Updates 2026-01-13

Happy New Year!

Today is Patch Tuesday for January, 2026.

If your Windows 10 computer can not be upgraded to Windows 11 then you should either replace your device or use the Windows 10 ESU program to get another year out of it.

Windows 11 25H2 is now available and Windows 11 23H2 and older are no longer supported. Treat Windows 11 25H2 as beta software and wait a few months before upgrading.

macOS 26 Tahoe is now available and macOS 13 Ventura and older are no longer supported. macOS 26 is now stable and it’s important to update to 26.2 to resolve a critical security vulnerability.

There were 1325+ major hacks, and over 305 application updates this month. It’s a relatively small month, with about 3.0 GB of updates for most users.

This Month in Technology

1Cube, 3gh Informatica Integral, 47Club, 700Credit, A. Uzzo, A.S.A.P. Restoration, Aarong, Abacus Employment Services, ABECO Zumtech Drucklufttechnik AG Müliweg, About Women Ob Gyn, Abri Credit Union, acarlar.com.tr, Accela, Acme Electric, ACME Industrial, Ada Technologies, Adamson Ahdoot LLP, Adelman & Gettleman, Adnan Sundra & Low, AdonisJS, Advance Dent Denver, Advanced ENT & Allergy Center, Advanced Family Surgery Center, Advanced Technology Group, Aero Fabrications, Aflac, Aforeserve, AgeRight, Agfri, Agralite Electric Cooperative, Agrícola Cerro Prieto, Agrícola Don Ricardo, AH Group, AIPAC, AIRCOND SRL, Alex Rubbish & Recycling, ALGO 8180, All Rush, Allen Printing, AllerVie Health, Alliance Vape, AllRush Print & Apparel, Allure Home Creation, Alpha Alternatives, Alpha Systems, Alpine Lumber, Alt Alpha, Amazon Kindle, Ambiente e Sistemas de Informação Geográfica, ambisig.com, American Health, American Trust, American Vanguard, Ameriprise, Amla Commerce, AMW Treuhand & Immobilien, Anderson Engineering, Andover Eye Associates, Android (DroidLock), Android Dolby library, ANG BROTHERS (M&E) PTE LTD, Angstrom USA, Anritsu VectorStar, Anteriad, Anwalt Aktuell, Apache StreamPipes, APC Home Health Service, Apex Legends, Apex Spine and Neurosurgery, Appalachian Community Federal, Apple Safari, all Apple devices (iPhone, iPad, Apple Watch, Mac), Applied LNG, Apro, LLC, Arab Falcons, Arabian Desert Safari, ARC Community Services, Arcom Digital, Ariel Clinical Services, Armenian Government, ARO, Art City Dental, Artemis Healthcare, Artisans’ Bank, Ashton Thomas, Asiana Airlines, Askul Corporation, ASML, Aspen View Academy, Associated Radiologists of the Finger Lakes, PC, Associated Thermoforming, Assolim, Atalian, ATG, Atlantic Coast Life Insurance, Auforum, Aultman Health System, Aurora College, Austin Associates, Autodesk AutoCAD, Autohaus Elstermann, Autohaus Paschke, Autohaus Pichel GmbH, Autohaus Willy Ernst, autohaus-paschke.de, Automation One Business Systems, AUTOSUR, Avenira, Awakenings Center, AWS Auto Scaling, Axion50plus, Axxel Business Solutions, Ayelet Shaked Contact List, AySA, AzeoTech DAQFactory, B&J Transportation, baja.gob.mx, Baker University, Banco Vimenca, Bangchak, Barnes and Jones, Basecamp, Bauerfeind, BD Morning, Beausejour Co-op, Behr Enterprises, Behran Lift, Bell Lifestyle Products, Bengineered, Benise Dowling and Associates, Berkmann Wine Cellars, Bernaillio County, Besco Electrical, Best Hotels Spain, Best Insurance Agency, Betterment, beycelik, Beyer Law Group, Beyçelik Gestamp, BildungsWerk in Kreuzberg, Bina Darulaman Berhad, BioNet Asia, Black Dog Salvage, BLACKSTORE, Blaze Credit Union, blockchain contracts, BMW Guatemala, BNZ Materials, Boathouse on the Bay, BOC Oncology Center, Bolttech, Bonfilet, Boring Business Systems, BORING.COM, Bosch Choice Welfare Benefit Plan, Bouygues Energies and Services, Bowman Trailer Leasing, Box Elder County, Braemac, Brave, BreachForums (again), Brevard Skin and Cancer Center, Bridgewater Law Group, PC, Brightspeed, British Holiday & Home Parks Association, Brockhaus, Buhlmann Group, Building Trades, Burdette Dental Lab, Burnex, Burnham Brown, Busbusbus, bwk-berlin.de, Bäckerei Sipl, Bär Cargolift, C&R Electric, Cabinets 2000, LLC, Cal Spas, Callipo Group, CANCER, Canopy Health, Cape Fear Country Club, Capital + Safi, Capsum, Capuano Distribuzione Fresco, Caramel, Carbis Loadtec Group, Cardiovascular Medical Group of Southern California (CVMG), CareOregon, Carseo, Casa Botas, casabotas.es, cc-estuaire, CE-Edinger Medical Group BA, Cedar Valley Services Inc, CEIVA Logic, Center for Life Resources, Centro Médico Palafox, Centurion Security & Investigations, Cerenade, Charles Leonard Steel Services, charoenchai.com, Chastain & Associates, Chatham Asset Management, Chema Ballester, Chemirol, Chemstress Consultant, Chiesi USA, Chipotle, Choate’s HVAC, Chrome, all chromium-browsers, Chrysler, Church’s Chicken, CIDEF Argentina, CIIF Oil Mills Group, Cinema Concepts, Circuitronix, Cisco AsyncOS, Cisco ISE, Cisneros, Citizens Bank, City of Midway, City of Milton FL, City of Signal Hill, CJ Global, CKM Kondring Montagen, Clackamas College, Clarinda Health, Clarinda Regional Health Center, Clarksville ISD, Clemar Assessoria e Logística em Comércio Internacional, Clever Power, clipan.co.id, Cloudflare MCP Server Portal, Club Atlético River Plate, Clínica Dávila, CMAC LLC, cmc.com.br, Collins Computing, Colonial Metals, Colorado Powerline, Colégio Miguel de Cervantes, Comcast, Comercializadora Construtodo, Commercial Paving, Committee to Protect Journalists, Commonwealth Business Bank, Communauté de communes de l’Estuaire, CompactInd, Complexul Energetic Oltenia, Computing Dynamics, Conduent, Conifer Value-Based Care, LLC, consigaz.com.br, Construction Management and Consulting, Coolify, CoreHQ, Coupang, Covenant Health, Inc, CPJ.ORG, CPS, Cranford, Buckley, Schultze, Tomchin, Allen & Buie, Crawford Orthodontics, Crawford Software, Cressi, CSA Tax & Advisory, CSD Drancy, CSS Services, CSV Group, Culinary Jet Concierge, curl, CVK Hotels & Resorts, CVMG, CyberVector, Cyma Systems, Cytek Biosciences, D-Link DSL gateways, DABA Finance, Dacon Networks, daispa.it, Dan Technologies Group, David M. Schwarz Architects, David Rosen Bakery Supply, Debra L. Morrison Coaching & Consulting, Deerfield, Deibel Laboratories, Dekoyap, DELKO, Dem İlaç, Denk & Roche Builders, Denny’s 5th Avenue Bakery, Dentistry.One, Denton County MHMR Center, Depth, Dermatology Associates, Desjardins, DESY, Deutsches Elektronen Synchrotron, Devereux Foundation, DFC Systems, DGM, DGP Commercialisti, Dhow Cruise Dubai Harbour, Diaz Gill Medicina Laboratorial, DIF Guadalajara, Dill Dill, Dillon Yarn, Discord, Distribuciones Notariales, Distribuzione Automatica Italiana, Distron, Docs Medical Group, Inc, Dolan Construction, Dom Development, Donaghy Sales LLC, Dot Foods, Dr. Busso Peus, drako.com.mx, Drivestream, Inc, Drogaria Drogales, DSM Bilişim Teknolojileri, DSM Information Technology Trade Ltd, Dublin Medical Center, Due Doyle Fanning and Alderfer, DXS International, D’Klima, E-apostille, EAG Realty International, Eagle Stores, Eanes Independent School District, East Bay Regional Park District, Eastern Townships School Board, Eastman Cooke, EazyTick, Eco Green Group, Edge, Edward J Kone, EGP Comunicaciones Sac, EI Connect, Elad, ELC Electroconsult, Electricidad Panamericana, Electronic Interconnect, Elford, Inc. Construction, Elite Auto, Ellison Educational Equipment, EM Resorts, EmEditor, EMP Closures, Empire Screen Printing, Empresas Maggi, Endesa, Enel X, Energogroup, Energy Capital Credit Union, Enerparc AG, Entreprise Menuiserie Bâtiment, Envases Group, EPI du Rouergue, Epport Richman & Robbins, Equans, Ericher, Erie Molded Plastics, Ernst Auto, Eros Elevators and Escalators, Escuela Técnica Roberto Rocca, ESOP Direct, Esquire Brands, ESSPL, estrumar.es, Ets Puzio, Eurofret Transports Et Logistique, European Space Agency (ESA), European Vegetarian, Eurostar, Event Rental Systems, Ever Green Industria e Comercio, Evercover, Evergreen Printing, Evoke Wellness at Hilliard, ExamRoom.AI, Excellent Home Care Services, Exms Expertise Mobsign, Expert MRI, Facebook, Fairgrove Oil & Propane, Falk, Waas, Hernandez, Cortina, Solomon & Bonner Overview Metrics, Farmacia San Pablo, Farwest Fabrication, FASSIC, FCL Components, fecrwy.com, Fedcap, Federal University of Sergipe, FedEx, Feldman and Lopez, Felix Gonzalez Law Firm, Ferreteria Scopazzo, Fest Group, FHIABA, Fieldtex, FilmRise, Firmengruppe Hoffmann, First Federal Savings & Loan Association of Pascagoula Moss Point, First Rate Financial, Fit-Line Global, Fitzpatrick Hotel Group, Flavor Producers, Flock cameras, Florida East Coast Railway, Florida Orthopaedic Associates, Flowty, FontForge, FortiCloud, Fortinet firewalls, Fortinet FortiSandbox, Fortrex, Foshee Architecture, Foundation Agents, FOX Architects, Foxit PDF Reader, FPMCM LLC, Framelink Figma, Freedom Chat, FreePBX, French Interior Ministry, French postal service, Fresh2You, Friends of Family Health Center, Friis & Moltke Architects, Fuji Electric Monitouch V-SFT, Fujitsu Component (Malaysia) SDN, Fundação do Câncer, Fyzical Therapy & Balance Centers, Fürth, G & L Mechanical Systems, G-WAY Microwave, G5 Enterprises, Galine, Frye, Fitting & Frangos, LLP, Gardner Health Services, Garner Foods, Garrett Leather, Gateway Fiber, Gaviota, GCC Services, GDEV, GearGrid, Gebrüder Bagusat, Gemini MCP, Gemotest, Genoa Lakes Golf Club, Gentex Optics, Geometrics, Georgia Dermatology & Skin Cancer Center, GeoServer, GES Elektrik, GIMP, github-kanban-mcp-server, GIV SRL, Gladinet CentreStack, Glassers TV, Global Miami JV, Global-e, Gobierno de Baja California, Gogs, GoldenLine, Goldman Sachs Investments, Golf Manor, Good Plus Foundation, Goodwin University, Google Chrome, Gordon Clifford Properties, Gordon Companies, GPC Industries, GPT Academic, Grade Results, Grafana, Grandes Vinos, Granos y Cereales de Colombia, Granville Inn, Grassroot DICOM, Greater St. Louis Oral & Maxillofacial Surgery, GreenBills, Greene Metal Products, GreenValley International, Group Echo, GROUPE ETMB, Grupo Amanus, Grupo Construtodo, Grupo Drako, Grupo Hafesa, Grupo Logistics, Grupo Olé, Grupo Panamá, Grupo Puma, Grupo Ruiz, Guan Chong Berhad, Gulshan Management Services, gumustasmaden.com.tr, Guttenberg Industries, Gümüştaş Madencilik ve Ticaret, Hale Makua Health Services, Hama Film, Hanlon Electric, Happy Telecom, Harbour Town Doctors, Hardesty & Hanover, Harmony Health Medical Clinic and Family Resource Center, Harris Consulting Engineers, Harrison Design, Hart, Hartford, Harvey & Martin, Hatta Heritage Village, Hauken Engineering, HAXcms, Hayden Safe & Lock, Health Bridge Chiropractic, Health Management Systems of America, Health Share of Oregon, Healthbridge MultiSpecialty Group, Healthcare Interactive, Heart of Texas Behavioral Health Network, heatcel.co.uk, Heating Components & Equipment, Henry Ford Health, Heritage Engineering, Hermes Medical Solutions, Hernando County, Hexacon Construction, Higham Lane School, Hikvision, hilden.in, Hintenberger Dächer, HKR Architects, HMPC CPA, Hodgins Devereaux, Hodgins Law Group, Hog Sla, Holiday Tours, Home Depot, Homestead Electrical Contracting, Hometech Window, Hongfa America, Hood River Dentist, Hope Cooperative, Hopital La Rabta, Hopper Developments, Household & Commercial Products Association, HPE OneView, Hr Björkmans Entrémattor, HSR Specialist, Huebsch Services, Hugging Face smolagents, Hugging Face Transformers, Hunneman Real Estate, Hydraulic Technologies, Hydrodiseño, Hyfresh, Hytec South Africa, Häussermann Stauden Gehölze GMBH, IAPMO, IATTC, IBM API Connect, IceWarp, IDeaS Revenue Solutions, Illinois Department of Human Services (IDHS), Illumina, Imperial Beach Community Clinic, Infinite Computing Systems, Ingomar Church, Inha University, Inotiv, Inc, inpipeproducts.com, Insight Enterprises, Inspired Universal McCann, Instagram, Institut Teccart, Institute for Biology of Inland Waters IBIW, Institute for Design Problems in Microelectronics, Integrated Technology Group, Inter-American Tropical Tuna Commission (IATTC), International Association of Plumbing and Mechanical Officials, International Door, International Freight & Commerce, International Pipeline Products, International Standard Valve, Intonu, IntraCare, InTTrust, Investigaciones Medicas, InvivoGen, Ireland Ombudsman’s office, Italgrafica Sistemi, Italian ferry, ITG Electronics, ITG Solutions, J. Grennan & Sons, Jabezco Industrial Group, Jaf Gifts, James Free Jewelers, JBS Foods, JBS Mental Health Authority, Jefar, Jeff D’Ambrosio Auto Group, Jennings School District, Jewish Family and Community Services, Jing Cheng Enterprise, JJ White, John Buck Company, Josh Steel, jsPDF, JumpCloud Windows Agent, JVDB Assoc, JZ Russell Industries, Kalamazoo Valley Community College, Kamunikat, Kasetsart University, Katana Network, kavi.fi, Keio University, Kelsey School Division, Kenalex Construction, Keycodes Inspection Agency, Keylogistics Chile, Keys to Literacy, Kidd’s Services, Kier & Wright, Kirby Agri, Kirloskar Oil Engines, Klax Gruppe, KLH Industries, Klingele Paper & Packaging Group, Knight Group, KOEL.CO.IN, Konig Print, Kontigo, Kopaş Kozmetik, Korean Air, Korean Air Catering & Duty-Free, Korean Association for Public Administration, kraslice.cz, Krenzer Marine Overview Metrics, KSL Ingenieure, KTL Group, Kuaishou, Kucera International, Kumpulan Prasarana Rakyat Johor, Kwik Ledgers, L Pollock PR, La Banque Postale, La Papelera, La Rosa Del Monte Express, Labayen y Laborde, Labeltex Group, Laidley Family Doctors, Lakeside Title Company, Lampire Biological Laboratories, lampus.com, Langflow, Lanmark Group, LAOC Building and Construction Trades, Lares, larosadelmonte.com, Larry Pitt & Associates, Lasercomb, Latitude 33 Planning & Engineering, Launie & Marino, Laurenzano Logistica, Laurysen Kitchens, Laval Virtual, Lawrence Family Jewish Community Center, LawSoft, Inc, Leadway Assurance, Leandri & Associés, Leco Switchgear, Ledger, Leduc County, Leger & Shaw, Leidos QTC Health First Rehabilitation Resources, lfval.net, Libya Telecommunications Company, LiftPRO International, Line, Linemaster Switch, Linux kernel, LiteConn Technology, LKQ, LO Trading, LogicVein, loginport, Lonich Patton Ehrlich Policastri, Louisiana Office of Student Financial Assistance, LPL, LS GRIM, Lugiano Medical, Luminex Software, Luxshare Precision Industry, Lycée Français International de Valence, Lynn Community Health Center, Lynn Electrical, L’Orange Bleu, L’Épi du Rouergue, M&M Auto Parts, maasa.com.ar, macOS, Madera County Superintendent of Schools, Madison Area YMCA Association, Madison Healthcare Services, Mailpit, Maison Law, ManageMyHealth, NZ, Manuaco, MariaDB, Marine Systems, Markham Stouffville Hospital, Marquis Software Solutions (700 banks and credit unions), Marshfield Clinic, Masarykova základní škola a mateřská škola Železnice, Massapequa Fire District, Mastermedia International, MAT 4Site Engineers, Maven Solutions, maxdream.tur.ar, Maypay Farms Inc, MC Squared, McAfee Trellix, McCraw Oil, McElroy & Associates, McIntosh Laboratory, Inc, McKee-Pownall Equine Services, McKenzie SewOn, MCP Manager for Claude Desktop, McPhillamys Gold Project, mdm NT, Med Atlantic, MedHelp Clinics, Medical Asset Management, MedStar Health, Mega Alfalfa Argentina, Melsing Engineering & Consulting, Mercadien PC, Mercury Wire Products, Merko Ehitus, Methodist Homes, MetroWest Community Federal Credit Union, Metálicas Estrumar, Meyer Lift, MG Chartered Professional Accountant, Microf, Microsoft Edge Mark-Of-The-Web, Microsoft Edge, Microsoft Visual Studio, Midkiff Muncie and Ross, Milhench Supply, Mill Brothers, Millcreek Pediatrics, Milton FL, MindsDB, Minersville Schools, Mission Neighborhood Health Center, Mohammad Omar Bin Haider Holding Group, Molecular Testing Labs, Money Mart, MongoDB, Moonachie Borough, Moore Lumber, Morgan Records Management, Morning Desert Safari, Morningstar Properties, Morton Buildings, Morton Drug Company, Mosty Katowice, MP Filtri, MS Corp, Mt. Spokane Pediatrics, Murray Irrigation Limited, Mutti Parma, MyTunes, MyVete, Město Kraslice, n8n, Naftali Bennett Chats, NAHGA Claim Services, Nartis Plant, Nashua Botswana, National Audiovisual Institute, National Biscuit Industries, National Credit Regulator, National Equipment, National Guard website, National Water Authority, Native American Health Center, NBS Canada, NCH Corporation Employee Benefits Plan, NECO Equipment, Neighbourly, Nepes, Net-SNMP, Netanyahu’s Cabinet Awaits Handala’s Next Move, Netstar Australia, Network of Biblical Storytellers, Canada, Neurological Associates of Washington, New High Pack, New Obscura 2.0!, News-Press & Gazette Company, Next Capital, Next.js servers, Nextclode, nhpsa.com.ar, Niradia Enterprises, Nissan Motor Co, NK Technologies, NLFX Professional, NordVPN, North Atlantic States Carpenters Health Benefits Fund, North Perth, North Star Asset Management, Northern Air Systems, NorthStar Asset Management, Notariat Gerresheim, Notepad++, Notin, NovaBio, Novelty Technology Care Espana, npm, NS Pharma, NS Support LLC, NSE Insurance Agencies, NSF Unidata, NT Tool Thai, NTC Pharma, NTH Consultants, Nura Clinics, NZ ManageMyHealth patient portal, Oakland Smile Dental, OCC Marketing Communication & Technologies, Ochsner LSU Health System, Office of Public Sector Anti-Corruption Commission, oFono, OGI Groupe, Ohio Public Safety, Oklahoma Spine Hospital, Ollama MCP, Oltenia Energy Complex, Oman Football Association, OMF International, Omnibus Japan, Omrania, One Community Health, Open Door Community Health Centers, Open WebUI, Optimum Window Manufacturing, Options Community Services Society, Optral, OPTUM-IES, Oracle Health, Oregon Department of Environmental Quality, Ortho Mattress, OSI Systems, OSSE San Juan, Outdoor Smart! Inc, ownCloud, Oxford Rehabilitation Center, Pacific Railway Enterprises, Pacific Rim Mechanical, Paizo GPS Solutions, Parexel International, LLC, Partido Revolucionario Institucional, PAUAT Architekten, pdfforge PDF Architect, PDFsam, Peaker Services, Pearlman Aesthetic Surgery and Associated Radiologists, Pecan Tree Dental, Pediatric Dentistry of Oklahoma, Pell City Schools, Pensam Capital, Pensam Residential, Pentadiet, Pernec, Pernel Media, Petco, Petróleos de Venezuela (PDVSA), Peugeot Motocycles, peus-muenzen.de, Pewarchuk, Phillipine Department of Trade and Industry, Phillips Scales, Physicians to Children & Adolescents, Pickett USA, Pierce County Library System, Pilot automotive, Pin Hwa High School, PJSC Quadra Power Generation, Planned Parenthood Northern California, PlayStation, Plonter Technologies, Podovia, POL-HUN, Polaris Parks, polhun.pl, Pollock Communications, Pools by Bradley, Pornhub, PortSwigger Web Security, Posillico, PostgreSQL, Power Curbers, Powerscourt, Precise Benefits Group, Precision Aluminum, Premier Auto Credit, Prime Label Consultants, Print-O-Tape, Productos Lácteos Flor de Aragua CA, Progressive Laboratories, Promm Group, Prosura, Proton System, PT Clipan Finance Indonesia Tbk, PTS Goldkist Industries Sdn Bhd, Publicidad Sarmiento, Pueblo West Colorado, Pueblo West Metropolitan District, Pulse Urgent Care, Purcell Architects, puzio-saunierduval.fr, Quasar Data Center, Questica, Quezon Power, Q‑Ads, R.I. Lampus, Rafael Construction, Ragland Law Firm, Rain Bird Corporation, Rainbow Communications, Rameder, Ramside Hall, Ranger Investigation Guard, Raritan Yacht Club, Rconcept, RD Metals, React Server, Real Tech, Red Star Studio Ltd, Redis, REDtone, Reger Zahntechnik, Region of Istria, Rene Industries, Republica Federative do Brasil, Resecurity, Resource Corporation of America, Retrofit Service, Revere Health, Revoil, RGD Consulting Engineers, Richmond Behavioral Health Authority, Right Power Technology, Rio Farms, LLC, Rio supermarket, RJ Enterprise, RJS Logistics, RK Centers, RM Medics, Rockport Technology Group, Rockrose Development LLC, Rod Danielson, Rodenburg Law Firm, Rodney’s Sign Company, Roebbelen Contracting, Inc, Rogitz & Associates, Romanian Waters, Roose Ressler & Green, Ruhrpumpen, Rusk County, WI, Rust on Linux, RustCrypto, RYC, Röben Tonbaustoffe, S.Med Handels, Saar Engineering, Sai Oral Surgery, Saint Petersburg State University of Economics, Salcom, Salvation Army, Samkee America, Sampoerna Agro, San Francisco Community Health Center, San Silvestre School, Sanchez Vadillo, Sanko Gosei UK, Santa Casa de Assis, Santa Rosa Community Health Centers, Sante PACS Server, Sanyang Motor, SapLog Italia, Sapphire Health, Sarl Alliance, Saudi Icon, SAV Antivibranti, Sax LLP, sbws.org.sg, Scenic Solutions, Schneider Prototyping, Scipioni, SEAC SUB, Seac, Seal Beach, CA, Seal Beach CA Police Department, Secorp Industries, Security ONE Alarm Systems, Sedgwick Government Solutions, Seeberger Appel, Seguridad Las Americas, SEIMITSU THAI COMPANY LIMITED, Self-Help Addiction Rehabilitation, SELP, Sem Plastik, SEM Val de Bourgogne, Sense Eletronica, Senstar Symphony, Sentinel Security, Sentry Advisors, SETEX Textil, Shah Law Office, Shamrock Technologies, Share Ourselves, sharinc.org, Shinhan Card, Shinsegae, Shlansky Law Group, SHOFCO, Shore Gardens Rehabilitation & Nursing Center, Shout Factory, Shwapno, Siemens Simcenter, Silverline Group, SINBON Electronics, Sindicato dos Professores da Zona Centro, Singapore Buddhist Welfare Services, Singing River Health System, Singular Genomics, Sintac Recycling, Sipl, SIRH Mexico, Sirio Pharma, sje.vic.edu.au, smallstep Step-CA, SMC Global Securities, smed.at, Smile Center Utah, Smith Hawks, Smith Roberts Baldischwiler, Snapchat, SNCC Automatisme Solutions Process, SOA People, Soapy Joe’s Car Wash, Société Tunisienne de Radiologie, Soda PDF Desktop, soeuae.ae, Softlab SpA, Solarpro Holding, Solumek SAS, Solus Tecnologia em Sistemas, SonicWall SMA1000, Sortimage Communications, SoundCloud, South Shore Tool & Die, South West Development Commission, Southern Oregon Neurosurgical and Spine Associates, Spartan Carbide, Spitzer Auto Group, Sponseller Group, Spring Grove Area School District, Springer’s Jewelers, SproutNet, SPZC, SSL and ACL, St Charles Preparatory School, St Ignatiusi Jamsville, St Josephs College Echuca, St Anthony Regional Hospital, St John’s Riverside Hospital, Stadt Fürth, Stadtwerke Clausthal-Zellerfeld, Stanley Co Malaysia, Startek Engineering Inc, STC Concrete Products, Steel Corners Industrial, Steel Dynamics, Inc, Steelworks Inc, Stesad, Stewart Engenharia, STIC Investments, stimgroup, Stipe Law Firm, Stoughton Steel, Strategic Technology, strtn.org, Studio DGP Dottori Commercialisti, studioelad.it, Sudamerica, Sugawara Laboratories, Sunair Electronics, Sunshine Group, Sunzen Biotech Berhad, SUPERAntiSpyware, Superior Water Conditioning, Surfish Trade, Susquehanna Glass, SV-Büro Ing. Schulz GmbH, SVA y Tecnología Móvil de España, svlawus.com, SW Automation, SW WireTerminal, SW/WC Service Cooperative, Swartz Campbell, Swavelle Group, swdc.wa, Swift Institute, Syrstone, Systherm Grupa, Sönmezler Metal, TACK Electronics, TaLachaim, Talarico, Taminsho, TapestryHealth, Target, TEALCA, teccart.qc.ca, Technicare Instrumental Cirúrgico, tecnicarobertorocca.edu.ar, Tecno Electric, Tein, Teknequip, Tele-Fonika Cable Americas, Telechaim, Telegram, Telstar Hommel, Temple Shalom, Tencent FaceDetection, Terminales Portuarias, Terport, Teruya Brothers, Texas Pete, Thai Pet Food Group, The Araneta Group, The Biosig Project, The Boathouse on the Bay, The Botting Network, The Carlson Law Firm, The Center of Association Management, The Cressi, The Day of Reckoning Awaits the Child-Killers, The Genesis Group, The Lewis Bear, The Outdoor Recreation Group, The Parkes, The Salarpuria Sattva Group, The Sonnenschein Groupe, The Structures Group, The Wardlaw + Hartridge School, ThermoEx Company Limited, Thrings Solicitors and Lawyers, THT Bio-Science, Thunder Bay Counselling, Titan Motor Group, Tlechaim, Tokyo FM, Tommotek, Top Dest, Topstep, TorHoerman Law, LLC, Total Wireless, Towell International Holding, TradingView Desktop, Transpedrosa, Transport Scolaire, Transrocamar, Trend Import Export, Trend Micro Apex Central, Trend Micro Cleaner One, Tri-State Metal Roofing Supply, Triad Packaging Inc, Trimble SketchUp, Trine Access Technology, Triple Eight Transport, TriVector Services, TriZetto Provider Solutions, Trubee Wealth Advisors, TrustWallet, Tucson Independent Physicians and Surgeons, TUPI, Turing & EDU Arena, Turnamics, Tuscon Physicans, Twinsoft, Typhoo Tea, Ubisoft’s Rainbow Six Siege, UBS Office, Udall Law Firm, UEFI, UK Foreign Office, UK Free Speech Union, UK Home Office, Unified Assessment Platform ExamRoom.AI, Union Home Mortgage Corp, Union of Shop, Distributive and Allied Workers, uniplaclages.edu.br, Unipres Alabama Inc, United Keetoowah Band of Cherokee Indians in Oklahoma, United Pacific, Universidad Nacional Autónoma de México, Universidade do Planalto Catarinense, Universiti Sains Islam Malaysia, University of Hawaii Cancer Center, University of Phoenix, University of Sydney, Unleash Protocol, UNRE AI, UPC Precision Castings, Upsonic, Urban Remedy, Urban VPN, urfishtrade.com, uro.com, US Art, US Dept Of Defense (hundreds!), US Equal Employment Opportunity Commission (EEOC), usdaw.org.uk, Usina Sao Jose do Pinheiro, Utair, Valle Redondo, Van Venrooy, Varimed Medikal, Veeam Backup, Veplastic, VeraBank, Veradigm LLC, Vereinigte Stadtwerke, Vernon Sales, Vestil Manufacturing, Vetco, VFM Systems & Services, Victoria Benelux, Victorian Catholic College, Victory Disability, Vida Y Salud, Viga Eatery, Village of Franklin, Ville de Dunkerque, Vim for Windows, Virginia Mental Health Authority, Virginia Records, Virginia Urology, Vishnick McGovern Milizio, Vision Wheel, VisionPoint Eye Center, Vitatrac, Vivaldi, VLP Hellas, VMware ESXi, Voltech Rebuilders, Voltras International, VroomVroomVroom, Váhostav, Wadzeck-Stiftung, Wall Street English, Walltopia, Walters Group Inc, Wamtechnik, Wardell Builders, Warka Bank for Investment and Finance, Warren County Treasurer’s Office, Warrior Crane Service, WatchGuard Firebox, WatchYourLan, Watermark Beach Resort, Watertech of America, Wavenet, Wavlink routers, Wearbest Sil Terhar, Web Hosting Talk, Wedbush Securities Inc, Wellcare, Wellpoint, Wesley Heating and Cooling, Westlake Christian Academy, Westminster City Council, Westquay, WhiteDate, Wilbarger General Hospital, Wild Bunch Distribution, Willowdale Steeplechase, Wilmington Community Clinic, Wilson Smith Cochran Dickerson, Windows Remote Access Connection Manager (RasMan), Windscribe, Windward Life Care, WIRED, Wisanka Indonesia, Wizix Technology, WJ Professional, Wood Personnel Services, Woodard, Emhardt, Henry, Reeves & Wagner, LLP, Woodglen Medical Group, WordPress Motors theme, Workers Compensation Insurance Rating Bureau of California, WorldPoint, Wright Architectural Millwork, WSI, XSpeeder, Yalidine Express, Yavne Educational Center, Yokosuka Gakuin, YoPipe, York Hospital, Young Wealth Management, Youngblood Tyler and Associates, Youngstown Pipe & Steel, Z-Tronix, Zenflow, Zimeda, Zoom, and zszeleznice.cz have reported hacking or compromises this month.

