.
https://wordpress.org/extend/plugins/contact-form-7/

Duplicator 1.5.11.2 adds database collation to table creation. This should be treated as a security update.
https://wordpress.org/plugins/duplicator/

Redirection 5.5.1 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/redirection/

Widgets on Pages 1.9.0 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/widgets-on-pages/

WPBakery 8.0.1 is a major update. This version improves compatibility, adds a dozen features and controls, and resolves several bugs. This is not a security update.
https://wpbakery.com/

WP Cerber Security 9.6.4 adds 2FA improvements, detailed cookie information, and regex exceptions. This is not a security update.
https://wpcerber.com/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/