Microsoft Exchange Online, Microsoft Teams, and X/Twitter have suffered from outages this month.

Internet access throughout Congo-Brazzaville, Finland, Guinea, Iran, Montana, San Francisco, CA, Ukraine, and Venezuela has been blocked our down for extended periods.

Last months updates broke Classic Outlook, VPN access, and Windows Message Queuing (MSMQ).

Microsoft is going to start blocking older, insecure and unsupported hardware from accessing their email platform, Exchange Online.

For all their blather, Apple will be using Google Gemini to power Siri.

Crucial is ending consumer sales. This is going to be bad for computer pricing.

It’s insanely easy to map out human movement within your home (or someone else’s) using your existing Wi-Fi routers.

Let’s Encrypt (the service behind most current website secure certificates) is shortening the expiration term for their certificates. By a lot. It’s almost completely automated so probably not going to be a bit deal.

California has added a privacy tool to request that data brokers remove your information. It uses a third-party precheck service responsible for breaking the Internet several times last year (CloudFlare) and one of the worst privacy violating services out there (login.gov), then requires you to give the California government all of the information about you (name, SSN, date of birth, email address, phone numbers, addresses and so much more) for the state to store so that participating data brokers know what to remove. My opinion: government is the worst of the worst when it comes to getting hacked and exploited, so if you’re concerned about dubious storage of your data, giving it to the state is literally the worst possible option. It might be more work, but it’s better to do it yourself.

Now for the good news:

Google is finally adding an option to remove information about you.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is relatively small this month. The typical computer should see roughly 3.0 GB in updates today. Let’s get started.

Microsoft released 60 updates to address 115 vulnerabilities in Agere Windows Modem Driver, Azure Connected Machine Agent, Azure Core shared client library for Python, Capability Access Management Service (camsvc), Connected Devices Platform Service (Cdpsvc), Desktop Window Manager, Dynamic Root of Trust for Measurement (DRTM), Graphics Kernel, Host Process for Windows Tasks, Inbox COM Objects, Microsoft Edge (Chromium-based), Microsoft Graphics Component, Microsoft Office, Microsoft Office Excel, Microsoft Office SharePoint, Microsoft Office Word, Printer Association Object, SQL Server, Tablet Windows User Interface (TWINUI) Subsystem, Windows Admin Center, Windows Ancillary Function Driver for WinSock, Windows Client-Side Caching (CSC) Service, Windows Clipboard Server, Windows Cloud Files Mini Filter Driver, Windows Common Log File System Driver, Windows Deployment Services, Windows DWM, Windows Error Reporting, Windows File Explorer, Windows Hello, Windows HTTP.sys, Windows Hyper-V, Windows Installer, Windows Internet Connection Sharing (ICS), Windows Kerberos, Windows Kernel, Windows Kernel Memory, Windows Kernel-Mode Drivers, Windows LDAP – Lightweight Directory Access Protocol, Windows Local Security Authority Subsystem Service (LSASS), Windows Local Session Manager (LSM), Windows Management Services, Windows Media, Windows Motorola Soft Modem Driver, Windows NDIS, Windows NTFS, Windows NTLM, Windows Remote Assistance, Windows Remote Procedure Call, Windows Remote Procedure Call Interface Definition Language (IDL), Windows Routing and Remote Access Service (RRAS), Windows Secure Boot, Windows Server Update Service, Windows Shell, Windows SMB Server, Windows Telephony Service, Windows TPM, Windows Virtualization-Based Security (VBS) Enclave, Windows WalletService, Windows Win32K – ICOMP, and MSRT. This includes security updates. A reboot is required.

Apple released updates for iOS 26.2, iPadOS 26.2, macOS Sonoma 14.8.3, macOS Sequoia 15.7.3, macOS Tahoe 26.2, Safari 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2. This includes security updates. Use Apple Software Update to install the most current versions.

iOS 26.2 is a security update. Use Settings, General, Software Update to install the most current update.

iPadOS 26.2 is a security update. Use Settings, General, Software Update to install the most current update.

watchOS 26.2 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 26.2 is a security update. Use System, Software Update to install the most current version.

visionOS 26.2 is a security update. Use System, Software Update to install the most current version.

Google ChromeOS 143.0.7499.196 and ChromeOS LTS 138.0.7204.300 are security updates. Use Menu, Help, About to install the most current version. A reboot is required.

Fedora 45 is a major update. This is a security update.
https://getfedora.org/en/workstation/download/

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Tahoe (26.x) means that macOS Ventura (13.x) and older are no longer supported. If you can not install at least macOS Sonoma (14) on your Mac then you should immediately remove your device from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

Windows 10 (all consumer versions) is end of life (EOL). All non-LTS versions of Windows 10 without ESU are now out of support, with the sole alternatives being to upgrade to Windows 11 or enable Extended Service Updates (ESU). If you aren’t sure whether you are using LTS, you aren’t. Enable the ESU now.

The current release of the Windows 11 (v25H2) is very large (30% larger than any previous release) so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it. If not, switch to Linux (Mint is nice) or replace your computer.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, drivers for hardware you’re not using (like old printers), and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with a SaferPC Subscription and we will install updates each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Logitech Options 10.26.14 fixes a MS Office compatibility issue. This is not a security update.
https://support.logi.com/hc/en-us/articles/360025297893

MTPdrive 5.1.202 improves compatibility. This is not a security update.
https://www.mtpdrive.com/

RICOH IM C4510 1.5.0.0 adds new languages. This is not a security update.
https://support.ricoh.com/bb/html/dr_ut_e/rc3/model/imc4510/imc4510.htm

Stream Deck 7.2.0 adds support for new hardware.
https://help.elgato.com/hc/en-us/categories/360001636492-Stream-Deck

TP-Link Archer AX55 v1 251119 is a security update.
https://www.tp-link.com/us/support/download/archer-ax55/v1/#Firmware

TP-Link Archer AX73 v2.0 250717 is a security update.
https://www.tp-link.com/us/support/download/archer-ax73/v2.0/#Firmware

UniFi airMAX NanoStation 5AC Loco 8.7.21 is a security update.
https://www.ui.com/download/software/loco5ac

VIISAN OfficeCam 7.2.15 doesn’t provide a change log so should be treated as a security update.
https://www.viisan.com/en/download/type1.html

Xerox Smart Start 2.1.24.0 doesn’t provide a detailed change log so should be treated as a security update.
https://www.support.xerox.com/en-us/content/143617

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.85.120 is a security update.
https://brave.com/

Firefox 147.0 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 140.7.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Google Chrome 143.0.7499.192 is a security update.
https://www.google.com/chrome/

Microsoft Edge 143.0.3650.139 is a security update.
https://www.microsoft.com/en-us/edge/business/download

SeaMonkey 2.53.23 is a security update.
https://www.seamonkey-project.org/

Vivaldi 7.7.3851.67 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Spark 3.27.5.126936 improves layout and adds sharing controls, recent activity folder and new display options. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.27.5.126935 improves layout and adds sharing controls, recent activity folder and new display options. This is not a security update.
https://sparkmailapp.com/

Thunderbird 146.0.1 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 9.6.7 resolves dozens of bugs, improves stability and cosmetics. This is a security update.
https://anydesk.com/en/downloads

AnyDesk (macOS) 9.6.1 improves reliability. This is not a security update.
https://anydesk.com/en/downloads

curl 8.18.0 updates libraries, removes support for older technology, and resolves over a hundred bugs. This is a security update.
https://curl.haxx.se/windows/

Dropbox 238.4.6305 doesn’t provide a detailed change log so should be treated as a security update.
https://www.dropbox.com/

FileZilla Server 1.12.1 resolves a stability bug. This is not a security update.
https://filezilla-project.org/

Google Drive 119.0 resolves several bugs. This is not a security update.
https://drive.google.com/start

MeshCentral 1.1.55 resolves over a dozen bugs. This is not a security update.
https://meshcentral.com/info/downloads.html

Nextcloud Server 31.0.2 updates libraries and resolves dozens of bugs. This is not a security update.
https://nextcloud.com/

Npcap 1.86 is a security update.
https://nmap.org/npcap/

OneDrive 25.222.1112.0002 resolves several bugs and increases AI integration with Copilot. This is not a security update.
https://support.microsoft.com/en-us/onedrive

Rclone 1.72.1 is a security update.
https://rclone.org/

Signal 7.84.0 resolves a cosmetic bug. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.68.4 adds polls and resolves a cosmetic bug. This is not a security update.
https://signal.org/android/apk/

Syncthing 2.0.13 resolves several bugs. This is not a security update.
https://syncthing.net/

Technitium DNS Server 14.3 resolves several bugs and updates included apps. This is not a security update.
https://technitium.com/dns/

Telegram 6.4.2 resolves several bugs. This is not a security update.
https://telegram.org/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.24 resolves several cosmetic bugs. This is not a security update.
https://en.3tene.com/

darktable 5.4.0 resolves many bugs, and improves user interface and performance. This is not a security update.
https://www.darktable.org/

Grayjay 363 improves DASH & UMP support and improves language filters. This is not a security update.
https://grayjay.app/index.html

KaraFun Player 3.10.6 resolves an updater bug, improves cosmetics for currently playing item, and resolves several other bugs. This is not a security update.
https://www.karafun.com/karaoke-windows/

VLC Media Player 3.0.23 is a security update.
https://www.videolan.org/vlc/

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.132.3 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

Nintendo Switch 21.2.0 improves stability. This is not a security update.
https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/system%20updates/p/989

Steam 2025.12.19 is the last build with 32-bit support, resolves stability bugs with controllers and resolves over a dozen bugs. This is not a security update.
https://store.steampowered.com/news/app/593110

SteamOS SteamDeck Update 3.7.19 resolves several bugs. This is not a security update.
https://store.steampowered.com/news/app/1675200/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Bridge 15.1.3 and 16.0.1 are security updates.
https://helpx.adobe.com/security/products/bridge/apsb26-07.html

Adobe ColdFusion 2025 Update 6 and 2023 Update 18 are security updates.
https://helpx.adobe.com/security/products/coldfusion/apsb26-12.html

Adobe DreamWeaver 21.7 is a security update.
https://helpx.adobe.com/security/products/dreamweaver/apsb26-01.html

Adobe Illustrator 29.8.4 and 30.1 are security updates.
https://helpx.adobe.com/security/products/illustrator/apsb26-03.html

Adobe InCopy 21.1 is a security update.
https://helpx.adobe.com/security/products/incopy/apsb26-04.html

Adobe InCopy 20.5.1 is a security update.
https://helpx.adobe.com/security/products/incopy/apsb26-04.html

Adobe InDesign ID21.1 and ID20.5.1 are security updates.
https://helpx.adobe.com/security/products/indesign/apsb26-02.html

Adobe Substance 3D Designer 15.1.0 is a security update.
https://helpx.adobe.com/security/products/substance3d_designer/apsb26-13.html

Adobe Substance 3D Modeler 1.22.5 is a security update.
https://helpx.adobe.com/security/products/substance3d-modeler/apsb26-08.html

Adobe Substance 3D Painter 11.1.2 is a security update.
https://helpx.adobe.com/security/products/substance3d_painter/apsb26-10.html

Adobe Substance 3D Sampler 5.1.3 is a security update.
https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-11.html

Adobe Substance 3D Stager 3.1.6 is a security update.
https://helpx.adobe.com/security/products/substance3d_stager/apsb26-09.html

Artweaver 8.1.2 resolves several bugs. This is not a security update.
https://www.artweaver.de/

Audiate 2026.1.0 improves cosmetics and resolves several bugs. This is a security update.
https://www.techsmith.com/camtasia/audiate/

GnuCash 5.14 resolves several bugs. This is not a security update.
https://www.gnucash.org/

ImageMagick 7.1.2-12 resolves several bugs. This is not a security update.
https://imagemagick.org/

Inkscape 1.4.3 resolves dozens of bugs. This is not a security update.
https://inkscape.org/release/

Krita 5.2.14 resolves over a dozen bugs. This is not a security update.
https://krita.org/en/download/

LibreOffice 25.8.4 and LibreOffice Fresh 25.8.4 resolves over 70 bugs. This is not a security update.
https://www.libreoffice.org/

Nextcloud Desktop 4.0.4 resolves several bugs. This is not a security update.
https://nextcloud.com/

Notepad++ 8.9 is a security update.
https://notepad-plus-plus.org/

PDF-XChange Editor 10.8.2.407 is a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

Scribus 1.6.5 is a security update.
https://www.scribus.net/

Operating System Updates

These are for specific Linux flavors and alternative operating systems and, sadly, are unlikely to be of interest to most people.

ChromeOS 143.0.7499.196 is a security update.
https://chromereleases.googleblog.com/search/label/Stable%20updates+ChromeOS

Fedora 43.0 updates apps and libraries, upgrading many services and systems to new current builds. This is a security update.
https://getfedora.org/en/workstation/download/

iOS 26.2 is a security update.
https://support.apple.com/kb/HT204204

iPadOS 26.2 is a security update.
https://support.apple.com/kb/HT204204

Linux Mint 22.3 adds support for newer hardware and removes support for some older hardware, updates drivers and changes defaults. This should be treated as a security update.
https://www.linuxmint.com/download.php

macOS 26.2 is a security update.
https://support.apple.com/kb/HT201541

Tails 7.3.1 is a security update.
https://tails.net/install/download/index.en.html

TOS 6 6.0.794 resolves several bugs. This should be treated as a security update.
https://support.terra-master.com/posts/TOS6_Release_Notes

tvOS 26.2 is a security update.
https://support.apple.com/kb/HT202716

watchOS 26.2 is a security update.
https://support.apple.com/kb/HT204641

Security Software Updates

One or more of these is likely to be of interest to most people.

.NET Runtime 10.0.1 improves stability and reliability. This is not a security update.
https://dotnet.microsoft.com/en-us/download/dotnet

HTTP Toolkit 1.24.2 doesn’t provide a change log so should be treated as a security update.
https://httptoolkit.tech/

ProtonVPN 4.3.9 improves stability and resolves several bugs. This is not a security update.
https://github.com/ProtonVPN/win-app/releases/latest

RogueKiller 16.5.4 resolves several bugs. This is a security update.
https://www.adlice.com/download/roguekiller/

Stinger 13.0.0.588 adds new detections
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

Capture Updates

These are unlikely to be of interest to most people.

Greenshot 1.3.312 is a security update.
https://github.com/greenshot/greenshot/releases

Open Broadcaster Software 32.0.4 resolves three minor bugs. This is not a security update.
https://obsproject.com/

Converter Updates

These are unlikely to be of interest to most people.

BookFab 1.2.1.8 improves TTS (text to speech), conversion, and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/kindle-converter.htm

DVDFab 13.0.5.4 resolves a stability bug. This is not a security update.
https://www.dvdfab.cn/download.htm

StreamFab 7.0.0.6 resolves dozens of bugs and improves reliability and consistency. This is not a security update.
https://streamfab.dvdfab.cn/downloader.htm

UniFab 4.0.0.0 is a major update adding new upscaling and conversion abilities. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Education updates

One or more of these are likely to be of interest to most people.

Zotero 7.0.31 adds several new fields and creator types and resolves several bugs. This is not a security update.
https://www.zotero.org/

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.11.23 resolves a stability bug when using passkeys. This is not a security update.
https://1password.com/downloads/windows/

AOMEI Partition Assistant 10.10.0 adds a disk space analyzer and resolves partition alignment bug. This is not a security update.
https://www.diskpart.com/

Beyond Compare 5.1.7.31736 improves stability and updates signing. This is not a security update.
https://www.scootersoftware.com/download

Bitwarden 2025.12.2 resolves several bugs. This is not a security update.
https://bitwarden.com/

CCleaner 7.03.1120 updates cleaning and improves analysis. This is not a security update.
https://www.ccleaner.com/

Coreinfo 4.0 adds a GUI version and newer CPU checks. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/coreinfo

CPU-Z Installer 2.18 adds support for newer hardware. This is not a security update.
https://www.cpuid.com/softwares/cpu-z.html

DesktopOK 12.26 resolves a couple bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.6.63.0 adds ability to search within office documents that are already open and updates libraries. This should be treated as a security update.
https://dngrep.github.io/

GoodSync 12.9.22 updates libraries and cleans up cosmetics. This is not a security update.
https://www.goodsync.com/

HWMonitor 1.61 adds support for newer hardware. This is not a security update.
https://www.cpuid.com/softwares/hwmonitor.html

LessMSI 2.11.6 updates table layout display and translations. This is not a security update.
https://lessmsi.activescott.com/

NConvert 7.230 doesn’t provide a change log so should be treated as a security update.
https://www.xnview.com/en/nconvert/

NotMyFault 4.30 adds Arm64 support and new crash types. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/notmyfault

NTLite 2025.12.10736 splits downloads for older versions of Windows and updates components. This is not a security update.
https://www.ntlite.com/download/

OSForensics 11.1.1014 resolves two crash bugs. This is not a security update.
https://www.osforensics.com/download.html

osquery 5.21.0 improves macOS integration, adds several new tables and sources, and resolves a couple bugs. This is not a security update.
https://osquery.io/downloads

Password Security Scanner 1.65 improves compatibility with newer browsers. This is not a security update.
https://www.nirsoft.net/utils/password_security_scanner.html

PointerStick 6.88 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

Process Explorer 17.09 fixes an image detection bug and adds details for .NET processes. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/process-explorer

Raspberry PI Imager 2.0.3 improves performance, networking, device and drive handling, and adds a custom URI scheme for custom distributions. This is not a security update.
https://www.raspberrypi.com/software/

Remotly 1.37.0 adds support for newer hardware and improves stability. This is not a security update.
https://remotly.com/

RoboForm 9.9.1 updates the icon and adds a caps lock indicator. This is not a security update.
https://www.roboform.com/

SetUserFTA 2.7.3 removes the DLL dependency for UCPD support. This is not a security update.
https://setuserfta.com/download-setuserfta/

Ventoy 1.1.10 resolves several bugs. This is not a security update.
https://www.ventoy.net/en/index.html

WinGet 1.12.440 adds font support, MCP server, and resolves several bugs. This is not a security update.
https://github.com/microsoft/winget-cli/releases/latest

WinScan2PDF 9.51 resolves a couple bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

Developer Updates

These are unlikely to be of interest to most people.

ADB 36.0.2 improves reliability and resolves a few bugs. This is not a security update.
https://developer.android.com/studio/releases/platform-tools

Android Studio 2025.2.2.8 resolves several bugs. This is a security update.
https://developer.android.com/studio

GameMaker Studio 2024.14.2.213 improves stability and resolves several bugs. This is not a security update.
https://www.yoyogames.com/en/gamemaker

GDevelop 5.6.251 improves performance, history, and resolves several bugs. This is not a security update.
https://gdevelop.io/download

Inno Setup 6.7.0 adds new cosmetics and compiling improvements, various scripting and control improvements, and a security change to add RedirectionGuard support. This should be treated as a security update.
https://www.jrsoftware.org/isdl.php

Node.js 20.20.0 is a security update.
https://nodejs.org/en/

Node.js 22.22.0 is a security update.
https://nodejs.org/en/

Node.js 24.13.0 is a security update.
https://nodejs.org/en/

Node.js 25.3.0 is a security update.
https://nodejs.org/en/

SQLite 3.51.2 resolves a couple stability bugs. This is not a security update.
https://www.sqlite.org/download.html

Visual Studio Code 1.108 resolves thousands of bugs and updates cosmetics, AI integration, and more. This is not a security update.
https://code.visualstudio.com/

Web Package Updates

These are likely to be of interest only to web developers.

HumHub 1.17.5 resolves several bugs. This is not a security update.
https://www.humhub.com/en

Joomla 6.0.2 & 5.4.2 are security updates.
https://www.joomla.org/

OpenPetra 2025.12 resolves several bugs and improves performance. This is not a security update.
https://www.openpetra.org/

Piwigo 16.2.0 resolves several bugs. This is not a security update.
https://piwigo.org/

My Sticky Bar 2.8.6 resolves a stability bug. This is not a security update.
https://wordpress.org/extend/plugins/mystickymenu/

Postie 1.9.74 is a security update.
https://wordpress.org/extend/plugins/postie/

Redirection 5.6.0 reduces size. This is not a security update.
https://wordpress.org/extend/plugins/redirection/

Sucuri Security 2.6 adds a new permissions library and resolves a cache bug. This is not a security update.
https://wordpress.org/extend/plugins/sucuri-scanner/

Top Commentators Widget 1.7 doesn’t provide a change log so should be treated as a security update.
https://wordpress.org/extend/plugins/top-commentators-widget/

WP Cerber Security 9.6.11 improves browser detection, translation, and DoS hardening. This should be treated as a security update.
https://wpcerber.com/

YOURLS 1.10.3 resolves over a dozen bugs. This is not a security update.
https://yourls.org/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

 

Updates 2025-11-11

Happy Veteran’s Day, Folks!

Today is Patch Tuesday for November, 2025.

If your Windows 10 computer can not be upgraded to Windows 11 then you should either replace your device or use the Windows 10 ESU program to get another year out of it.

Windows 11 25H2 is now available and Windows 11 23H2 and older are no longer supported. Treat Windows 11 25H2 as beta software and wait a few months before upgrading.

macOS 26 Tahoe is now available and macOS 13 Ventura and older are no longer supported. Treat macOS 26 as beta software and wait a few months before upgrading.

There were 750+ major hacks, and over 650 application updates this month. It’s a relatively small month, with about 4.0 GB of updates for most users.

This Month in Technology

5CA, Abilene Family Medical Associates, Accord Carton, Adichunchanagiri Institute Of Technology, Adobe Commerce, Adobe Experience Manager, Adore Children and Family Services, Advanced Delivery Services, Advanced Installer, Afghan Ministry of Defence, AGFA, Agri-Food and Biosciences Institute (AFBI), (at least) 2/3rds of AI companies, Air Arabia, Al Ahly Leasing & Factoring Company, Al Rimal Group, Albanese Physical Therapy, Albert Heijn, Alibaba Cloud Workspace Client, Alight Solutions, Alios Finance Group, Alissa Group, Alitech, Alpha Omega Winery, LLC, Altimedia, Amazon Smart plugs, AMD CPU VM (RMPocalypse), AMD CPUs (TEE.fail), American Airlines, American PowerNet, Ami Bearings, Anderson-Moore Construction, Android, ANIA KRUK, Ansell, Antigo Construction, Apache OpenOffice, Aphase II, ApleNet, Applied Technology Resources, Aptura Group & Central Indiana Hardware, ArcGIS, Armed Forces of the Philippines, Artistica Rubens, Asahi Group Holdings, Ashlar-Vellum Cobalt, Askul, ASP.NET Core, Assemblée Nationale, Astra Nova, AT&T Careers, Athol Hospital, ATIRG, Atrium Living Centers, Auckland City, Aunt Martha’s Health and Wellness, Aussie Fluid Power, Autodesk AutoCAD, Autodesk On-Demand Install Services, Automated Logistics Systems, Autorotor, Avast, AVG, Axelson, Williamowsky, Bender & Fishman, Badger Popcorn and Concession Supply, BAE Systems SOCET, Balancer, Bank3, BARCO Rent-A-Truck, Batta Fulkerson Law Group, Bay West, Bayu Buana Travel, Beijing Time Systems, Bell Engineering, Bellflower Unified School District, Benda Grace Stulz, Benefitelect, Benworth Capital Partners, Bergman Dacey Goldsmith, Berkeley Research Group, LLC, Bestlog Logistic Solutions, Beta Dyne, Beverly Hills Oncology Medical Group, Bicing, BIND DNS, BK Technologies, Black Hills Bentonite, Blavity Inc, blockchain smart contracts (EtherHiding), Blue Cross Blue Shield of Montana, BMP Worldwide, Boilersource, Bolt Electricity, Oil & Gas, Bovavet, Boyer, BRDSoft, Bridgehead IT, Brihta, Bristol Student Union, Buffalo Games, Edaron, Ceaco, Cabinets 2000, LLC, Canada water and energy facilities, Canadian Tire, Canon imageCLASS MF654Cdw, Cape Dara Resort Pattaya, CapitalPlus Exchange, Castilla, Cavalry Consulting, CCI Tax Pros, CDS, CentOS Web Panel, Central Jersey Medical Center, Central Plate Services Limited, CESO, CEVA Logistics, CHDFS, Chi Rho Chiropractic, Chiapas Health Secretariat, Christina Development, Cisco ASA firewalls, Cisco FTD firewalls, Cisco IOS XE, Cisco networking devices (SNMP), Cisco Snort, Cisco Unified Contact Center Express (UCCX), City of Gloversville, NY, City of Houston Fire Department, TX, City of La Vergne, TN, City of Ottawa, Canada, City of Riviera Beach, FL, City of Sugar Land, TX, Clackamas Community College, Claimlinx, Clarion Safety Systems, Claude Desktop, ClearCare Periodontal & Implant Centre, Co-op Credit Union, Cocamar Cooperativa Agroindustrial, Cohen’s Fashion Optical, Coilplus, Cole Huber, LLP, Collins Aerospace, Colombia’s CNSC, Comcast, Community Unit School District 201, Computer World WLL, Conduent Business Services, LLC, ConnectWise Automate, Consolidated Restaurant Operations, ConvExx, Cooperativa Esercenti Farmacia Scrl, Core Resources Inc, Crave Management, Crenshaw Community Hospital, Crown Automotive Sales, Cursor, CyPark, D Magazine Partners, Dairy Farmers of America, Dakota Dostavka, Darvin Furniture, DataChain, Dayal Metal Containers Factory LLC, DCS Technologies Inc, Deco Dental, Defensoría del Pueblo de Colombia, Dekalb County, GA, Dell BSAFE Crypto-C, Dell CloudLink, Delmia Apriso, Delta Electronics ASDA-Soft, Delta Electronics CNCSoft-G2, Delta Electronics DIAScreen, Delta, Dental Society of La Plata, Dentsu Merkle, Dermatology Associates, Designs for Vision, Desjardin Bank Group, Desjardins, Devolutions, Dilosa Food Companies, Dimarco Group LLC, Disseny Dental, Django, dmwapp, Docker runC, Doctor Alliance, Docurail, Dodo, Doha British School, DomeWatch, Domy, Double Oak Construction, Dublin Airport, DUC App, Dulcich, Dundee City Council, Durvet, E-First Aid Supplies, East Jefferson General Hospital, Eastern Cape Department of Human Settlements, South Africa, Easterseals Arc of Northeast Indiana, Echo Lake Foods, Econo-Pak, Eligibility Tracking Calculators, Elliott Tax Service, Elmcrest Children’s Center, Encore Repair Services, ENEA, Enem Nostrum Remedies, Enessance Holdings, Engineered Profiles, Entr’ouvert Lasso, Envoy Air, Episource, LLC, Ernst & Young, Essential Cabinetry Group, Essilor of America, Eticex Hosting, evernote-mcp-server, Evogence, Evolve Mortgage Services, over 266,000 F5 BIG-IP instances, FA Servers, Fast Freight, Fatih Turizm, Fellou browser, Fidelity Pension Managers, Nigeria, Figment POS, FinWise, Fleet Landing, Flegenheimer International, Flock, Florida Marking Products, Florida-Spectrum Environmental Services, Form Energy, Inc, Fort Wayne Medical Education Program, Fouad Alghanim & Sons Group of Companies Holding, Fountains Condominium Operations, Framework Secure Boot, Francehopital, Fujifilm Biotechnologies, Fédération Internationale de l’Automobile (FIA), G & H Distributing, G-Plans, G-Xchange, Inc, G. Hauswirth Architects, Galine, Frye, Fitting & Frangos, LLP, Gardiners Solicitors, Garvin Promotion Group, Gas Generator Solutions, Gateworks Corporation, GB Mail, GCC Productions Inc. Fade In, GeBePro, Gemini Group, General Micro Systems (GMS), George E. Weems Memorial Hospital, Gerar, Gericke AG, Gerson & Schwartz Accident & Injury Lawyers, GIMP, Gittens Healthcare, Gladinet CentreStack, Gladinet Triofox, Global Go, GlobalLogic Inc, Goglia Nutrition LLC, Goodfellow & Schuettlaw, Google Chrome, Google’s Find Hub, Grande Prairie Public Library, Greater Mental Health of New York, Gulf Warranties LLC, Gullco International, Gun Accessory Supply, Habib Bank AG Zurich, Hall Estill, Harmony Brands, Harvard University, Health and Vitality Center, Health Dimensions Group, Healthy Living Market and Café, Heart South Cardiovascular Group, Heartland Health Center, Heimbrock, Heimdall Data, HeiTech Padu Berhad, Hello Cake, Hematology Oncology Consultants, Henrietta Ezeoke Law Firm, Henry Raymond & Thompson, Heywood Hospital, Hikvision iSecure Center, Hitzinger, HMP Global, Holtz Office Support, Home Assistant Green, Hometown Credit Union, Hongji Metal, Hosteur, HSBC USA, Huber, Erickson & Bowman, Huddle01, Hyundai AutoEver America, I-Tek Medical Technologies, IBEW Local 697, iCare Software, ICET Studios, ICTBroadcast, IKAD, Il Manifesto, Imagicle, Indian Spring Country Club, ING Bank, Instituto Nacional de Oftalmologia, Peru, Integrated Silicon Solution, Inc, Intel CPUs (TEE.fail), International Social Survey Programme (ISSP), International.com, Invacare, Ioxo & Stream Computers, IPrimus, Iran’s Ravin Academy, Iraqi Electoral Commission, IREM companies, Irwin Car, Izaki Group Investments, J & S Electrical And Lighting Supply, JA Jennings, Jack’s Family Restaurants, JavaScript expr-eval, Jazeera Airways, JC Auto Accident Law Firm, Jean-Georges, Jewett-Cameron, JFS Wealth Advisors, Kansas City Police Department, KS, Karnes Electric Cooperative, Kasmawi, Kaufman & Stigger, Kaufman County, Texas (twice), Kearney Public Schools, NE, Kelowna airport, BC, Kettering Health, Khan and Associates CPA, Khatami Law, KHL Printing, Kipp & Christian, Kirby Corporation, KIS Asset Evaluation, KISS FM, Kitchen Design Concepts, KLA Instruments, Klae Construction, Kobayashi, Koch & Co, Koch & White Heating & Cooling, Koncise Company, Kottster Server, Krita, KT Corp, Kubernetes runC, Kudela & Weinheimer, Kumwell, Kwik Mix Materials, LaBonne, Land Title Guaranty, Lanscope Endpoint Manager, LaRosa’s Pizzeria, Latona Trucking, 42 Latvian municipalities, Laxmi Niwas Palace, Legacy Health, Legacy Manufacturing, Legal Aid Agency, Lexmark CX532adwe, LG U+, LGAA LLC, Lidera Network, LifeBridge Health, Limocar, Lincoln University, LMHT Associates, LNER, Logitech, Long Island Weight Loss Institute, Lorber, Greenfield & Polito, LLP, Louvre Museum, LP Insurance, LuBian, Ludwigshafen, Germany, Luis Garratón, Lumma Stealer, Luxury Escapes, Lüks Artvin Seyahat, M-TIBA, Mack Energy, Magna Hospitality Group, Mailing.com, Maine Course Hospitality Group, Mainetti UK, Maki Building Centers, Malibu Boats Australia, Manassas City Public Schools, Mango, Mango’s Tropical Cafe, Manko Window Systems, Marine Turbine Technologies, Marmotech, Matlusky, Max.ru, Mayco International, McDonald Building, McIntosh Labs, Mciver Engineering & Controls, Mecanex USA, MedImpact, Meinhardt Group, Meritage Hospitality, Metal Pros, Methodist Homes of Alabama & Northwest Florida, MetroWest Community FCU, Mexican Bank Debtor, Michael R. Schwartz, MD, FACS, Microbix Biosystems, Microsoft SharePoint, Microsoft Teams, Microsoft Windows, Middlesex Appraisal Associates, Middlesex Endodontics, Miljödata, Mission City Community Network, Inc, Modernizing Medicine (ModMed), Mold In Graphic Systems, Monsta FTP, Montage Marketing Services, Moonlight Basin, More Than Gourmet, Morris Communications Company LLC, Motex Lanscope Endpoint Manager, Mountain West, Moxa security appliances, MS Metal Solutions, MSC-Wireless, Mt. Baker Imaging, Muji, MusikComputer GmbH, MyCardiologist, MyVidster, NAHGA Claims Services, NasDem Party, National Coatings, National Informatics Centre (NIC) Kavach, National Institute of Administration, Navigator Business Solutions, Nelligan White Architects, NetcoreCloud, Netgate pfSense CE, New Toyo International Holdings Ltd, Newk, Newmark Healthcare Services, Nikkei, Nintendo, NJ Lenders Corp, Noble Compaña de Seguros, Nobu Restaurants, Noroaco, Northern Light Technologies, Northern Montana Health Care (NMHC), Northwest Radiologists, NurseSpring, NVIDIA CPUs (TEE.fail), OB-GYN Associates, OCI International Holdings, Oglethorpe, OMS, One Agency Eastlakes, oobabooga, OpenAI Assistants API, OpenAI Atlas browser, OpenEyes Technologies, Opera Neon, Oracle E-Business Suite, Oracle VirtualBox, Origin Energy, Origin, Oscars Group, Ouranos, Outcomes One, Inc, OYO Hotel & Casino Las Vegas, Palacios Marine Industrial (PMI), Palomar Health Medical Group, Pan-American, Pangea, Paris Rétina Vision, Paterson & Dowding, Patron Insurance, Patterson-Schwartz & Associates, Inc, PCB Uitvaartzorg, People’s Postcode Lottery, PeopleGuru Holdings, Inc, Peppermint Properties, Peraso, Perplexity Comet, Phia Group, Phillips Hue Bridge, Phillips Printing Company, Phoenix Village Dental, PHP CGI, PHPUnit, Pine Pharmaceuticals, Pinto Coates Kyre & Bowers, Pittsburgh Gastroenterology Associates, Pixar OpenUSD, Plastics Extrusion Machinery, Platinum Wines & Spirits, PLP SoCal, Pocatello Ready Mix, Polymarket, Ponzini SPA, Post Ranch Inn, PQCNC Hospitals, Precision Machined Products, Prime Dental, Pritchard Brown & Chillicothe Metal, Productive Tool Products, Professional’s Choice Sports, Propertyfinder / PropSpace CRM, Prosper, Prova, Provincial Department of Health Services Sri Lanka, Pruksa Holding, PT Kalimantan Prima Persada, Pulse Urgent Care Center, Punjab Forensic Science Agency, Qatar Gas and Tar Company, Iran, QNAP Qhora-322, QNAP TS-453E, Radiant Capital, Ravin Academy, React Native CLI, Real Estate Specialists, Reese Group, Regency Specialist Hospital, Resana, Revive Adserver, Rex-Hide, Ribbon Communications, Richmond Behavioral Health Authority, Riddell Law Group, Right at Home, Ringmor, Rios Espinosa, Ritz, Clark & Ben-Asher, River City Eye Care, RKA Consulting Group, Roblox, Rockhill Women’s Care, Rockstar, Rogers Mechanical, Romanian National Penitentiary Association (ANP), Ronemus & Vilensky, Royal Thai, RPI Roofing, Sai Mai Hospital, Saigon Industrial Service, Samera Health, Samsung Android, Samsung Galaxy S25, San Benito County, CA, San Bernard Electric Cooperative, San Diego Automotive Museum, Santander Bank, SAP Solution Manager, Sarulla Operation, Saturday Spotlight, Saturn Machine, Sauter Modulo, Saxun, Scales Sales & Service, Scouts Canada, Seasons Federal Credit Union, Sedgebrook, Selig Enterprises, Sellars Absorbent Materials, Sensational Teeth, Sensory, Servicios del Valle del Fuerte, Mexico, Seward County, KS, Shadrix & Parmer, Shands Elbert, Shaparak, Shelbyville Police Department, Shollenberger Januzzi & Wolfe, SHRM New Mexico, SIAD, Sierra Vista Hospital & Clinics, Signet Armorlite, Silverado Contractors, Inc, Silverlake Axis, Simon Property Group, Sincros Lab, SK Shieldus, SK-Telecom, Snipe-IT, Soapy Joe’s Car Wash, Soft Serve, Software Unlimited Corp, Sold Real Estate, SonicWall, Sonos Era 300, Sotheby’s, SourceOne Corporation, South African Revenue Service (SARS), South Alabama Regional Planning Commission, South Atlanta Medical Clinic, Speedmais, Spijkermat, Spindletop Center, Sports Medicine and Orthopaedics, Sprague & Jackson, St Stephen’s International, Stephenson’s Rental Services, Stowaway Storage, Studio Corvo Parma, Sullivan Interests, Summit Golf Brands, Summit Hotel Properties, Sunnyvale Elementary School District, Super Quik, Super Value, SuperGrosz, Superior Air Parts, Superior Court of California for the County of San Joaquin, Superior Linen Service, Svenska Kraftnät, Sydney Centre for Ear, Nose & Throat, Sylvester Roofing, SymbolTransport, Synnovis, Synology ActiveProtect Appliance DP320, Synology BeeStation Plus, Synology CC400W, Synology DiskStation DS925+, Systems Integrated, Tass Meister Patent Firm, Tavo Packaging Inc, TBM Service Group, TELACU Property Management, Inc, TENAX Law Group PC, Tenryu America, Tex-Tube, Thailand’s Department of Agricultural Extension (DOAE), The Blood and Marrow Transplant Group of Georgia, The Fence People, The Gerson, The Job Shop, The Laxmi Niwas Palace, The Phia Group, The Thayer Hotel, The Union League of Philadelphia, ThinkPHP, Thompson Dorfman Sweatman, Time Equities, TISZA Világ, TMF Logistics, Toys R Us Canada, TP-Link Festa routers, TP-Link Omada gateways, Trans7, Travere Therapeutics, Tri City Foods, Tri-Century Eye Care, Trojan Construction & Holding Group, Truffle Security Co. TruffleHog, Truro Cannabis, Tryon Distributing, Ubiquiti AI Pro8 UK Ministry of Defence bases, UK National Health Service (NHS), UniCursos, Unigym Gatineau, UnitedLayer, University of Cádiz, University of Pennsylvania, UrbanX, US Attorneys Office (USAO), US Congressional Budget Office (CBO), US Department of Homeland Security (DHS), US Department of Justice (DOJ/FBI), US Federal Aviation Authority (FAA), US Immigration and Customs Enforcement (ICE), US National Security Administration (NSA), USB Memory Direct, UScraft, Vanan Online Services, Vascara, Vietnam, Veeam Agent, Verdugo Hills Dental, Verisure, Vertikal Systems, Vexels, Vibra Hospital, Victorian Chemical, Victory Christian Center, Village of New Lenox, Ville de MontLaurier, Vinomofo, Vitalmex, VIZ Media, Volkswagen, Vrata Tech, VZW Avalon, Wakefield & Associates, WarmBlue, Washington Post, WatchGuard Firebox, WatchGuard Fireware, Watsonville Community Hospital, Waveny LifeCare, We R Family Foundation, Weber, Weintraub Traub Tracy & Virk Cra’s LLP, West Welch Reed Engineers, Western Sydney University, WhatsApp, Wheale Law Firm, Windows Server Update Service (WSUS), Windsurf, Winholt Equipment Group, Wisconsin Department Of Corrections, Wits University, Wood PLC, WordPress Anti-Malware Security and Brute-Force Firewall plugin, WordPress Gravity Forms plugin, WordPress GutenKit plugin, WordPress Hunk Companion plugin, WordPress JobMonster theme, WordPress King Addons for Elementor plugin, WordPress Post SMTP plugin, WordPress Slider Revolution plugin, Workers Compensation Insurance Rating Bureau of California, Wright Tool, Wright-Gardner Insurance, X.Org Server, Xortec, Xubuntu website, XWiki, Yaesu, Yas Takaful Dubai Insurance, Zacho-Lind, Zierick Manufacturing Corporation, Zoho ManageEngine, Zoom Workplace, and ZZ Dats have reported hacking or compromises this month.

Amazon Web Services (AWS US-EAST-1), Microsoft 365, Microsoft Azure (more than once), Microsoft Security Response Center, and YouTube have suffered from outages this month.

Internet access throughout Bermuda, Cameroon, Dominican Republic, Italy, Jamaica, Kenya, Pakistan, Philippines, Tanzania, and Ukraine has been blocked our down for extended periods.

Last months updates broke Cisco Duo, HP OneAgent / Microsoft Entra ID, Microsoft Internet Information Server (IIS), Microsoft Outlook, smart card authentication, sprotect.sys compatibility, USB mouse and keyboard in WinRE, wallpaper managers, Windows 11 Media Creation Tool, Windows Task Manager and Start menu, and the Windows Update Hotpatch service.

There’s a new type of worm out there. GlassWorm uses a combination of Solana, UTF-concealed code, and remote access trojans to ensure that it’s impossible to shut down or kill from the top-down while still being fully manageable by the people behind it. In addition, it uses compromised developer accounts to propagate by uploading itself to their repositories in order to grow the botnet to new audiences. This signals the first major use of these three aspects in combination and the first software of its kind to operate with no centralized command-and-control server. This evolution is going to cause a massive change in how we deal with security incidents and how we protect our devices.

Half of all the satellites in orbit are exposing your information in clear text.

Nearly 2 billion accounts from hundreds of thousands of different platforms have been disclosed in a credential stuffing database (Synthient). While this appears to mostly be the result of stealer logs (the result of hacked devices), there is a lot of duplication in the data which demonstrates a lot of password re-use and thus a high chance of other accounts being abused as a result.

The boss of a defense contractor, Trenchant, has been selling exploits to foreign governments.

The Louvre Museum security system was “hacked” in order to enable thieves to steal the crown jewels. It’s hardly hacking when the password was so stupid.

“Beware that, when fighting monsters,
you yourself do not become a monster.”
— Friedrich Nietzsche

Now for the good news:

SpaceX disabled 2,500 Starlink terminals in Asia to curb their use by scammers.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is relatively small this month. The typical computer should see roughly  4.0 GB in updates today. Let’s get started.

Microsoft released 41 updates to address 68 vulnerabilities in Azure Monitor Agent, Customer Experience Improvement Program (CEIP), Dynamics 365 Field Service (online), GitHub Copilot and Visual Studio Code, Host Process for Windows Tasks, Microsoft Configuration Manager, Microsoft Dynamics 365 (on-premises), Microsoft Edge, Microsoft Graphics Component, Microsoft Office, Microsoft Office Excel, Microsoft Office SharePoint, Microsoft Office Word, Microsoft Streaming Service, Microsoft Wireless Provisioning System, Multimedia Class Scheduler Service (MMCSS), Nuance PowerScribe, OneDrive for Android, SQL Server, Storvsp.sys Driver, Visual Studio, Visual Studio Code CoPilot Chat Extension, Windows Administrator Protection, Windows Ancillary Function Driver for WinSock, Windows Bluetooth RFCOM Protocol Driver, Windows Broadcast DVR User Service, Windows Client-Side Caching (CSC) Service, Windows Common Log File System Driver, Windows DirectX, Windows Hyper-V, Windows Kerberos, Windows Kernel, Windows License Manager, Windows OLE, Windows Remote Desktop, Windows Routing and Remote Access Service (RRAS), Windows Smart Card, Windows Speech, Windows Subsystem for Linux GUI, Windows TDX.sys, Windows WLAN Service, and MSRT. This includes security updates. A reboot is required.

Oracle released 374 security updates this quarter to address 170 vulnerabilities in 29 product lines.

Apple released updates for iOS 18.7.2, iOS 26.1, iPadOS 18.7.2, iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, Safari 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1, and Xcode 26.1. This includes security updates. Use Apple Software Update to install the most current versions.

iOS 18.7.2 and 26.1 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 18.7.2 and 26.1 are security updates. Use Settings, General, Software Update to install the most current update.

watchOS 26.1 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 26.1 is a security update. Use System, Software Update to install the most current version.

visionOS 26.1 is a security update. Use System, Software Update to install the most current version.

Google ChromeOS 141.0.7390.115 and ChromeOS LTS 138.0.7204.296 are security updates. Use Menu, Help, About to install the most current version. A reboot is required.

Fedora 43 updates libraries, adds Hare support, changes UEFI+MBR requirements, and enables automatic updates. This is not a security update.
https://getfedora.org/en/workstation/download/

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Tahoe (26.x) means that macOS Ventura (13.x) and older are no longer supported. If you can not install at least macOS Sonoma (14) on your Mac then you should immediately remove your device from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The current — and final — release of the Windows 10 (v22H2) is end of life (EOL). All non-LTS versions of Windows 10 without ESU are now out of support, with the sole alternatives being to upgrade to Windows 11 or enable Extended Service Updates (ESU). If you aren’t sure whether you are using LTS, you aren’t. Enable the ESU now.

The current release of the Windows 11 (v25H2) is very large (30% larger than any previous release) so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it. If not, switch to Linux (Mint is nice) or replace your computer.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, drivers for hardware you’re not using (like old printers), and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with a SaferPC Subscription and we will install updates each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 25.10.2 is a security update.
https://www.amd.com/en/support

BullZip PDF Printer 2025.2.0.2990 is a security update.
https://www.bullzip.com/products/pdf/info.php#download

Epson ET-2720 2.100.00 is a security update.
https://epson.com/Support/Printers/All-In-Ones/ET-Series/Epson-ET-2720/s/SPT_C11CH42201?review-filter=Windows+10+64-bit

Epson ET-2988 3.60.00 is a security update.
https://epson.com/Support/Printers/All-In-Ones/ET-Series/Epson-ET-2988/s/SPT_C11CL41203?review-filter=Windows+11

Epson ET-15000 3.60.00 is a security update.
https://epson.com/Support/Printers/All-In-Ones/ET-Series/Epson-ET-15000/s/SPT_C11CH96201?review-filter=Windows%2010%2064-bit

MTPdrive 4.5.179 resolves a stability bug. This is not a security update.
https://www.mtpdrive.com/

Plustek ePhoto Z300 6.7.0.5 resolves a couple bugs. This is not a security update.
https://plustek.com/us/products/film-photo-scanners/ephoto-z300/support.php

TP-Link Archer A6 v3 250718 improves stability and PPPoE support. This is not a security update.
https://www.tp-link.com/us/support/download/archer-a6/v3/#Firmware

TP-Link Archer AX72 v1.60 250814 is a security update.
https://www.tp-link.com/us/support/download/archer-ax72-pro/#Firmware

UniFi U6 Professional 6.7.33 adds packet capture, Roaming Assistant, 5GHz channel selection, mesh improvements, and resolves a dozen bugs. This is not a security update.
https://www.ui.com/download/software/u6-pro

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.84.132 is a security update.
https://brave.com/

Firefox 145.0 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 140.5.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Google Chrome 142.0.7444.134 is a security update.
https://www.google.com/chrome/

Microsoft Edge 142.0.3595.69 is a security update.
https://www.microsoft.com/en-us/edge/business/download

SeaMonkey 2.53.22 is a security update.
https://www.seamonkey-project.org/

Email Updates

One or more of these are likely to be of interest to everyone.

DavMail Gateway 6.5.1 resolves several bugs. This is not a security update.
https://davmail.sourceforge.net/

Spark 3.27.2.122708 ramps up the AI integration. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.27.2.122707 ramps up the AI integration. This is not a security update.
https://sparkmailapp.com/

Thunderbird 144.0.1 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 9.6.4 resolves several bugs. This is not a security update.
https://anydesk.com/en/downloads

AnyDesk (macOS) 9.5.1 resolves several bugs. This is not a security update.
https://anydesk.com/en/downloads

curl 8.17.0 resolves dozens of bugs. This is a security update.
https://curl.haxx.se/windows/

Discord November 4, 2025 resolves dozens of bugs. This is not a security update.
https://discord.com/download

Dropbox 236.4.5918 resolves several bugs and improves stability. This is not a security update.
https://www.dropbox.com/

Google Drive 117.0 is a security update.
https://drive.google.com/start

MeshCentral 1.1.53 resolves a couple bugs and improves UI controls. This is not a security update.
https://meshcentral.com/info/downloads.html

Mumble 1.5.857 is a security update.
https://www.mumble.info/

Nextcloud Server 32.0.1 updates libraries and resolves dozens of bugs. This is a security update.
https://nextcloud.com/

OneDrive 25.184.0921.0004 adds Copilot actions, improves offline mode, renames binaries, and adds the ability to cleanly opt out of the OneDrive Backup service. This is not a security update.
https://support.microsoft.com/en-us/onedrive

Rclone 1.71.2 updates libraries and resolves several bugs. This is a security update.
https://rclone.org/

Signal 7.78.0 resolves a couple bugs. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.63.3 adds split-screen support, improves performance and resolves many bugs. This is not a security update.
https://signal.org/android/apk/

Syncthing 2.0.11 migrates database to SQLite, improves log structure, changes CLI syntax, and resolves several bugs. This is not a security update.
https://syncthing.net/

Technitium DNS Server 14.0.1 is a security update.
https://technitium.com/dns/

Telegram 6.2.4 makes a couple minor changes in the UI and resolves crash bugs. This is not a security update.
https://telegram.org/

WinSCP 6.5.4 is a security update.
https://winscp.net/eng/index.php

Zoom 6.6.6.19875 resolves several bugs. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.22 resolves several bugs related to facial tracking. This is not a security update.
https://en.3tene.com/

Grayjay 342 resolves a couple bugs. This is not a security update.
https://grayjay.app/index.html

iTunes 12.13.9.1 is a security update.
https://www.apple.com/itunes/download/

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.122.2 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

Nintendo Switch 21.0.0 updates cosmetics and cloud settings, and resolves a couple bugs. This is not a security update.
https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/system%20updates/p/989

PS5 2025.101 displays more hardware details and messaging. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

SteamOS SteamDeck Update 2025.11.06 improves UI and resolves a couple bugs. This is not a security update.
https://store.steampowered.com/news/app/1675200/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Format Plugins 1.1.2 is a security update.
https://helpx.adobe.com/security/products/formatplugins/apsb25-114.html

Adobe Illustrator 29.8.3 and 30.0 are security updates.
https://helpx.adobe.com/security/products/illustrator/apsb25-109.html

Adobe Illustrator Mobile 3.0.10 is a security update.
https://helpx.adobe.com/security/products/illustrator-mobile-ios/apsb25-111.html

Adobe InCopy 21.0 and 20.5.1 are security updates.
https://helpx.adobe.com/security/products/incopy/apsb25-107.html

Adobe InDesign ID21.0 and ID20.5.1 are security updates.
https://helpx.adobe.com/security/products/indesign/apsb25-106.html

Adobe Pass 3.8.0 is a security update.
https://helpx.adobe.com/security/products/pass/apsb25-112.html

Adobe Photoshop 26.9 is a security update.
https://helpx.adobe.com/security/products/photoshop/apsb25-108.html

Adobe Reader DC 25.001.20844 resolves stability bugs. This is not a security update.
https://get.adobe.com/reader

Adobe Substance 3D Stager 3.1.6 is a security update.
https://helpx.adobe.com/security/products/substance3d_stager/apsb25-113.html

Calibre 8.14.0 resolves several bugs. This is a security update.
https://calibre-ebook.com/

Columns++ 1.3 resolves several bugs and improves compatibility. This is not a security update.
https://github.com/Coises/ColumnsPlusPlus

LibreOffice 25.2.7 resolves over 40 bugs. This is not a security update.
https://www.libreoffice.org/

Nextcloud Desktop 4.0.1 resolves several bugs. This is not a security update.
https://nextcloud.com/

Notepad++ 8.8.7 adds a publisher certificate for the installation packages and resolves several bugs. This is a security update.
https://notepad-plus-plus.org/

OpenOffice 4.1.16 is a security update.
https://www.openoffice.org/download/

Paint.net 5.1.11 resolves several bugs. This is not a security update.
https://www.getpaint.net/

PDF-XChange Editor 10.7.5.403 updates libraries and resolves several bugs. This is a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

Operating System Updates

These are for specific Linux flavors and alternative operating systems and, sadly, are unlikely to be of interest to most people.

Fedora 43 updates libraries, adds Hare support, changes UEFI+MBR requirements, and enables automatic updates. This is not a security update.
https://getfedora.org/en/workstation/download/

Google ChromeOS 141.0.7390.115 is a security update. Use Help, About to install this update.

Google ChromeOS LTS 138.0.7204.296 is a security update. Use Help, About to install this update.

iOS 18.7.2 and 26.1 are security updates.
https://support.apple.com/en-us/100100

iPadOS 18.7.2 and 26.1 are security updates.
https://support.apple.com/en-us/100100

macOS Tahoe 26.1 is a security update.
https://support.apple.com/en-us/100100

macOS Sequoia 15.7.2 is a security update.
https://support.apple.com/en-us/100100

macOS Sonoma 14.8.2 is a security update.
https://support.apple.com/en-us/100100

tvOS 26.1 is a security update.
https://support.apple.com/en-us/100100

visionOS 26.1 is a security update.
https://support.apple.com/en-us/100100

watchOS 26.1 is a security update.
https://support.apple.com/en-us/100100

Security Software Updates

One or more of these is likely to be of interest to most people.

KeePass 2.60 adds group path search, consistent shortcuts and hot keys, improved import options, and improves several other UI and integration features. This is not a security update.
https://keepass.info/

ProtonVPN 4.3.5 resolves several bugs and adds FIDO2 security key support. This is not a security update.
https://github.com/ProtonVPN/win-app/releases/latest

RogueKiller 16.5.1 resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

SanDisk PrivateAccess 6.4.14.0 adds messaging signaling that the software is now end of life and should be removed as soon as possible. Migrate your data out of PrivateAccess and remove it.
https://support-en.wd.com/app/answers/detailweb/a_id/48025

Stinger 13.0.0.562 adds support for new detections. This is not a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

uBlock Origin 1.67.0 resolves a couple bugs and improves various features. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

WebBrowserPassView 2.18 improves compatibility. This is not a security update.
https://www.nirsoft.net/utils/web_browser_password.html

YARA 4.5.5 resolves several bugs. This is not a security update.
https://github.com/VirusTotal/yara/

Capture Updates

These are unlikely to be of interest to most people.

Open Broadcaster Software 32.0.2 resolves a couple crash bugs. This is not a security update.
https://obsproject.com/

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.5.1 adds support for new encodings and improves menu editing. This is not a security update.
https://www.dvdfab.cn/download.htm

StreamFab 6.2.6.2 adds multithreading, improves compatibility, and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 3.0.3.1 resolves several bugs. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Education updates

One or more of these are likely to be of interest to most people.

Zotero 7.0.27 resolves several bugs. This is not a security update.
https://www.zotero.org/

Zotero (macOS) 7.0.29 resolves Safari and Word clipboard issues. This is not a security update.
https://www.zotero.org/

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.11.18 resolves several bugs. This is not a security update.
https://1password.com/downloads/

Beyond Compare 5.1.6.31527 resolves several bugs. This is not a security update.
https://www.scootersoftware.com/download

Bitwarden 2025.10.0 improves observation of data ownership policies, adds direct importer for Chromium browser accounts, and resolves several bugs. This is not a security update.
https://bitwarden.com/

BulkFileChanger 1.74 resolves a field copy bug. This is not a security update.
https://www.nirsoft.net/utils/bulk_file_changer.html

CCleaner 7.01.1042 resolves several bugs and renames several features. This is not a security update.
https://www.ccleaner.com/

Cygwin 3.6.5 resolves several bugs. This is a security update.
https://cygwin.com/

DesktopOK 12.21 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.6.39.0 resolves several bugs. This is a security update.
https://dngrep.github.io/

Everything 1.4.1.1030 is a security update.
https://www.voidtools.com/

Everything SDK 1.4.1.1030 is a security update.
https://www.voidtools.com/support/everything/sdk/

Everything Toolbar 2.1.1 resolves a couple bugs. This is a security update.
https://github.com/stnkl/EverythingToolbar/

ExplorerPatcher 26100.4946.69.6 improves compatibility and resolves several bugs. This is not a security update.
https://github.com/valinet/ExplorerPatcher/

Fing 3.9.2 adds PDF reporting and resolves several bugs. This is not a security update.
https://www.fing.com/products/fing-desktop-download-windows

Git SCM 2.51.2 resolves several bugs. This is not a security update.
https://git-scm.com/

GoodSync 12.9.14 resolves several bugs. This is not a security update.
https://www.goodsync.com/

Homedale 2.22 improves filtering. This is not a security update.
https://www.the-sz.com/products/homedale/

LessMSI 2.10.4 resolves a selection bug. This is not a security update.
https://lessmsi.activescott.com/

MPAM 1.441.121.0 adds support for new detections. This is not a security update.
https://www.microsoft.com/en-us/wdsi/defenderupdates

MultiMonitorTool 2.21 resolves a stability bug. This is not a security update.
https://www.nirsoft.net/utils/multi_monitor_tool.html

NTLite 2025.11.10669 adds support for Windows 24H1 and updates component support. This is not a security update.
https://www.ntlite.com/download/

PolicyPlus October 2025 updates included policies. This is not a security update.
https://github.com/Fleex255/PolicyPlus/releases

PowerToys 0.95.1 resolves several bugs. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

Process Explorer 17.07 adds strings for Arm64 binaries and fixes a notification bug. This is not a security update.
https://learn.microsoft.com/sysinternals/downloads/process-explorer

PSAppDeploy 4.1.7 resolves several bugs and improves compatibility. This is not a security update.
https://psappdeploytoolkit.com/

Remotly 1.35.0 adds UPnP port forwarding. This is not a security update.
https://remotly.com/

RDCMan 3.11 enables Entra ID login. This is not a security update.
https://learn.microsoft.com/sysinternals/downloads/rdcman

ripgrep 15.1.0 resolves a bug with line buffering. This is not a security update.
https://github.com/BurntSushi/ripgrep/releases/latest

RoboForm 9.8.3 resolves a security bug. This is a security update.
https://www.roboform.com/

WinGet 1.12.350 improves compatibility and resolves several bugs. This is not a security update.
https://github.com/microsoft/winget-cli/releases/latest

WinScan2PDF 9.44 adds support for newer hardware. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

ZoomIt 9.20 adds ability to export to MP4 and GIF. This is not a security update.
https://learn.microsoft.com/sysinternals/downloads/zoomit

Developer Updates

These are unlikely to be of interest to most people.

.NET Runtime 9.0.10 and 10.0.0 are security updates.
https://dotnet.microsoft.com/en-us/download/dotnet

Android Studio 2025.2.1.7 resolves several bugs. This is not a security update.
https://developer.android.com/studio

DB Browser for SQLite 3.13.1 resolves several bugs and improves compatibility. This is not a security update.
https://sqlitebrowser.org/

GameMaker Studio 2024.14.0.207 is a security update.
https://www.yoyogames.com/en/gamemaker

GDevelop 5.5.245 adds new templates and resolves several bugs. This is not a security update.
https://gdevelop.io/download

GitHub Desktop 3.5.4 is a security update.
https://desktop.github.com/

Go 1.25.4 resolves several bugs. This is not a security update.
https://go.dev/

Inno Setup 6.6.0 improves dark mode, custom styling support, and pascal scripting. This is a security update.
https://www.jrsoftware.org/isdl.php

Java 8u471 is a security update.
https://www.java.com/en/download/manual.jsp

Node.js 22.21.1 resolves several bugs. This is not a security update.
https://nodejs.org/en/

Node.js 24.11.0 marks the transition to LTS. This is not a security update.
https://nodejs.org/en/

Node.js 25.1.0 updates libraries and resolves several bugs. This is not a security update.
https://nodejs.org/en/

SQLite 3.51.0 adds a couple new macros, improves JSON support and CLI capabilities, and resolves several bugs. This is not a security update.
https://www.sqlite.org/download.html

TortoiseGit 2.18.0 updates libraries and resolves several bugs. This is not a security update.
https://tortoisegit.org/

Visual Studio Code 1.105.1 resolves several bugs. This is not a security update.
https://code.visualstudio.com/

WinMerge 2.16.52 resolves several bugs. This is not a security update.
https://winmerge.org/

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 7.2.4 resolves several bugs and improves compatibility. This is not a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

HumHub 1.17.4 adds a nonce for OEmbeds and resolves several bugs. This is a security update.
https://www.humhub.com/en

MailEnable 10.54 resolves several bugs and improves logging. This is a security update.
https://www.mailenable.com/

ownCloud Client 6.0.2.17506 is a security update.
https://owncloud.com/desktop-app/

Piwigo 15.7.0 is a security update.
https://piwigo.org/

Contact Form 7 6.1.3 resolves a couple bugs. This is not a security update.
https://wordpress.org/extend/plugins/contact-form-7/

Email Log 2.62 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/email-log/

WordPress Importer 0.9.5 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/wordpress-importer/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2025-05-13

Welcome back, Folks!

Today is Patch Tuesday for May, 2025.

It’s as safe as it’s going to be to upgrade to Windows 11 24H2 or macOS 15/Sequoia.

If your Windows 10 (or older) computer can not be upgraded to Windows 11, or if you used a registry or installation bypass to install an older version of Windows 11 on it that is no longer supported, then it’s time for you to start looking for a replacement computer. Actually, the time was months ago. Pickin’s are thin right now. 🙁

However… if you do need to replace your laptop there’s an awesome Lenovo laptop available at Costco right now for $600 (plus tax & shipping).

There were 495+ major hacks, and over 600 application updates this month. It’s an insanely large month, with about 6 GB of updates for most users.

This Month in Technology

1st Health Inc, 30 London Job Centres, 4chan, 90 Degree Benefits, Inc – MN/WI Office, Abergavenny, Abilene, Texas, Active! Mail, Adelaide’s Women’s and Children’s Hospital, Adobe Acrobat Reader DC, Advanced Simulation Technology, Adyen, Agencia Browne y Espinoza, Ahold Delhaize, Alabama government, Alabama Ophthalmology Associates, Allegra, Allied Telesis, Inc, AllTrust, Alternate Solutions Health Network, Altior Healthcare, Alvin Independent School, Amazon ElastiCache, American Eagle Logistics, American Express Travel Related Services Co, Amethyst Group, Amtech Software, Andy Frain Services, Anfarm Hellas, Apache ActiveMQ, Apache Parquet, Apache Roller, Apache Tomcat, Apple AirPlay, Apple iPhone, Apple iPhone Messages, Apple macOS, Arizona Arthritis and Rheumatology Associates, Arkansas Primary Care, Ascension Health, Associated Wholesale Grocers, Astra Products, ASUS AiCloud, ASUS AMI, ASUS DriverHub, Avast Free Antivirus, Balance Diagnostics, Baltimore City Public Schools, Bangalore Water Supply and Sewerage Board (BWSSB), Barnstable County Sheriff’s Office, Barr Dermatopathology, Bartlesville Public Schools, BayMark Health Services, Bell Ambulance, Berkeley Research Group, Bertie, NC Schools, Bervar and Jones, Bigfork Valley Hospital, Bilbie Faraday Harrison, Bindi SpA, Bio-Clima Service, Bloom Family Eye Surgeons, Blue Shield of California (to Google!), Bluestone Bank, Bolivar Insulation, Boudreaux’s Specialty Compounding Pharmacy, Boulanger, Brainard Surgery Center LLC, British Columbia Health Authority, Broadcom Fabric OS, Brunswick Medical Center, Brydens Lawyers, Business Functions, Cabot Medical Care, California Correctional Health Care Services, Caltrol Inc, Cambridge University Press & Assessment, Canada Revenue Agency, CAPTCHA systems on 400,000+ websites (AkiraBot), Caritas Catholic charities, Carlton County Public Health and Human Services, Carrefour Mobile, Cato Networks Cato Client, Cell C, Central Texas Pediatric Orthopedics, Chang Shen Hospital, Charleston Fire Department, Chepstow, Chicano Federation of San Diego County, Cisco IOS XE, Cisco Webex, City of Bristol, TN, City of Grove, City of Long Beach, CA, Cloudera Hue Ace Editor, CMC Corporation, Co-op Group, Cobb County, GA, Colorado River Adventures, Community Dental Care, Commvault Command Center, Commvault, Complete Payroll SolutionsCompliance Consulting Group, Comport Technology Solutions, Conduent, Conrey Insurance Brokers & Risk Managers, Corporate Flight, Cortez Resources, Cosmos, Couples Learn, CPUs, Craft CMS, Culinary Services of America Inc, Curve Finance, Custom Paper, D’Granel, Dale Partners Architects, Dameron Hospital, Daniels & Taylor, PC, DaVita, six DDoS-for-hire platforms, Dedicated Web Consultants, DermCare Management, Destination Toronto, Diedrich Coffee, Dior, Discord, Disney, Dominion Lending Centres, Drug and Alcohol Treatment Services, Inc, Dutch Ministry of Climate Policy and Green Growth, Dutch Ministry of Economic Affairs, Dutch Ministry of the Interior and Kingdom Relations, DYNAMIS Insurance, East Central Missouri Behavioral Health Services, eCharge Hardy Barth, Eclipse ThreadX NetX Duo, ECOM America, Edinburgh schools, Ehlers Inc, EIZO Rugged Solutions, EMX Enterprises, Endue Software, Enflame Technology, Erlang/OTP SSH, Erlanger Health, ESP Associates, Esse Health, Everest Bank, eXch, Extreme Fire, Family Christian Health Center, Feldman & Lopez, Fleet Canada, Fogelman Management Group, Forsyth County Schools, 16,000 Fortinet devices, FortiSwitch, Fowler Elementary School District, Framlingham College, France’s Municipality of Ardon, Franklin Nursing Home, Frederick Health Medical Group, FreeType 2, Frisco Chamber, Galvatech, Gardena Honda, GeoLogics Corporation, German Association for East European Studies, Gistic Research, Gladinet CentreStack, Gladinet Triofox, Global Media Group, GlobalX, GMA Network, Google Chrome DevTools, Google Sites, Government of Peru, Great Plains Transport, GStreamer, Hacienda La Puente Unified School District, Hamilton County, TN, Hamrah Aval, Harman Becker MGU21, Harrods, Hayward Quartz Technology, HC Sheriff, HealthEquity, IncHeinz Hammer Vertragswerkstatt, Helix Tools, Hertz Corporation, Highland Rivers Behavioral Health, Hitachi Energy MicroSCADA Pro/X SYS600, Hong Kong Science and Technology Parks, HOPI, Horizon Behavioral Health, Hyalogic, Hyundai Motor Group, IBM Cloud, IBM Portal, iClicker, iHeartMedia + Entertainment, IKEA, Impact Canada, Inaba Denki Sangyo CHOCO TEI WATCHER, Independent Financial Services, Independent Title Agency, Indian Air Force (IAF) aircraft, Indian government defence websites, 1.5+ million Indian websites, Inductors Inc, Insight Partners, Insight Pipe Contracting, Interior Health, Internet Initiative Japan, Iowa County, WI, Iris ID, Isle of Man government, Ivanti Endpoint Manager, J. Banks Design, Jackpot Junction, Jacksonville Medical Care, James & Sons Fine Jewelers, Jamjoom Pharma, Janco Steel, Jani-King International, Inc, Jet Ice, Jordan Kuwait Bank, Ju Percussion Group, Julia Evans Accountants, Just Concrete & Masonry, Karachi Port Trust, Kasb Bank, Kaye Lifestyle Homes, Kelly & Associates Insurance Group, Kenworth Del Sur, Khan Academy, Kickidler, KiloEx, King Industries Inc, Kintetsu World Express, Kittrich Corporation, Korea Land and Housing Corporation, KraftKisarna, Kuala Lumpur International Airport, Kyiv Notaries, LabHost, Laboratory Services Cooperative, Lake HVAC, Lake Shore Paving, Lamberti Group, Landmark Admin, Langer & Langer, Langflow, Law Firm of Rochelle McCullough, Law Offices of Chris M. Ingram, Lee Valley Tools, Ltd, Legends International, Lemonade, Lexmark CX331adwe, Limestone District School Board, Lincoln Financial, Lithium Americas, LockBit Ransomware Group, Long Beach Convention and Entertainment Center, Loretto Hospital, Luxion KeyShot, Machu Picchu Foods, Madison School District, Magento, Malaysia Airports Holdings Berhad, Manchester Credit Union, Marc Irwin Sharfman, MD, PA, Marks & Spencer, Marsicovetere & Levine Law Group, Mashburn Construction, Masimo Corporation, Mataró Water Utility Company, MATE Desktop, McElwee Firm, MedDream PACS Server, MedDream WEB DICOM Viewer, MedEx Ambulance, Medical Express Ambulance Service, Megachem Singapore, Mercer County Joint Township Community Hospital, Merri-Makers, Microsoft 365 OAuth, Minyard Morris LLP, Mission Laguna Pathology Medical Group, Monongalia Health System, Mountain View Mushrooms, Movistar Venezuela, Mt. Baker Imaging and Northwest Radiologists, MTN Group, Munich Re, Municipality of Pisa, N8XT, Nagios Log Server, NASCAR, National Social Security Fund (CNSS) of Morocco, Nationwide Recovery Services, Nelson University, Neurological Institute of Savannah & Center for Spine, Nevada Ready Mix, New York Post, Newport Advisory, LLC, Nintendo, Nippon Life Mutual Fund, Nixon, Inc, North Kitsap School District, Northeast Georgia Health System, Northern California Children’s Therapy Center, Nova Scotia Power, Nth Degree, O’Brien & Ryan, OCH Regional Medical Center, Oettinger Brewery, Omni Healthcare Financial Holdings, OnRPG, Onsite Mammography, Oracle, Oracle VirtualBox, Orange County Medical Group Pathology, Oregon Department of Environmental Quality, Orthopaedic Specialists of Connecticut, OttoKit WordPress plugin, Output Messenger, Oversea Casing, Pacific Metallurgical, Palo Verde Hospital, Pawnee Heights Unified School District, Pearson, PESEL, Pharma Force, Pienaar Brothers, Planet Technology Industrial Switches, Planned Parenthood, Plastic Surgery Specialists of Lawrence, PlayStation, Port of Seattle, PR TIMES, Pratt Homes, Premier Meats South Africa, Prestonwood Baptist Church, Inc, Promenade Village Dental, Pryor Morrow, Pulse Urgent Care Center, Qraved, R&N Manufacturing, Radford University, Radware Cloud Web Application Firewall, Raw, Rayle Electric Membership Corporation, Red Chamber, RFID, Richmond СPA, Roblox, Rockwell Automation Industrial Data Center, Rocky View Schools, Roman Catholic Bishop of San Diego, Ruby Servers, Russell Child Development Center, Saint James Hospital Group, Sally B Gold, Salus Group, Samsung phones, Samsung Galaxy S24, Samsung Germany, Samsung MagicINFO 9 Server, San Francisco Campus for Jewish Living, San Francisco crosswalk system, Santa Cruz Properties, SAP NetWeaver, SavantCare, Scharnhorst Ast Kennard Griffin PC, Schultz Industries Inc, Scrubs & Beyond LLC, SeaCMS, Seneca Gaming, Sensata Technologies, Sentara Health, SentinelOne, Setpoint Systems, Seydel Companies, Shinko Shoji, Shopify, Shrader Law, Silgan Containers, SIMCO Electronics, Sinalisa Segurança Viária Ltda, SK Inc, SK Telecom, SogoTrade, Inc, SonicWALL Connect, SonicWall SMA, Sonos Era 300, Sonrisas Dental Health, South African Airways, South African IT, Southern Fidelity, Springer & Steinberg, St Anthony Hospital, St Clair Orthopaedics & Sports Medicine, St James Hospital, Study Hotels, Sunsweet Growers Inc, Sweet Shop USA, Synology BeeStation BST150-4T, Synology DiskStation DS1823xs+, Synology TC500, SysAid, T-Mobile, Takeda, TehetségKapu, TeleMessage, Tenda AC9, Tesla Model 3, Tesla Model S, Texas Health and Human Services Commission, The City of Long Beach, CA, The Fortune Society, The Michelson Organization, Thompson Coburn LLP, Thrive Physical Therapy Partners, TicketToCash, TikTok, TMA Group, Toppan Next, Toronto District School Board, Town of Orangeville, Traefik, Trend Micro Apex Central, Trend Micro Deep Security, Troicare College, True Dental Care for Kids and Adults, TrussWorks International, Tänzer GmbH, Ubiquity UniFi Protect Cameras, UK Department of Work and Pensions, UK Legal Aid Agency, Union Health System, Inc, UniTrak, Universal Window, Urban One, Urban Renewal Authority, US Claims Capital, Inc, US Office of the Comptroller of the Currency (OCC), Vanni and Humphrey, Vastaamo, VeriSource Services, Inc, Verrex, Versa Networks, Via Credit Union, Vicarage Court Solicitors, Victure RX1800, Virtuvian Health, Voigt-Abernathy Company, Wan Hai, Wazuh server, WDEF-TV, Webmin, Weil Construction, Weir Canyon Honda, West Lothian Council, Western New Mexico University, Western Sydney University, Whiteboard Technologies Pvt Ltd, Whitman County Public Hospital District No 3, Wilmington Personal Injury Lawyer – DPLAW, Windows Common Log File System, Windows NTLM hashes, Wisconsin Supreme Court, Wizz Air, Wolters Kluwer, WooCommerce, WordPress AIHub theme, WordPress BuddyBoss Platform Pro plugin, WordPress Flynax Bridge plugin, WordPress InstaWP Connect plugin, WordPress Smart Product Review plugin, WordPress UrbanGo Membership plugin, WorkComposer, WPM Pathology Laboratory, Chartered, XP Investimentos, XRP Ledger NPM Package (xrpl.js), Yale New Haven Health, Yankee Trails, Yodogawa Steel, Yokogawa Recorder, Young Consulting LLC, ZKsync, and Zoom remote control have reported hacking or compromises this month.

4chan, Atlassian Jira, Coinbase 2FA, Exchange Admin Center, Microsoft 365, and pretty much all of Spain (and some neighboring countries) less than a week after bragging about how they were finally able to run on 100% renewable energy, have suffered from outages this month.

By the way, did you know that 4chan was mostly run by the US government? Duh.

Last months updates broke
Broadcom Brocade Fabric OS, Classic Outlook calendar, Classic Outlook typing, Hitachi Vantara, Microsoft 365 “paste special”, Microsoft Entra ID, Microsoft Office, Microsoft Office 2016, Microsoft Outlook online, SAP NetWeaver, SharePoint Online, Windows 10 Start Menu, Windows 11 24H2 upgrades, Windows Domain Controllers, Windows Hello for Business (WHfB) Key Trust, Windows kernel, Windows Remote Desktop, Windows Server 2025, and the Win Recovery Environment (WinRE).

A Florida bill that would have required backdoors to any encryption for social media accounts has failed.

AT&T will be the first of the big telcos to drop their email-to-sms gateway – in only about a month. You’ll still be able to send emails to email addresses and text to and from cell numbers, but their gateway that allows you to send messages between email and text will be disabled in mid June. This should have a massive impact on the amount of spam received by AT&T mobile customers. It will not stop it, of course.

Broadcom is threatening to sue their own customers for installing security updates in VMware.

Your heated car seats (among other features) are exposing you to law enforcement tracking.

IPv6 makes MitM easy.

Kali Linux lost their repo signing key, requiring manual end-user intervention to install security updates.

CISA is “trimming the fat” by removing some of their communication methods (even though I’m sure they were fully automated). This is going to disrupt important intelligence resources for those in the tech industry.

Skype is dead. Microsoft will finally start killing off ActiveX in Office and Microsoft 365. All new Microsoft accounts will now be “passwordless” by default.

I’ve been warning about the Copilot AI storage access risks since they changed their Terms of Service in October. My fears were justified. Microsoft will no longer “accidentally” flag all Gmail messages as spamOr Adobe.

In the wake of a study that demonstrates how easy it was for AI to manipulate Reddit users, Reddit is considering legal action to protect their victims, I mean, users.

Android and Apple both now have auto-reboot to reduce the effectiveness of brute force attacks.

Apple is getting spanked for violating the letter and the intent of the judge’s order following the Apple v Epic Games lawsuit from a couple years ago.

BIG NEWS: US Attorney for the District of Columbia, Ed Martin, calls out Wikimedia Foundation (Wikipedia) for violating 501(c)(3) status by allowing propagandists to flood platform. He gave them until May 15th to turn over documents.

Google is finally consolidating all of it’s country TLDs to use “google.com“. Google will pay $1.4 billion to Texas to settle claims the company collected users’ data without permission. Google’s updated Local Services Ads Terms have sparked privacy fears and threaten confidentiality in medical and legal sectors. Google would never really harvest all of your medical data though, right? LOL.

Now for the good news:

T-Mobile has added satellite-based 5G support to their lineup. While currently in beta, this signals a huge improvement to coast to coast, and in fact world-wide, phone support using Starlink’s satellites to back up your 5G service when no towers are available (like when there’s a power outage or localized service issue or when you live in the middle of nowhere).

I suspect this mean Elon will soon be buying T-Mobile.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is insane this month. The typical computer should see roughly 6 GB in updates today. Let’s get started.

Microsoft released 48 updates to address 83 vulnerabilities in .NET, Active Directory Certificate Services, Azure, Azure Automation, Azure DevOps, Azure File Sync, Azure Storage Resource Provider, Build Tools for Visual Studio, Microsoft Brokering File System, Microsoft Dataverse, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Edge, Microsoft Office, Microsoft Office Excel, Microsoft Office Outlook, Microsoft Office PowerPoint, Microsoft Office SharePoint, Microsoft PC Manager, Microsoft Power Apps, Microsoft Scripting Engine, Remote Desktop Gateway Service, Universal Print Management Service, UrlMon, Visual Studio, Visual Studio Code, Web Threat Defense, Windows Ancillary Function Driver for WinSock, Windows Common Log File System Driver, Windows Deployment Services, Windows Drivers, Windows DWM, Windows File Server, Windows Fundamentals, Windows Hardware Lab Kit, Windows Hyper-V, Windows Installer, Windows Kernel, Windows LDAP, Windows Media, Windows NTFS, Windows Remote Desktop, Windows Routing and Remote Access Service, Windows Secure Kernel Mode, Windows SMB, Windows Trusted Runtime Interface Driver, Windows Virtual Machine Bus, Windows Win32K – GRFX, and MSRT. This includes security updates. A reboot is required.

Oracle released 378 security updates this quarter to address vulnerabilities in 117 products.

Apple released updates for macOS Sequoia 15.4.1, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, Safari 18.5, iOS 18.4.1, iOS 18.5, iPadOS 17.7.7, iPadOS 18.4.1, iPadOS 18.5, tvOS 18.4.1, tvOS 18.5, visionOS 2.4.1, visionOS 2.5, and watchOS 11.5. This includes security updates. Use Apple Software Update to install the most current versions.

iOS 18.4.1 and 18.5 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 17.7.7, 18.4.1 and 18.5 are security updates. Use Settings, General, Software Update to install the most current update.

watchOS 11.5 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 18.4.1 and 18.5 are security updates. Use System, Software Update to install the most current version.

visionOS 2.4.1 and 2.5 are security updates. Use System, Software Update to install the most current version.

Google ChromeOS 134.0.6998.198, ChromeOS 135.0.7049.120, and ChromeOS LTS 132.0.6834.223 are security updates. Use Menu, Help, About to install the most current version. A reboot is required.

Fedora 42.0 is a major update (leaning hard into “42”), with changes to the installer, updates to libraries, defaults and now offering COSMIC. This is not a security update.
https://getfedora.org/en/workstation/download/

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sequoia (15.x) means that macOS Monterey (12.x) and older are no longer supported. If you can not install at least macOS Ventura (13) on your Mac then you should immediately remove your device from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v24H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it. If not, switch to Linux (Mint is nice) or replace your computer.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with a SaferPC Subscription and we will install updates each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 25.5.1 adds support for newer hardware, improves performance and resolves several bugs. This is not a security update.
https://www.amd.com/en/support

Crucial Storage Executive 11.03 doesn’t provide a change log so should be treated as a security update.
https://www.crucial.com/support/storage-executive

Daemon Tools Lite 12.3.0 resolves several bugs. This is not a security update.
https://www.daemon-tools.cc/products/dtLite

GoXLR Utility 1.2.2 resolves several bugs. This is not a security update.
https://github.com/GoXLR-on-Linux/goxlr-utility/

Intel Driver and Support Assistant 25.2.15.9 is a security update.
https://www.intel.com/p/en_US/support/detect

UniFi Network Server 9.1.120 is a security update.
https://www.ui.com/download/releases/network-server

VIISAN OfficeCam 7.2.8.1 doesn’t provide a change log so should be treated as a security update.
https://www.viisan.com/en/download/type1.html

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.78.97 is a security update.
https://brave.com/

Google Chrome 136.0.7103.92 is a security update.
https://www.google.com/chrome/

Firefox 138.0.3 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 128.10.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Vivaldi 7.3.3635.12 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

OutlookAttachView 3.54 adds black background support. This is not a security update.
https://www.nirsoft.net/utils/outlook_attachment.html

Spark 3.22.9.106186 improves Team support and resolves a couple bugs. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.22.9.106183 improves Team support and resolves a couple bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 138.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 9.5.4 resolves several bugs. This should be treated as a security update.
https://anydesk.com/en/downloads

AnyDesk (macOS) 9.0.2 resolves several bugs. This should be treated as a security update.
https://anydesk.com/en/downloads

Discord May 1, 2025 resolves dozens of bugs. This is not a security update.
https://discord.com/download

Dropbox 223.4.4909 resolves several bugs. This is not a security update.
https://www.dropbox.com/

FileZilla Client 3.69.1 resolves several bugs. This is not a security update.
https://filezilla-project.org/

FileZilla Server 1.10.3 resolves several bugs. This is not a security update.
https://filezilla-project.org/

Google Drive 108.0 doesn’t provide a detailed change log so should be treated as a security update.
https://drive.google.com/start

MeshCentral 1.1.44 resolves dozens of bugs. This is not a security update.
https://meshcentral.com/info/downloads.html

Microsoft Teams 1.8.00.9760 improves GUI and resolves several bugs. This is not a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 31.0.4 resolves dozens of bugs. This should be treated as a security update.
https://nextcloud.com/

Nmap 7.97 is a security update.
https://nmap.org/

Npcap 1.82 resolves several bugs. This is not a security update.
https://nmap.org/npcap/

Pocketnet-Core 0.22.17 resolves several bugs. This is not a security update.
https://pocketnet.app/

Pocketnet-GUI 0.9.119 resolves several bugs. This is not a security update.
https://pocketnet.app/

Rclone 1.69.2 is a security update.
https://rclone.org/

Signal 7.53.0 adds new device attachment transfer and resolves several bugs. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.41.3 doesn’t provide a detailed change log so should be treated as a security update.
https://signal.org/android/apk/

Syncthing 1.29.6 resolves several bugs. This is not a security update.
https://syncthing.net/

Technitium DNS Server 13.6 resolves several bugs. This is not a security update.
https://technitium.com/dns/

Telegram 5.14.2 resolves a compatibility bug and adds marketplace sales. This is not a security update.
https://telegram.org/

WinSCP 6.5.1 resolves several bugs. This is not a security update.
https://winscp.net/eng/index.php

Zoom 6.4.6.64360 resolves several bugs. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.17 resolves several bugs. This is not a security update.
https://en.3tene.com/

Bitwig Studio 5.3.8 resolves a series of crash bugs. This is not a security update.
https://www.bitwig.com/download/

Grayjay 306 adds remote sync and resolves several bugs. This is not a security update.
https://grayjay.app/index.html

Plex Media Server 1.41.6.9685 adds DOVI filter and resolves several bugs. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.80.3 should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

Nintendo Switch 20.0.1 improves stability. This is not a security update.
https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/system%20updates/p/989

PS5 2025.429 adds audio focus and new themes. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2025.05.10 resolves several bugs. This is not a security update.
https://store.steampowered.com/news/app/593110

SteamOS SteamDeck Update 2025.05.06 improves compatibility, resolves several bugs, and updates libraries. This is not a security update.
https://store.steampowered.com/news/app/1675200/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Animate 23.0.12 and 24.0.9 are security updates.
https://helpx.adobe.com/security/products/animate/apsb25-42.html

Adobe Bridge 14.1.7 and 15.0.4 are security updates.
https://helpx.adobe.com/security/products/bridge/apsb25-44.html

Adobe ColdFusion 2021.20, 2023.14, and 2025.2 are security updates.
https://helpx.adobe.com/security/products/coldfusion/apsb25-52.html

Adobe Connect 12.9 is a security update.
https://helpx.adobe.com/security/products/connect/apsb25-36.html

Adobe Dimension 4.1.2 is a security update.
https://helpx.adobe.com/security/products/dimension/apsb25-45.html

Adobe Dreamweaver 21.5 is a security update.
https://helpx.adobe.com/security/products/dreamweaver/apsb25-35.html

Adobe Illustrator 28.7.6 and 29.4 are security updates.
https://helpx.adobe.com/security/products/illustrator/apsb25-43.html

Adobe InDesign 19.5.3 and 20.3 are security updates.
https://helpx.adobe.com/security/products/indesign/apsb25-37.html

Adobe Lightroom 8.3 is a security update.
https://helpx.adobe.com/security/products/lightroom/apsb25-29.html

Adobe Photoshop 25.12.3 and 26.6 are security updates.
https://helpx.adobe.com/security/products/photoshop/apsb25-40.html

Adobe Reader DC 25.001.20467 resolves several bugs. This is not a security update.
https://get.adobe.com/reader

Adobe Substance 3D Modeler 1.22.0 is a security update.
https://helpx.adobe.com/security/products/substance3d-modeler/apsb25-51.html

Adobe Substance 3D Painter 11.0.1 is a security update.
https://helpx.adobe.com/security/products/substance3d_painter/apsb25-38.html

Adobe Substance 3D Stager 3.1.2 is a security update.
https://helpx.adobe.com/security/products/substance3d_stager/apsb25-46.html

Artweaver 8.0.4 resolves several bugs. This is not a security update.
https://www.artweaver.de/

Calibre 8.4.0 resolves several bugs and improves compatibility. This is not a security update.
https://calibre-ebook.com/

Ghostscript 10.05.1 is a security update.
https://www.ghostscript.com/releases/gsdnld.html

Inkscape 1.4.2 resolves dozens of bugs. This is not a security update.
https://inkscape.org/release/

LibreOffice 24.8.7 resolves over a dozen bugs. This is not a security update.
https://www.libreoffice.org/

LibreOffice Fresh 25.2.3 resolves over sixty bugs. This is not a security update.
https://www.libreoffice.org/

Manager 25.5.8.2317 does not provide a detailed change log so should be treated as a security update.
https://www.manager.io/

Nextcloud Desktop 3.16.4 resolves several bugs. This is not a security update.
https://nextcloud.com/

Notepad++ 8.8.1 resolves over a dozen bugs and improves colorization. This is not a security update.
https://notepad-plus-plus.org/

PDF-XChange Editor 10.6.0.396 is a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

Scribus 1.6.4 resolves several bugs. This is not a security update.
https://www.scribus.net/

Operating System Updates

These are for specific Linux flavors and alternative operating systems and, sadly, are unlikely to be of interest to most people.

ChromeOS 134.0.6998.198 and ChromeOS 135.0.7049.120 are security updates.

Fedora 42.0 is a major update (leaning hard into “42”), with changes to the installer, updates to libraries, defaults and now offering COSMIC. This is not a security update.
https://getfedora.org/en/workstation/download/

iOS 18.4.1 and 18.5 are security updates.
https://support.apple.com/kb/HT204204

iPadOS 17.7.7, iPadOS 18.4.1, and iPadOS 18.5 are security updates.
https://support.apple.com/kb/HT204204

macOS Sequoia 15.4.1, macOS Sequoia 15.5, macOS Sonoma 14.7.6, and macOS Ventura 13.7.6 are security updates.
https://support.apple.com/kb/HT201541

Tails 6.14.2 and Tails 6.15 are security updates.
https://tails.net/install/download/index.en.html

tvOS 18.4.1 and tvOS 18.5 are security updates.
https://support.apple.com/kb/HT202716

visionOS 2.4.1 and visionOS 2.5 are security updates.
https://support.apple.com/en-us/122721

watchOS 11.5 is a security update.
https://support.apple.com/en-us/122722

Security Software Updates

One or more of these is likely to be of interest to most people.

FRSTx64 2025.5.9 doesn’t provide a detailed change log so should be treated as a security update.
https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/

HTTP Toolkit 1.20.1 doesn’t provide a detailed change log so should be treated as a security update.
https://httptoolkit.tech/

JShelter 0.20.2 improves privacy and resolves several bugs. This is not a security update.
https://jshelter.org/install/

MalwareBytes Desktop Security 5.3.0.186 resolves several bugs. This is not a security update.
https://www.malwarebytes.org/antimalware/

OpenSSL 3.5.0 is a security update.
https://slproweb.com/products/Win32OpenSSL.html

PassRec 3.65 updates included apps. This is not a security update.
https://www.nirsoft.net/password_recovery_tools.html

RogueKiller 16.1.3 resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

Stinger 13.0.0.347 adds and improves detections. This should be treated as a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

uBlock Origin 1.64.0 resolves a couple bugs and adds several new scriptlets and controls. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

WebBrowserPassView 2.15 adds support for app-bound encryption in recent Chrome releases. This is not a security update.
https://www.nirsoft.net/utils/web_browser_password.html

Capture Updates

These are unlikely to be of interest to most people.

Camtasia 25.1.1 resolves a startup crash. This is not a security update.
https://www.techsmith.com/video-editor.html

SnagIt 25.1.1 resolves several bugs and improves compatibility. This is not a security update.
https://www.techsmith.com/screen-capture.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.4.0 adds support for newer encodings and adds an AI upscaler. This is not a security update.
https://www.dvdfab.cn/download.htm

IsoBuster 5.6 adds support for new media formats, a new Preview mode, and resolves several bugs. This is not a security update.
https://www.isobuster.com/download.php

PDF Creator 6.0.0 is a major update, switching to newer libraries, adds document previews, SharePoint integration, and resolves a couple bugs. This is not a security update.
https://www.pdfforge.org/pdfcreator

StreamFab 6.2.3.5 improves compatibility, adds support to download from several new sources, and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 3.0.1.6 adds SDR and new output formats, resolves several bugs and improves subtitle and Face Enhancer. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.10.76 resolves a couple bugs and improves error messages.
https://1password.com/downloads/

Agent Ransack 2022.3517 improves favorites list, cosmetics and resolves several bugs. This is not a security update.
https://www.mythicsoft.com/agentransack/download/

Beyond Compare 5.0.7.30840 improves cosmetics, updates libraries, and resolves several bugs. This is not a security update.
https://www.scootersoftware.com/download

Bitwarden 2025.4.2 resolves several bugs. This is not a security update.
https://bitwarden.com/

CalyxOS Device Flasher 1.1.1 is a security upate.
https://calyxos.org/install/

CrucialScan 20250424 doesn’t provide a change log so should be treated as a security update.
https://www.crucial.com/store/systemscanner

Cygwin 3.6.1 resolves several bugs. This is not a security update.
https://cygwin.com/

DesktopOK 11.81 improves cosmetics. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.5.8.0 updates libraries. This is a security update.
https://dngrep.github.io/

Etcher 2.1.2 removes analytics. This is not a security update.
https://www.balena.io/etcher/

FileLocator Pro 2022.3517 improves favorites list, cosmetics and resolves several bugs. This is not a security update.
https://www.mythicsoft.com/filelocatorpro/download

FoneTool 3.0.0 is a major update that adds a new “My Devices” interface, improves iPhone to PC interface, and resolves a couple bugs. This is not a security update.
https://www.fonetool.com/download.html

Free Virtual Serial Ports 6.22.00.1498 resolves several bugs. This is not a security update.
https://freevirtualserialports.com/

GoodSync 12.8.8 improves compatibility and resolves several bugs. This is not a security update.
https://www.goodsync.com/

HWiNFO 8.26 improves hardware detection and reporting. This is not a security update.
https://www.hwinfo.com/download/

HWMonitor 1.57 adds support for newer hardware and resolves a couple bugs. This is not a security update.
https://www.cpuid.com/softwares/hwmonitor.html

Kingston SSD Manager 1.5.5.3 doesn’t provide a change log so should be treated as a security update.
https://www.kingston.com/us/support/technical/ssdmanager

NTLite 2025.04.10406 adds Power Plan integration support, improves registry writes, updates components and resolves a bug. This is not a security update.
https://www.ntlite.com/download/

OSForensics 11.1.1007 improves performance and resolves a couple bugs. This is not a security update.
https://www.osforensics.com/download.html

osquery 5.17.0 resolves over a dozen bugs and updates libraries. This is not a security update.
https://osquery.io/downloads

Password Security Scanner 1.63 adds support for app-bound passwords in recent Chrome releases. This is not a security update.
https://www.nirsoft.net/utils/password_security_scanner.html

PowerToys 0.90.1 resolves several bugs and updates libraries. This is a security update.
https://github.com/microsoft/PowerToys/releases/latest

RoboForm 9.6.8 improves update process and adds support for Google Workspace SSO. This is not a security update.
https://www.roboform.com/

Rufus 4.7 resolves several bugs and improves UEFI detection and download. This should be treated as a security update.
https://rufus.ie/en_US/

ScreenConnect 25.2.4.9229 is a security update. Updates were released for other “recent” versions as well so you’re not forced to upgrade to the Canary version that breaks several other features.
https://screenconnect.connectwise.com/download

SimpleWMIView 1.56 adds Black Background support. This is not a security update.
https://www.nirsoft.net/utils/simple_wmi_view.html

SmartMonTools 7.5 adds dozens of new diagnostic objects and reporting elements and improves reliability and performance. This is not a security update.
https://smartmontools.org/

Starwind V2V Converter 9.755 adds CLI conversion support. This is not a security update.
https://www.starwindsoftware.com/starwind-v2v-converter

SysinternalsSuite 2025.5.5 updates RDCMan. This is a security update.
https://docs.microsoft.com/en-us/sysinternals/

TeamViewer 15.65.6 resolves a bug. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/

WinGet 1.10.390 improves end-to-end support for Entra ID, configuration file controls, and resolves several bugs. This is a security update.
https://github.com/microsoft/winget-cli/releases/latest

WinScan2PDF 9.33 improves hardware support and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

XnConvert 1.105.0 doesn’t provide a change log so should be treated as a security update.
https://www.xnview.com/en/xnconvert/

ZoomText 2025 2025.2504.25.400 improves performance, multi-monitor support, and resolves several bugs.
https://support.freedomscientific.com/Downloads/ZoomText

Developer Updates

These are unlikely to be of interest to most people.

.NET Runtime 9.0.4 is a security update.
https://dotnet.microsoft.com/en-us/download/dotnet

ADB 36.0.0 resolves several bugs. This is not a security update.
https://developer.android.com/studio/releases/platform-tools

Android Studio 2024.3.2.14 resolves several bugs. This is not a security update.
https://developer.android.com/studio

cx_Freeze 8.3 updates libraries. This is not a security update.
https://cx-freeze.readthedocs.io/en/latest/index.html

GameMaker Studio 2024.13.1.193 resolves several bugs. This is not a security update.
https://www.yoyogames.com/en/gamemaker

GDevelop 5.5.230 resolves several bugs. This is not a security update.
https://gdevelop.io/download

GitHub Desktop 3.4.19 resolves over a dozen bugs. This is not a security update.
https://desktop.github.com/

Go 1.24.3 is a security update.
https://go.dev/

Inno Setup 6.4.3 improves restore operations, resolves seeral bugs, and adds a new tool for ECDSA P-256 support. This is not a security update.
https://www.jrsoftware.org/isdl.php

Java 8u451 is a security update.
https://www.java.com/en/download/manual.jsp

Node.js 20.19.1 updates libraries. This is not a security update.
https://nodejs.org/en/

Node.js 22.15.0 updates libraries and resolves several bugs. This is a security update.
https://nodejs.org/en/

Rustup 1.28.2 improves download stack and management controls. This is not a security update.
https://www.rust-lang.org/

SQLite 3.49.2 resolves several bugs. This should be treated as a security update.
https://www.sqlite.org/download.html

Visual Studio Code 1.100.1 is a security update.
https://code.visualstudio.com/

WinMerge 2.16.48.2 resolves several bugs. This is not a security update.
https://winmerge.org/

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 7.1.8 resolves over a dozen bugs. This is not a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

Adminer 5.3.0 resolves over a dozen bugs and improves compatibility. This is not a security update.
https://www.adminer.org/en/

Joomla 5.3.0 improves email templates, media management, scheduled tasks, read more, accessibility and compatibility. This is not a security update.
https://www.joomla.org/

YOURLS 1.10.1 resolves several bugs. This is not a security update.
https://yourls.org/

WordPress 6.8.1 resolves over a dozen bugs. This is not a security update.
https://wordpress.org/

bbPress 2.6.13 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/bbpress/

Contact Form 7 6.0.6 is a security update.
https://wordpress.org/extend/plugins/contact-form-7/

My Sticky Bar 2.8.1 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/mystickymenu/

Show IDs 1.1.11 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/wpsite-show-ids/

Sucuri Security 2.1 resolves a couple bugs and adds support for several new scanners. This is not a security update.
https://wordpress.org/extend/plugins/sucuri-scanner/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

 

Updates 2024-11-12

Happy Thanksgiving, Folks!

Today is Patch Tuesday for November, 2024.

Hold the line: do not upgrade to 24H2 yet. There have been quite a few issues. Let everyone else be the guinea pigs.

Windows 10 now has only 11 months of support left. If your computer can not be upgraded to Windows 11 either start planning for a switch to Linux or replacing your computer.

There are critical security updates for all supported Apple products and (as is now the norm) new critical security updates for every browser every single week.

QuickBooks Desktop 2025 will be released later this month, and on November 1st all previous versions of QuickBooks Desktop will be end-of-life (EOL).

Windows Server 2025 has been released. And it’s “accidentally” being force-installed on recent Windows Server builds.

Entrust certificates are being disavowed as soon as today. There have been months to prepare, but this will still kill off about 0.1% of active SSL certificates.

There were 645+ major hacks and over 525 application updates this month.
It’s a huge month, with about 5 GB of updates for most users.

This Month in Technology

1st Credentialing, 1StopBedrooms, 1stUnited Credit Union, 20 Canadian government networks, 5.11, Abbott Laboratories Employees Credit Union, Absolute Machine Tools, Acadian Ambulance Service, Inc, Accounting Resource Group, Acko.ru, Action Heating & Cooling, Adguard Home, ADT, Advanced Accounting & Business Advisory, Advanced Recovery Equipment & Supplies, AeoTec Smart Home Hub, AEP, Air Specialists Heating & Air Conditioning, Al Ahly SC, Al Fajer School, Alliance Laundry Systems, AlpineReplay, Altenen, Amazon, Ambica Steels, American Mechanical, Inc, American Medical Billing, American River College, American Water, Amourgis & Associates, Android, ANU Enterprise, Apache Mills, Inc, Apache Solr, Apex, Apple iPhone, Apple macOS, Arango Billboard, Arctrade, Arkansas Blue Cross and Blue Shield, Asheville Arthritis Centre, Aspen Healthcare, Astac, Atlantic Coast Consulting Inc, Atlantic Medical Management, ATSG Inc, AudoCAD, Australian Nursing Home Foundation, Aviva Spain, Axis Health System, Ayurvedic Herbs Online, Azure AI, Bahrain government, Banco Sucredito Regional, Barnes Cohen and Sullivan, Bel-Air Bay Club Ltd, Belle Tire, Berling.gr, Berridge Manufacturing Co, Bethalto School District, Birth Choice of San Marcos, Blackburn College, Bliss Worldwide, BNBuilders, Boart Longyear, Boston Children’s Health Physicians, Brandenburger Plumbing, Brazil’s SAIC, BrightStar Care, BSN Sports, Bucharest’s District 5 City Hall, Buenos Aires, Burgess Kilpatrick, Bury Council, UK, BWD Technology, By Design LLC, Byerly Aviation, C & C Industries, Caleb & Brown, Calgary Public Library, California Department of Social Services, Call of Duty, Campus.gov.il, Canon imageCLASS MF656Cdw, Cape Cod Regional Technical High School, Cardiology of Virginia, Carolina Arthritis, CAS Software, Casio, Cathexis Holdings LP, Center for Urban Community Services, Central Pennsylvania Food Bank, Central Tickets, Centreon, CGR Technologies, Cheasapeake Regional Information System for our Patients, Inc, Chicago Cardiology Institute, Children’s Health Ireland, Chimienti & Associates, CIIT Wah, Cisco DevHub, City of Sheboygan, CLAS Information Services, Clay Platte Family Medicine, Clayton Properties Group, Clear Connection, ClickFix, Club Vélez Sarsfield, College of Business – Tanzania, Columbus, OH, Comcast, Community Day School, Community Dental in Portland, Compex Legal Services Inc, Compound, Continental Casualty Company, CoPilot, Cordogan Clark and Associates, Cornerstone Healthcare Group Management Services LLC, Corporate Job Bank, Costa Del Sol Hotels, Cottonwood Union School District, Country Club El Bosque, Country Inn & Suites by Radisson, CreaGen Inc, CreditRiskMonitor, Crypto Vеnturе Cаpitаl, CSU Contracting, Cucamonga Valley Water District, CUSO Financial Services, LP, CyberPanel, D-Link routers, Dana Safety Supply, De Rose Lawyers, Delfin Design & Manufacturing, Delta Electronics CNCSoft-G2, Delta Electronics DIAScreen, Delta Electronics InfraSuite, Dennis Kirk, Department of Occupational Safety and Health (Malaysia), Detroit Wayne Integrated Health Network, Devtron, DieTech North America, Dietzgen Corporation, digiDirect, Diligent Delivery Systems, Directorate for Combating Organised Crime, Disney World, DMEScripts, Doctors Regional Cancer Center, DoctorsToYou, DocuSign, Dohman, Akerlund & Eddy, Dome Construction, Doscast, DR Butler and Associates, Dr.Web, Drug and Alcohol Treatment Service, Dstat.cc, Dudley Council, UK, Eagle Industries, Eagle Recovery Associates, Earth 2, Easterseals, EasyPay, Ecovacs, EIGEN Holdings, Elections Nova Scotia, Embody Performance & Recovery, Empower Management Group, English Construction Company, Epicor Software Corporation, Equalize, Equator Worldwide, Ericsson codechecker, ESET, European External Action Service, Evergreen Public Schools, Exeter City Council, Eye Clinic Surgicenter, Fair Vote Canada, Fairfield Memorial Hospital, Falo, Family Medical Center in Mount Airy, Federal Board of Revenue (Pakistan), Fidelity Investments, Firefox, First Nations Health Authority, Fiskars, Fitzgerald, DePietro & Wojnas, FloridaCentral, Floyd County Public Schools, Followmont TransportPty, Food Sciences Corporation, Form I-9 Compliance, Fortinet FortiManager, Fortis, Fractal ID, France’s Ministry of Labour and Employment, Free (ISP), Freedom Home Care, Fromm, Funadmin, Funlab, Fylde Coast Academy Trust, Game Freak, Gandara Mental Health Center, General Physician, PC, German Chamber of Commerce, GitLab, Globe Life, Gluckstein Personal Injury Lawyers, Google Scholar, Goshen Central School District, Grafana, Granite School District, Gryphon Healthcare, GSR Andrade Architects, Guardian Healthcare, H&R Block Canada, Hafetz and Associates, Harris Personal Injury, Hawaii State Judiciary, Health & Palliative Services of the Treasure Coast, Healthcare Management Systems, Healthfund Solutions, Hemel Hempstead Council, UK, Henry County Schools, Henry Schein, Hewlett Packard Enterprise Aruba OS, Holistix Treatment Center, Hope Valley Recovery, Hot Topic, Housing Authority of the City of Los Angeles, Houston Housing Authority, Howell Electric Inc, HP Color LaserJet Pro MFP 3301fdw, Hyundai, IBM Security Verify, Icedrive, IdeaLab, iFocus Consulting, Illumin8 Global, IM Cannabis, Immuno Laboratories, IMPAXX, InCare Technologies, Indian government email, India’s COVID-19 tracking platform, Indonesia’s E-Visa System, Infosys McCamish Systems LLC, Inner City Education Foundation, Insurance Regulatory and Development Authority of India (IRDAI), Interbank, Interbel, International University of Sarajevo, Internet Archive (three times!), Intesa Sanpaolo Bank of Italy, IrfanView, Iron World Manufacturing, Israeli Ministry of National Security, Israeli Ministry of Welfare, Ivanhoe Club, Ivanti Cloud Services Appliance (CSA), Jacksonville Children’s Multispecialty Clinics, Jardine Aviation Services, Jillamy, Johnson & Johnson, Jomar Electrical Contractors, Jordan Ministry of Education, Jordan Public Schools, JS McCarthy Printers, Justice.fr, K&S Tool & Mfg Co, Kaiser Foundation Hospitals, Kaiser Permanente, Kansas City Hospice, Karman Inc, KEE Process, Kenana Sugar Company, KMC Controls, Knox Law Center, Konecta Group, Kubernetes Image Builder, Kuhn and Associates, Kulicke and Soffa Industries, L & B Transport, LLC, La Tazza D’oro, Lampard Community School, Landmark Admin, Laravel Reverb, Law Office of Omar O Vargas, Legacy Treatment Services, Lein Law Offices, Levales Solicitors LLP, LevelOne WBR-6012, Lexco, Lexmark CX331adwe, LG Electronics, LifeMine, Lincoln University, Linux Kernel, Long Island Plastic Surgical Group, Lorex cameras, Loring, Wolcott & Coolidge, LottieFiles Lotti-Player, Luxwood Software Tools, Magento Open Source, Mainelli Mechanical Contractors, Marisa SA, Maval Industries, Maxxis International, Mazda Connect Connectivity Master Unit (CMU), McElroy, Quirk & Burch, APC, McMillan Electric Company, MCNA Dental, MedElite Group, Memorial Hospital and Manor, GA, Mercury Theatre, Meshworks, Metawin, MiCare Health Center, Michael J Gurfinkel, Microlise, Microsoft Bookings, Microsoft SharePoint, Mid State Electric, Middlesborough Council, UK, Minuteman Senior Services (MSS), MiPC Mexico, MIT Technology Review, Mixfame, Mizuno USA, MMI Services, Inc, MMP Union, Model Die & Mold, Moldova’s parliamentary email servers, MoneyGram, Moodle, Mozilla Firefox, Mr. Winter Wheels, Muah.AI, Muskogee City County Enhanced 911 Trust Authority, MVES, MWI Veterinary Supply, Inc, MySQL Connector/Python, Mystic Valley Elder Services, Nagoya Stock Exchange, NARSTCO, National Financial Services, National Institute of Administration, Native Village of Eyak Ilanka Community Health Center, Navarra & Marzano, Neighbors Credit Union, New Law, New York Plastic Surgery, Newpark Resources, Nidec Precision, Niko Resources Ltd, Nikon NEF, NoBroker, Noida Metro, Nokia, Nor-Well, Northeast Professional Caregivers, Northeast Spine and Sports Medicine, NVIDIA Container Toolkit, NVIDIA GeForce, NVIDIA Onyx, NW Health Porter, Okta, Ollama AI, OMA, Omni, OnePoint Patient Care, Open Range Field Services, Opera Browser, Oracle VirtualBox, ORBCOMM, Orbit Software, Inc, Oregon Department of Corrections, ORM Fertility, Orthopedics Rhode Island, OrthopedicsNY, Osmedeus Web Server, Ottawa Valley Handrailing Company, Over a thousand online shops, OwlTing, OxyHealth, OzarksGo, Pacific Pulmonary Medical Group, PAJ GPS, Palm Hills Developments, Palmisano & Goodman, PA, Palo Alto Networks PAN-OS, Panda Security Dome, Paragon Plastics, Parkland Health, Parnell Defense, Paul White Company, PayDo, Paystack, pCloud, Peoria Lawyers, Petropolis Pet Resort, Pheim Unit Trusts Berhad, Philadelphia Macaroni, Philips Smart Lighting, Phoenix Contact EV chargers, Physical Medicine & Rehabilitation Center, Planned Parenthood of Montana, PlayBoy, Portsmouth City Council, UK, Positive Business Solutions, Postcard Mania, PostHog, Potomac Medical Aesthetics, PRC-Saltillo, Precision Steel Services, Preferred Travel Group, Presbyterian Healthcare Services, PrestaShop, PriceBlink, Professional Probation Services, Promise Technology, Inc, Protective Industrial Products, PT Haleyora Power, PTZOptics cameras, Pureflow Airdog, qBittorrent, QEMU, QNAP QHora-322, QNAP TS-464, QNQB, Qualcomm chips, Quest Diagnostics Inc, Racing Forensics Inc, Radiant Capital, Radisson’s Country Inn and Suites, Raeyco Lab Equipment, Raimondo Pettit Group, Rancher, RANEPA University, RDC Control Ltd, Redwood Coast Regional Center, Regional Government of Ica, ReliaQuest, RENIEC, Rhode Island Orthopedic Practice, Ridgewood Public School District, Rim Country Health and Rehabilitation, Riverview Health, Rockstar Games, Rockwool, Rocky Mountain Gastroenterology, Rosen Legal, Roundcube Webmail, Royal Thai Police, RRCA Accounts Management, Inc, Rumpke Consolidated Companies, Russell Law Firm, LLC, Russian Foreign Ministry, Russian State TV VGTRK, S & W Kitchens, Sage Automotive Interior, Saint Xavier University, SalesGig, Salford Council, UK, Samsung, Samsung Galaxy S24, San Joaquin County Superior Court, Sanglier Limited, Sango Family Dentistry, Sarah Bush Lincoln Fayette County Hospital, Saratoga Liquor, Save Mart Supermarkets, LLC, Schneider Electric, Schneider Electric EcoStruxure, Schneider Electric Zelio Soft 2, Schreck Financial Group, Schweiger Transport, Scullion LAW, Seafile, Sector 5, Bucharest, SelectBlinds, SEP, Set Forth, Inc, Seven Counties Services, Shareholders in Hong Kong, Sit & Sleep, Smart Media Group Bulgaria, SmartSource, Smeg, Smile Design Management, Smiles in the Pines, Smitty’s Supply, Smoker’s Choice, Solairus Aviation, LLC, SolarWinds Web Help Desk, Soliant Health, SonicWall firewalls, Sonoma County Superior Court, Sonos Era 300, Sophos Firewall, South China Athletic Association, South West Family Medicine Associates, South-East Technological University Waterford, Spine by Villamil MD, Spirit Lake Community School District, SRS-Stahl GmbH, St Albans Council, UK, St. Anthony Regional Hospital, Stalker Online, Standard Bank, Star Health Insurance, Stark County Criminal Justice Information Systems, Starkweather and Shepley Insurance Brokerage, Steel Art Signs, Strava, StreamCraft, Strike Bowling, Structural and Steel Products, Sumitomo, Summit Pathology and Summit Pathology Laboratories, Inc, Sunrise Express, Suntrust Properties, Superior Quality Insurance Agency, Supply Technologies, Surfnet Communications, Survival Flight, Inc, SVP Worldwide, Swalekha.in, Switch, Symetra Life Insurance Company, Symfony, Sync, Synology BeeStation, Synology DiskStation, Synology TC500, Systems Application & Technologies Inc, T-Space, Tameside Council, UK, TargetMaps, TaxPros of Clermont, TDM Technical Services, TEAM Software, Texas Department of Public Safety, Texas Spine Consultants, Texas Tech University Health Sciences Center, The Club Penguin Experience, The Getz Group, The Knesset, The Law Offices of Jed Silverman, The Nolan Financial Group, The Physical Medicine & Rehabilitation Center, PA, The Povman Law Firm, The Strainrite Companies, Therabel Lucien Pharma SAS, TheraCom, ThinkPHP, Thompson Coburn, Tiketek, TNAFlix, Toro Enterprises, Inc, Totally Promotional, Tower Clock Eye Center, TrackMan, Trafford Council, UK, Transak, Trend Micro Cloud Edge, Trend Micro Deep Security, Tresorit, Tri-City Healthcare District, Tri-City Medical Center, Tricon Energy, Trimarc Financial, Trimble SketchUp, True World Group, TrueNAS Mini X, TrueNAS X, Truist Bank, TU Parks, Tungsten Automation Power PDF, TV Guide Magazine, Ubiquiti AI Bullet, UK Ambulance Services, UK Biobank, Ultra Tune, United Sleep Diagnostics, Universal Companies, Universal Health Corporation, Universal Music Group, University Medical Center, University of California, Unlimited Lawn Care, US Customs and Border Protection, Uttarakhand State Data Center, Valleygate Dental Surgery Centers, Value City NJ, Van Wagner Group, LLC, Varsity Brands, VasTopUp, Venezuelan Government, VeriSource Services, Inc, Verizon Wireless, Vermilion Parish Schools, VimeWorld, Visionworks of America, Inc, VMware HCX, VMware vCenter Server, Volkswagen, Volta River Authority, Wacom Center, Washington courts, Wayne County, Webb Institute, Weber Packaging, Weiser Memorial Hospital, Well Chip Group, Wellfleet Group, Wells Fargo, Western Sydney University, Westwood Country Club, Wetherby Town Council, Wexford County, WhatsUp Gold, Whitaker Construction Group, Wichita County, Wilson & Lafleur, Wilson Tarquin, WimCoCorp, Windows Driver Signature, Windows Themes, Winestyle, Winnebago Public School Foundation, WordPress Jetpack, WordPress LiteSpeed Cache, X.Org Server, Youngs Timber Builders Merchants, Z-lib, Zalo.vn, Zamalek Club, Zendesk, ZicroDATA, Zierick Manufacturing Corporation, and Zimbra GraphQL have reported hacking or compromises this month.

Calgary Public Library, DHL, Microsoft, Serco, and The Internet Archive have suffered from outages this month.

Last months updates broke Microsoft 365 Outlook, Microsoft Azure Virtual Desktop, Microsoft OneDrive, Microsoft’s “New” Outlook, OpenSSH on Windows Server, Windows 10, and Windows Remote Desktop.

Never again use a third-party charging cord. Treat your USB ports with more concern.

Half of US county websites can be spoofed.

iPhones will now force restart after idle in order to reencrypt data.

Now for the good news:

The Mozilla Foundation has finally dropped their advocacy division. Unfortunately, they’ll be rolling it into their other programs. It still could mean that tech companies might actually start prioritizing their tech instead of politics or other agendas.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is huge this month. The typical computer should see roughly 5 GB in updates today. Let’s get started.

Microsoft released 98 updates to address 88 vulnerabilities in .NET and Visual Studio, airlift.microsoft.com, Azure CycleCloud, Azure Database for PostgreSQL, LightGBM, Microsoft Defender for Endpoint, Microsoft Edge, Microsoft Office SharePoint, Microsoft PC Manager, Microsoft SharePoint Server, Microsoft SQL Server, Microsoft Virtual Hard Disk (VHDX), Microsoft Virtual Hard Drive, Microsoft Windows DNS, Microsoft Windows VMSwitch, TorchGeo, Visual Studio, Visual Studio Code, Win32k Elevation of Privilege Vulnerability, Windows Active Directory Certificate Services, Windows CSC Service, Windows Defender Application Control, Windows DNS, Windows DWM Core Library, Windows Hyper-V, Windows Kerberos, Windows Kernel, Windows NT OS Kernel, Windows NTLM, Windows Package Library Manager, Windows Registry, Windows Secure Kernel Mode, Windows SMB, Windows SMBv3 Client/Server, Windows Telephony Service, Windows Update Stack, Windows USB Video Driver, Windows VMSwitch, Windows Win32 Kernel Subsystem, Winlogon, and MSRT. This includes security updates. A reboot is required.

Oracle released 334 security updates this quarter to address vulnerabilities in 109 applications and service.

Apple released updates for iOS 17.7.1, iOS 18.1, iPadOS 17.7.1, iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, Safari 18.1, tvOS 18.1, visionOS 2.1, and watchOS 11.1. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

iOS 17.7.1 and 18.1 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 17.7.1 and 18.1 are security updates. Use Settings, General, Software Update to install the most current update.

watchOS 11.1 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 18.1 is a security update. Use System, Software Update to install the most current version.

visionOS 2.1 are security updates. Use System, Software Update to install the most current version.

Google Chrome OS 130.0.6723.101 and Google Chrome OS LTS 126.0.6478.257 are security updates. Use Menu, Help, About to install the most current version. A reboot is required.

Fedora 41-1.4 is a major update, adding many new features, removing unsupported and deprecated tools and applications, and hardening the operating system. This should be treated as a security update.
https://getfedora.org/en/workstation/download/

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sequoia (15.x) means that macOS Monterey (12.x) and older are no longer supported. If you can not install at least macOS Ventura (13) on your Mac then you should immediately remove your device from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v24H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it, but I recommend you continue to use Windows 10 until early 2025 before you consider switching to it.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with a SaferPC Subscription and we will install updates each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 24.10.1 resolves several bugs and improves stability. This is not a security update.
https://www.amd.com/en/support

Intel Driver and Support Assistant 24.5.40.11 resolves several bugs. This is not a security update.
https://www.intel.com/p/en_US/support/detect

Nvidia Driver 566.03 resolves several bugs. This is not a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

UniFi AC Professional 6.6.77 resolves several bugs and improves performance, reliability and stability. This is not a security update.
https://www.ui.com/download/software/uap-ac-pro

UniFi airMAX NanoStation 5AC Loco 8.7.14 resolves several bugs. This is not a security update.
https://www.ui.com/download/software/loco5ac

UniFi Network Server 8.6.9 improves SIEM integration, dozens of improvements and bug fixes. This is a security update.
https://www.ui.com/download/releases/network-server

UniFi U6 Professional 6.6.77 resolves several bugs and improves performance, reliability and stability. This is not a security update.
https://www.ui.com/download/software/u6-pro

VIISAN OfficeCam 7.2.4.0 doesn’t provide a detailed change log so should be treated as a security update.
https://www.viisan.com/en/download/type1.html

Xerox Smart Start 2.1.22.0 doesn’t provide a detailed change log so should be treated as a security update.
https://www.support.xerox.com/en-us/content/143617

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.71.123 is a security update.
https://brave.com/

Firefox 132.0.2 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 128.4.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Google Chrome 130.0.6723.116 is a security update.
https://www.google.com/chrome/

Vivaldi 7.0.3495.6 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

ProtonMail (Android) 4.2.1 resolves several bugs. This is not a security update.
https://proton.me/mail/download

Spark 3.17.11.89740 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.17.12.90683 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 128.4.2 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk (macOS) 8.1.4 improves compatibility and requires re-granting persmissions. This is a security update.
https://anydesk.com/en/downloads

BrowsingHistoryView 2.59 improves compatibility. This is not a security update.
https://www.nirsoft.net/utils/browsing_history_view.html

curl 8.11.0 resolves dozens of bugs. This is a security update.
https://curl.haxx.se/windows/

Dropbox 211.4.6008 doesn’t provide a change log so should be treated as a security update.
https://www.dropbox.com/

FileZilla Client 3.68.1 resolves several bugs. This should be treated as a security update.
https://filezilla-project.org/

FileZilla Server 1.9.4 resolves several bugs, including improved Let’s Encrypt compatibility.
https://filezilla-project.org/

FreeFileSync 13.8 adds SFTP support for IPv6, improves copmatibility and resolves several bugs. This is not a security update.
https://www.freefilesync.org/download.php

Google Drive 99.0 *finally* adds differential uploads, which will save huge amounts of bandwidth for large files with minor changes. This is not a security update.
https://drive.google.com/start

MeshCentral 1.1.33 resolves dozens of bugs. This is not a security update.
https://meshcentral.com/info/downloads.html

Microsoft Teams 1.7.00.27855 improves BYOD and audio source detection. This is not a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 30.0.2 resolves dozens of bugs. This is a security update.
https://nextcloud.com/

Omada Software Controller 5.14.32.3 resolves a dozen bugs and improves the GUI. This is not a security update.
https://www.tp-link.com/us/support/download/omada-software-controller/

Signal 7.32.0 improves performance, bulk downloads, and adds Call Links. This is not a security update.
https://signal.org/download/

Signal (Android) 7.23.1 adds chat folders. This is not a security update.
https://signal.org/android/apk/

Syncthing 1.28.0 resolves several bugs. This is not a security update.
https://syncthing.net/

Technitium DNS Server 13.1.1 resolves several bugs and improves protocol support. This is not a security update.
https://technitium.com/dns/

Telegram 5.7.2 resolves over a dozen bugs. This is not a security update.
https://telegram.org/

Zoom 6.2.7.49583 is a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.11 improves compatibility. This is not a security update.
https://en.3tene.com/

Bitwig Studio 5.2.5 resolves several bugs. This is not a security update.
https://www.bitwig.com/download/

iTunes 12.13.4.4 is a security update.
https://www.apple.com/itunes/download/

KaraFun Player 3.2.2.56 resolves a dozen bugs. This is not a security update.
https://www.karafun.com/karaokeplayer/

Plex Desktop 1.104.0.241 now includes an advertising consent popup.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Media Server 1.41.1.9057 improves hardware-encoding for DVR, media support, and metadata. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.44.01 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

Minecraft Server (Java) 1.21.3 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server

Nintendo Switch 19.0.1 improves compatibility. This is not a security update.
https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/system%20updates/p/989

PS5 2024.101 resolves several bugs. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2024.11.05 adds Steam Game Recording and resolves dozens of bugs. As of this version Windows 7 and 8 are no longer supported. These end-of-life operating systems can continue to use the prior build (for now). https://help.steampowered.com/en/faqs/view/4784-4F2B-1321-800A
https://store.steampowered.com/news/app/593110

SteamOS SteamDeck Update 2024.11.06 resolves several bugs. This is not a security update.
https://store.steampowered.com/news/app/1675200/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe After Effects 24.6.3 & 25.0 are security updates.
https://helpx.adobe.com/security/products/after_effects/apsb24-85.html

Adobe Audition 24.6.3 and 25.0 are security updates.
https://helpx.adobe.com/security/products/audition/apsb24-83.html

Adobe Bridge 14.1.3 and 15.0 are security updates.
https://helpx.adobe.com/security/products/bridge/apsb24-77.html

Adobe Commerce 3.2.6 is a security update.
https://helpx.adobe.com/security/products/magento/apsb24-90.html

Adobe Illustrator 28.7.2 and 29.0.0 are security updates.
https://helpx.adobe.com/security/products/illustrator/apsb24-87.html

Adobe InDesign 18.5.3, 18.5.4 and 20.0 are security updates.
https://helpx.adobe.com/security/products/indesign/apsb24-88.html

Adobe Photoshop 24.7.4 and 25.12 are security updates.
https://helpx.adobe.com/security/products/photoshop/apsb24-89.html

Adobe Reader DC 24.004.20243 resolves several bugs. This is not a security update.
https://get.adobe.com/reader

Adobe Substance 3D Painter 10.1.1 is a security update.
https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html

Audacity 3.7.0 resolves more than a dozen bugs. This is not a security update.
https://www.audacityteam.org/download/

Blender 4.2.3 resolves dozens of bugs. This is not a security update.
https://www.blender.org/download/

Calibre 7.21.0 resolves over a dozen bugs. This is not a security update.
https://calibre-ebook.com/

Columns++ 1.1.3 resolves several bugs. This is not a security update.
https://github.com/Coises/ColumnsPlusPlus

Inkscape 1.4 resolves several bugs. This is not a security update.
https://inkscape.org/release/

Kdenlive 24.08.3 resolves dozens of bugs. This is not a security update.
https://kdenlive.org/

LibreOffice 24.2.7 resolves over 50 bugs. This is a security update.
https://www.libreoffice.org/

Manager 24.11.11.1937 resolves several bugs and improves inventory support. This is not a security update.
https://www.manager.io/

Nextcloud Desktop 3.14.3 resolves dozens of bugs. This is not a security update.
https://nextcloud.com/

Notepad++ 8.7.1 resolves a couple bugs. This is a security update.
https://notepad-plus-plus.org/

PDF-XChange Editor 10.4.3.391 resolves almost a dozen bugs. This is not a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

QuickBooks Pro 2022 20240726-R17_41 doesn’t provide a detailed change log so should be treated as a security update.
https://downloads.quickbooks.com/app/qbdt/products

QuickBooks Pro 2023 20240726-R14_49 doesn’t provide a detailed change log so should be treated as a security update.
https://downloads.quickbooks.com/app/qbdt/products

Operating System Updates

These are for specific Linux flavors and alternative operating systems and, sadly, are unlikely to be of interest to most people.

Google Chrome OS 130.0.6723.101 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Fedora 41-1.4 is a major update, adding many new features, removing unsupported and deprecated tools and applications, and hardening the operating system. This should be treated as a security update.
https://getfedora.org/en/workstation/download/

iOS 18.1 is a security update.
https://support.apple.com/kb/HT204204

iPadOS 18.1 is a security update.
https://support.apple.com/kb/HT204204

macOS 15.1 is a security update.
https://support.apple.com/kb/HT201541

Tails 6.9 is a security update.
https://tails.net/install/download/index.en.html

tvOS 18.1 is a security update.
https://support.apple.com/kb/HT202716

watchOS 11.1 is a security update.
https://support.apple.com/kb/HT204641

Security Software Updates

One or more of these is likely to be of interest to most people.

Chainsaw 2.10.1 resolves several bugs. This is not a security update.
https://github.com/countercept/chainsaw

FRST 2024.11.12 doesn’t provide a change log so should be treated as a security update.
https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/

FSS 2024.10.30 doesn’t provide a change log so should be treated as a security update.
https://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/

HTTP Toolkit 1.19.1 doesn’t provide a change log so should be treated as a security update.
https://httptoolkit.tech/

MalwareBytes Anti-Malware 5.2.1.144 resolves several bugs and hardens security controls. This should be treated as a security update.
https://www.malwarebytes.org/antimalware/

OpenSSL 3.4.0 is a security update.
https://slproweb.com/products/Win32OpenSSL.html

ProtonVPN (macOS) 4.5.0 improves WireGuard connectivity and improves stability. This is not a security update.
https://protonvpn.com/download

RogueKiller 15.19.2 resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

Stinger 13.0.0.215 adds support for new detections. This should be treated as a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

uBlock Origin 1.61.0 resolves over a dozen bugs. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.3.0 adds support for new encodings. This is not a security update.
https://www.dvdfab.cn/download.htm

PDF Creator 5.3.2 resolves several bugs and updates libraries. This is a security update.
https://www.pdfforge.org/pdfcreator

StreamFab 6.2.0.4 adds support for new sources and resolves several bugs.
https://www.dvdfab.cn/downloader-new.htm

UniFab 2.0.3.7 resolves several bugs. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Education updates

One or more of these are likely to be of interest to most people.

Zotero 7.0.9 resolves several bugs. This is not a security update.
https://www.zotero.org/

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.10.52 resolves a dozen bugs. This is not a security update.
https://1password.com/downloads/windows/

AppResourcesUsageView 1.06 improves compatibility. This is not a security update.
https://www.nirsoft.net/utils/app_resources_usage_view.html

balenaEtcher 1.19.25 updates SDK. This is not a security update.
https://etcher.balena.io/

Beyond Compare 5.0.3.30258 improves shell menu, updates libraries and resolves dozens of bugs. This is not a security update.
https://www.scootersoftware.com/download

Bitwarden 2024.10.4 resolves several bugs and improves auth methods and recovery. This is not a security update.
https://bitwarden.com/

CCleaner 6.29.11342 resolves several bugs. This is not a security update.
https://www.ccleaner.com/

CPU-Z Installer 2.12 adds support for newer hardware. This is not a security update.
https://www.cpuid.com/softwares/cpu-z.html

Dell OS Recovery Tool 2.4.1.2181 doesn’t provide a change log so should be treated as a security update.
https://www.dell.com/support/home/uk/en/ukbsdt1/drivers/osiso/recoverytool

DesktopOK 11.45 improves configuration and language files. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.2.95.0 resolves several bugs and updates libraries. This is a security update.
https://dngrep.github.io/

email-oauth2-proxy 2024-11-11 improves compatibility and adds a couple new features. This is not a security update.
https://github.com/simonrob/email-oauth2-proxy

ESEDatabaseView 1.75 improves compatibility. This is not a security update.
https://www.nirsoft.net/utils/ese_database_view.html

Etcher 1.19.25 updates SDK. This is not a security update.
https://www.balena.io/etcher/

ExplorerPatcher 22621.4317.67.1 improves compatibility. This is not a security update.
https://github.com/valinet/ExplorerPatcher/

Fing 3.7.2 improves network insights and resolves several bugs. This is not a security update.
https://www.fing.com/products/fing-desktop-download-windows

FoneTool 2.9.2 adds support for iOS 18 and iPhone 16. This is not a security update.
https://www.fonetool.com/download.html

Free Virtual Serial Ports 6.20.00.1466 adds support for virtual script ports and resolves a compatibility bug. This is not a security update.
https://freevirtualserialports.com/

GoodSync & GoodSync2Go 12.7.7 resolves several bugs and improves compatibility. This is not a security update.
https://www.goodsync.com/

grepWin 2.1.6 resolves several bugs. This is not a security update.
https://github.com/stefankueng/grepWin/releases/latest

GSmartControl 2.0.0 is a major update, reduces dependencies, improves input/output and scaling support. This is not a security update.
https://gsmartcontrol.shaduri.dev/

Homedale 2.14 is a cosmetic change. This is not a security update.
https://www.the-sz.com/products/homedale/

HWiNFO 8.14 adds support for newer hardware, improves output details, and logging. This is not a security update.
https://www.hwinfo.com/download/

Memtest86+ 7.20 adds support for new hardware and resolves several bugs. This is not a security update.
https://www.memtest.org/

MultiMonitorTool 2.15 improves compatibility and adds monitor position support. This is not a security update.
https://www.nirsoft.net/utils/multi_monitor_tool.html

NTLite 2024.11.10163 adds support for new components and resolves a couple bugs. This is not a security update.
https://www.ntlite.com/download/

OSForensics 11.0.1015 updates libraries, resolves a crash bug and improves clarity for sparse records. This is not a security update.
https://www.osforensics.com/download.html

osquery 5.14.1 resolves several bugs. This is not a security update.
https://osquery.io/downloads

PowerToys 0.86.0 resolves several bugs and improves Advanced Paste, Workspaces, Mouse Jump and more. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

RoboForm 9.6.3 resolves several bugs. This is not a security update.
https://www.roboform.com/

Rufus 4.6 improves compatibility and resolves several bugs. This is not a security update.
https://rufus.ie/en_US/

ScreenConnect 24.3.7.9067 resolves several bugs. This is not a security update.
https://screenconnect.connectwise.com/download

Starwind V2V Converter 9.554 adds support for new disk image formats. This is not a security update.
https://www.starwindsoftware.com/starwind-v2v-converter

TeamViewer 15.59.3 adds AI log generation, improved address book, reporting and a dozen bug fixes. This is not a security update.
https://www.teamviewer.com/en-us/download/

WhyNotWin11 2.6.1.1 adds TSV, improved logging, and resolves a couple bugs. This is not a security update.
https://github.com/rcmaehl/WhyNotWin11

WifiInfoView 2.95 improves error reporting. This is not a security update.
https://www.nirsoft.net/utils/wifi_information_view.html

WinGet 1.9.25180 resolves more than 100 bugs. This is not a security update.
https://github.com/microsoft/winget-cli/releases/latest

WinScan2PDF 9.11 improves compatibility and resolves a couple bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WizTree 4.22 adds MTP/PTP device support, improves compatibility, scaling support and resolves several bugs. This is not a security update.
https://www.diskanalyzer.com/

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 2024.2.1.11 resolves several bugs. This is not a security update.
https://developer.android.com/studio

DB Browser for SQLite 3.13.1 resolves several bugs. This is not a security update.
https://sqlitebrowser.org/

GDevelop 5.4.217 resolves several bugs. This is not a security update.
https://gdevelop.io/download

GitHub Desktop 3.4.9 resolves several bugs and updates libraries. This is not a security update.
https://desktop.github.com/

Go 1.23.3 resolves several bugs. This is not a security update.
https://go.dev/

Java 8u431 is a security update.
https://www.java.com/en/download/manual.jsp

Microsoft Visual C++ 2017 Redistributable 14.16.27052.0 is a security update.
https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist

Microsoft Visual C++ 2019 Redistributable 14.29.30156.0 is a security update.
https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist

Microsoft Visual C++ 2022 Redistributable 14.40.33816.0 is a security update.
https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist

MySQL ConnectorNet 9.1.0 resolves several bugs, including crash bugs. This is not a security update.
https://dev.mysql.com/downloads/connector/net/

Node.js 22.11.0 is a security update.
https://nodejs.org/en/

Node.js 23.2.0 is a security update.
https://nodejs.org/en/

Redemption 6.6.0.6338 resolves several bugs. This is not a security update.
https://www.dimastr.com/redemption/

SQLite 3.47.0 resolves several bugs. This is not a security update.
https://www.sqlite.org/download.html

TortoiseGit 2.17.0.2 improves compatibility. This is not a security update.
https://tortoisegit.org/

TortoiseSVN 1.14.8 resolves several bugs. This is not a security update.
https://tortoisesvn.net/downloads.html

Visual Studio Code 1.95.2 resolves several bugs. This is not a security update.
https://code.visualstudio.com/

WinMerge 2.16.44 resolves several bugs. This is not a security update.
https://winmerge.org/

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 7.1.4 resolves several bugs. This is not a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

Invision Community 4.7.19 is a security update.
https://invisioncommunity.com/

Joomla 5.2.1 is a security update.
https://www.joomla.org/

Piwigo 15.1.0 is a security update.
https://piwigo.org/

Antispam Bee 2.11.7 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/antispam-bee/

BuddyPress 14.2.1 is a security update.
https://wordpress.org/extend/plugins/buddypress/

Contact Form 7 6.0 provides more than a dozen code and feature changes. This is not a security update.
https://wordpress.org/extend/plugins/contact-form-7/

Duplicator 1.5.11.2 resolves a charset bug. This should be treated as a security update.
https://wordpress.org/plugins/duplicator/

Interactive World Map 3.4.8 is a security update.
https://wordpress.org/extend/plugins/interactive-world-map/

Sucuri Security 1.9.6 improves reporting and log behavior. This is not a security update.
https://wordpress.org/extend/plugins/sucuri-scanner/

WordPress Importer 0.8.3 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/wordpress-importer/

WP Plugin Update Checker 5.5 resolves a couple bugs and improves debug and ZIP support. This is not a security update.
https://github.com/YahnisElsts/plugin-update-checker/releases/latest

WPBakery 8.0 adds new features, improves controls, and resolves several bugs. This is not a security update.
https://wpbakery.com/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

 

Updates 2024-10-08

Welcome back, Folks!

Today is Patch Tuesday for October, 2024.

Windows 11 24H2 is out. So is macOS 15/Sequoia. iOS 18, iPadOS 18, tvOS 18, watchOS 11, and visionOS 11 are out now.  The first set of security updates for each of these are released now, too.

All versions of Windows 11 prior to 23H2 are no longer be supported. Upgrade to 23H2 now, then do not upgrade to 24H2, yet. Let everyone else be the guinea pigs. It’s already showing quite a few issues.

All versions of macOS prior to 13/Ventura are no longer supported. If you can’t upgrade your Mac to Ventura you need to permanently take it offline and/or replace it.

Windows 10 now has only 12 months of support left. If your computer can not be upgraded to Windows 11 either start planning now for a switch to Linux or replacing your computer.

There were 505+ major hacks, and over 395 application updates this month. It’s an enormous month, with about 4 GB of updates for most users.

This Month in Technology

4B Components, 5.11 Tactical, A1 Mobile Locksmith, Access Ambulatory Surgery Center, LLC, Access Sports, Accurate Railroad Construction Ltd, Acuity Advisor, Adobe Acrobat Reader DC, Adobe After Effects, Adobe Audition, Adobe Commerce & Magento stores (5% of all their commerce sites!!!),  Adobe Media Encoder, Adobe Photoshop, Adobe Premiere Pro, ADT, Advanced Sterilization Products, Inc, Affirm Agency, AFP, air-gapped government systems, Akromold, Al Rajhi Bank, Albany College of Pharmacy, Alliance, Ally Bank, Alshaya Group, Altman Plants, Alvan Blanch, American Water Works, Amgen Inc, Amplitude Laser, Andamen, Andantex USA, Anniversary Holding, Apache Avro, Apache HugeGraph-Server, Apex Softcell, Aramark myPay, Arc browser, Arelance Group, Around the Clock Companies, Asheville Arthritis and Osteoporosis Center, PA, AT&T, ATG Communications Group, Atrium Health, Autel Maxicharger, Auto Recyclers, AutoCanada, Autodesk Navisworks Freedom DWF, automatic storage tank gauge (ATG) systems (6 models), Avi Resort & Casino, Avis, Balboa Bay Club Ventures LLC, Banana Gun, Bangladeshi government, Barbados Revenue Authority, Barnes & Cohen, Batcom, Battle Lumber Co, Bay Ridge Automotive Management Group, Bazooka, Bel-Air Bay Club, BELL DATA, Inc, Benny Gantz, Bethalto Community Unit School District, Betterhalf, Bharat Petroleum, BingX, Bloom Hearing Specialists, Blundstone USA Inc, BNBuilders, BotSpace, Branhaven Chrysler Dodge Jeep Ram, Brechbuhler Scales Inc, BroadGrain Commodities, Broward Realty Corp, Brown Bottling Group, Brown Integrated Logistics, Brunswick Hospital Center, BSH Soft, BudTrader, C&L Ward, CaleyWray, Calibrated Healthcare, LLC, California Department of Social Services, Cameroon’s pension fund, Canstar Restorations, Capgemini, Capital Printing, Carlile Group, Cascade Columbia Distribution, Casino Fandango, Casio, Caterpillar Inc, Cellular Plus, CentralTickets, CF Medical, Charles Darwin School, Chernan Technology, ChiceDNA, Chinese government, a Chinese government botnet, Chrome, Chunghwa Telecom Data, Cincinnati Public Schools, City of Aberdeen, WA, City of Forest Park, City of Pleasanton, CA, City of Richardson, TX, CK Associates, CKS Packaging, Classic Business Products, CobelPlast, Cohesive Networks VNS3, Comcast Cable Communications, Community Clinic of Maui, Inc, Community Hospital of Anaconda, Compass Group, Concord Management Services, Condere IP, Conductive Containers, Inc, Connally Memorial Medical Center, Control Panels USA, CopySmart LLC, Corantioquia, Creative Consumer Concepts, Creative Playthings, CrediHealth, Crown Mortgage Company, CSG Consultants, D-Link routers, DATASUS, Daughterly Care, David’s Bridal, Del Valle Independent School District, Delaware Library system, Dell (twice in a week),  Deloitte, Delta Prime, Department of Foreign Affairs (DFA), Philippines, DETRAN, Detroit Public TV, Diamond Contracting, LLC, Didi Chuxing, digiDirect, Dimensional Merchandising, DINAS Corp, Divine Interprises INC, DJH Jugendherberge, Domain Industries, DotPe, DPC DATA, Dr. Web, DrayTek routers, Dreyfuss + Blackford Architecture, Duopharma Biotech, Dutch Police, EasyMPS, Edge Imaging, eFile.com, EigenLayer, Elgin Separation Solutions, Elitecare Emergency Hospital, Elitecare, Empereon Marketing, English Football League, Enterprise Outsourcing, EnviroNET Inc, Environmental Code Consultants Inc, Erasmus+, ETC Companies, Ethena Labs, Eurobulk, Evans Distribution Systems, Experience Engine, Express Services, Fabrica Industrial Machinery & Equipment, FastStone Imave Viewer, Fazenda Brazil government, FBCS, Fedbank Financial Services, Feeld, Feldstein & Stewart, Fireworks Software, First Choice, Fleet Equipment, FoccoERP, Forshey Prostok LLP, Fortinet, Fortive, Foundation, Foxit PDF Reader, Freshstart Credit Repair, Frigocenter, Fritzøe Engros, FTV Employment Services LLC, Fylde Coast Academy Trust, G/S Solutions, Galloway MacLeod, Games Box, GameVN, Garvey, GenPro Inc, GitLab, GNOME Project G, GoDaddy, Golden Age Nursing Home, Gough Construction, Graminex, Graybill Medical Group, Greene Acres Nursing Home, Guerriere & Halnon, GW Mechanical, Hair Club for Men, Hamel Cranial Chiropractic & Wellness INC, Harvard Pilgrim Health Care, Harvey Nichols, HDI, Hertz, Hezbollah, Hindle Group, Holmes & Brakel, Howard CPAs, HPE Aruba Networking, Hughes Gill Cochrane Tinetti, Hunter Dickinson Inc, HuntStand, I-MED, Ibermutuamur, ICBC London, IDEALEASE INC, Idre Fjäll, Indian Supreme Court, Indodax, Infosys McCamish Systems, Instituto Nacional de Deportes de Chile, Insurance Agency Marketing Services, Inc, InteriorWorx Commercial Flooring, iOS Password Manager, 260,000 IoT devices (Raptor Train), Iron Metals, Isola, Israel Defense Minister, Israel Foreign Affairs Minister, Israel Harel Insurance, Israel Prime Minister, an Israeli analytics company, Israeli defense companies, Israeli Industrial Batteries, Istrail, Italian Ministry, Ivanti Cloud Services Appliance, Ivanti Endpoint Manager, Ivanti Workspace Control, Jackson Paper Manufacturing, Jacobsen Construction Co, Inc Health Plan, Joe Swartz Electric, Johnson & Wales University, JTaylor & Associates LLC, Juice Generation, Kawasaki Motors Europe, Keller Williams Realty Group, Kennedy Funding, Keuka College, Keya Accounting and Tax Services LLC, Kia dealer portal, Kia vehicles (again), KintApp, Kravit, Hovel & Krawczyk SC, KukuFM, Kuwait Health Ministry, LA Financial Federal Credit Union, Labib Funk Associates, Ladov Law Firm, Lakeland Chamber, Lancaster Royal Grammar, three-quarters of law firms (which explains a lot of the hacks this month), Law Offices of Michael J Gurfinkel, Inc, Lawrie Insurance Group, Lee Hoffoss Injury Lawyers, LEGO, Lenovo Service Bridge, Liberty First Credit Union, Local 1964 ILA Health & Insurance Fund, Lumen Technologies, Luso Cuanzа, Lyomark Pharma, MacGillivray Law, macOS graphics driver, macOS video decoder, Magenta Photo Studio, Malwarebytes Antimalware, Markdom Plastic Products, Maryville Academy, Mattson Technology, Inc, Max Shop, MC2 Data, McAbee Construction, Inc, McCarty Company, MCNA Dental, MDSi INC, MediCheck, MedReview, Messe C, Miami Dolphins Forum, Michigan Masonic Home, Michigan Medicine, Microsoft Azure API Management, Microsoft C++ redistributable, Microsoft Pragmatic General Multicast Server, Microsoft SharePoint, Microsoft Windows, Microsoft Windows 10 AllJoyn Router Service, Microsoft Windows Internet Explorer, Microsoft Windows SmartScreen, Mile Hi Foods, MIPS Holding, Inc, Mobility Compare, Model Engineering, Moeller Door and Window, MoneyGram, Mozambique Election System, Mt. Carmel Behavioral Healthcare, Muskogee City County Enhanced 911 Trust Authority, mySCADA myPRO, NASA, New Electric, New River Electrical, New York Sports Club, Noble Environmental, North American Breaker, Nova Sinseg, Nusser Mineralöl GmbH, NVIDIA Container Toolkit, Octapharma Plasma, OffRoadAction, Omega Industries, One Point HR Solutions, Onyx, OpenAI, OpenPLC_v3 Runtime, Optigo Networks ONS-S8, Oracle WebLogic, Pacific Coast Building Products, Pacific Islands Forum, Fiji, Pacific Scientific Energetic Materials Company LLC, Palomar Medical Group, PaperCut NG, Partners Air, Patelco Credit Union, Patrick Sanders Company, PDF-XChange Editor, Pearl Cohen, Peerless Umbrella, Performance Food Centers, Performance Therapies, PetEdge, Pete’s Road Service, PetroChina, Physical Medicine & Rehabilitation Center, Piggly Wiggly, Plaisted Companies, Plastics Plus, Plumbers Stock, Port of Seattle/Seattle-Tacoma International Airport (SEA), Power Torque Services, PRC-Saltillo, Premier Packaging, Prentke Romich Company, Progress Software WhatsUp Gold, Pureform Radiology Center, Qualcomm DSP, Quantum Healthcare, Raaga, Rackspace, Radio Geretsried, 19 UK railway stations, Ranveer Allahbadia, Reading Train Station, Red Barrels, Repsol, Research Electronics International, Reutter, Richland County, WI, Richmond Auto Mall, Richmond Community Schools, Riley Gear Corporation, Rim Country Health and Rehabilitation, Ring Power, River Delta Unified School District, River Region Cardiology Associates, Riverside Resort Casino, Rob Levine & Associates, Robson Planning Group Inc, Rockwell Automation PLC Software, Sacred Heart Catholic School, Sage Home Loans Corporation, SaniRent, Satia Group, Savannah Candy, Schäfer, dein Bäcker GmbH & Co KG, Scranton School District, Sellafield, ServiceNow, Shenango Area School District, Sherr Puttmann Akins Lamb PC, Shezmu, Shin Bet, ShoreMaster, Signature Healthcare Services LLC, siParadigm LLC, Slim CD, Smart Buy, Smart Source, Inc, 2,700 “smart” devices in the Netherlands, SolarWinds Access Rights Manager, Solutii Sistemas, Sono Bello, Southeast Cooler, Southern Bone, SpaceX, Spectrum Industries, Sportstech, spWETH Wallet, Star Blizzard, Star Health (India), Stillwater Mining Company, Storck-Baugesellschaft mbH, Structural Concepts, Sub-Zero, Wolf, and Cove, Sunrise Farms, Synnovis, TANYA Creations, TeamViewer, TeleHealth Center (India), Temu, Tewkesbury Borough Council, Thai Honda Manufacturing, The Gill Corporation, The Maids International, The Rubber Resources, The Superior Court of California, The Tech Interactive, Theresa Gordon Tax Services, Inc, Think Simple, Thomas Lloyd, Thompson Construction Supply, TIAA, Title Financial Corporation, Total Electronics, TOTVS, Toyota, TradeZero America Inc, Transport for London, Transtec SAS, TransUnion Risk and Alternative Data Solutions, Inc, Travel Alberta, TRC Worldwide Engineering, Trend Micro Deep Discovery Inspector, True Family Enterprises, Truflation, Truist Bank, Trump campaign, Tuttle-Click Automotive Group, Twilio, Uber Eats, UCC Retreivals, United Animal Health, Universal Music Group, University Medical Center, University of Minnesota Orthodontics, US Centers for Medicare and Medicaid Services, US Congress, US Dermatology Partners, UT Southwestern Medical Center, Uttarakhand (India) government, Veertu Anka Build, Verizon, Vermilion Parish Schools, Versa Director, VGTRK, Vickers Engineering, Vidisco, Virginia Dare Extract Co, Visionary Homes, Visteon Infotainment System, VMware vCenter Server, Ward Transport, Wayne County, MI, WazirX, We Level Up Treatment Lake Worth, Weiser Memorial Hospital, Weldco-Beales Manufacturing, Wells Fargo, Western Digital MyCloud PR4100, WhatsApp, Wichita Police, Wilmington Convention Center, Wilson & Lafleur, Wisconsin Physicians Service Insurance Corp, Woodard, Hernandez, Roth & Day, WordPress Houzez Login Register plugin, WordPress Houzez theme, WordPress LiteSpeed Cache Plugin, Wright, Moore, DeHart, Dupuis & Hutchinson, LLC, Young Consulting LLC, and Zimbra email servers have reported hacking or compromises this month.

AFP, AT&T, Cloudflare, Confidant Health, Dr. Web, Google CloudImposer, Highline Public Schools, MoneyGram, PlayStation Network, Port of Seattle, Providence Public Schools, State Data Center (India), Verizon, and WP Engine have suffered from outages this month.

Last months updates broke M4 iPad Pro devices, macOS Sequoia VPN & antivirus software, Microsoft 365 apps, Microsoft Outlook mail vs nested folders, Microsoft Word (serious – Word deletes your files if they have mixed case extensions!), Windows 11 24H2 BSODs, Windows 11 24H2 gaming performance, Windows 11 24H2 license activation, Windows reboots, and Windows USB & Bluetooth.

In other news

The Internet backdoor mandated by US federal law has been hijacked by China (Salt Typhoon) and is being actively exploited again across several phone providers. It’s not good.

Almost 3 in 5 of breached UK firms admit to paying ransom on demand. An insane 92% of healthcare firms in the US were hit by cyberattacks this year.

Now that “exploding pagers” (and more) are a thing, will people start to take supply chain and physical security seriously?

Fearing exposure of weak security processes, Apple has moved to dismiss their lawsuit against NSO Group.

Now for the good news

Discord has added end-to-end encryption for audio & video calls.

NIST has finally scrapped their complexity and change frequency recommendations. The math on these recommendations simply doesn’t add up.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is enormous this month. The typical computer should see roughly 4 GB in updates today. Let’s get started.

Microsoft released 65 updates to address 121 vulnerabilities in .NET Framework, .NET, Azure CLI, Azure Monitor, Azure Stack, BranchCache, Code Integrity Guard, DeepSpeed, Internet Small Computer Systems Interface (iSCSI), Microsoft ActiveX, Microsoft Configuration Manager, Microsoft Defender for Endpoint, Microsoft Edge (Chromium-based), Microsoft Graphics Component, Microsoft Management Console, Microsoft Office Excel, Microsoft Office SharePoint, Microsoft Office Visio, Microsoft Office, Microsoft Simple Certificate Enrollment Protocol, Microsoft WDAC OLE DB provider for SQL, Microsoft Windows Speech, OpenSSH for Windows, Outlook for Android, Power BI, Remote Desktop Client, RPC Endpoint Mapper Service, Service Fabric, Sudo for Windows, Visual C++ Redistributable Installer, Visual Studio Code, Visual Studio, Windows Ancillary Function Driver for WinSock, Windows BitLocker, Windows Common Log File System Driver, Windows Cryptographic Services, Windows cURL Implementation, Windows EFI Partition, Windows Hyper-V, Windows Kerberos, Windows Kernel, Windows Kernel-Mode Drivers, Windows Local Security Authority (LSA), Windows Mobile Broadband, Windows MSHTML Platform, Windows Netlogon, Windows Network Address Translation (NAT), Windows NT OS Kernel, Windows NTFS, Windows Online Certificate Status Protocol (OCSP), Windows Print Spooler Components, Windows Remote Desktop Licensing Service, Windows Remote Desktop Services, Windows Remote Desktop, Windows Resilient File System (ReFS), Windows Routing and Remote Access Service (RRAS), Windows Scripting, Windows Secure Channel, Windows Secure Kernel Mode, Windows Shell, Windows Standards-Based Storage Management Service, Windows Storage Port Driver, Windows Storage, Windows Telephony Server, Winlogon, and MSRT. This includes security updates. A reboot is required.

Apple released updates for Apple TV 1.5.0.152 for Windows, iOS 17.7, iOS 18, iOS 18.0.1, iPadOS 17.7, iPadOS 18, iPadOS 18.0.1, macOS Sequoia 15.0.1, macOS Sonoma 14.7, macOS Ventura 13.7, Safari 18, Safari 18.0.1, tvOS 17.6.1, tvOS 18, visionOS 2, visionOS 2.0.1, watchOS 10.6.1, watchOS 11, watchOS 11.0.1, and Xcode 16. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

iOS 17.7, 18, and 18.0.1 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 17.7, 18, and 18.0.1 are security updates. Use Settings, General, Software Update to install the most current update.

watchOS 10.6.1, 11, and 11.0.1 are security updates. Use the Watch app on your iPhone to install the most current version.

tvOS 18 is a security update. Use System, Software Update to install the most current version.

visionOS 2 and 2.0.1 are security updates. Use System, Software Update to install the most current version.

Google Chrome OS 128.0.6613.163, 129.0.6668.80, and ChromeOS LTS 126.0.6478.254 are security updates. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sequoia (15.x) means that macOS Monterey (12.x) and older are no longer supported. If you can not install at least macOS Ventura (13) on your Mac then you should immediately remove your device from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 11 (v24H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it, but I recommend you continue to use Windows 10 until early 2025 before you consider switching to it.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with a SaferPC Subscription and we will install updates each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 24.9.1 improves hardware compatibility, game support, resolves several bugs and expands Vulkan extensions. This is not a security update.
https://www.amd.com/en/support

TP-Link Archer AX55 v1 240628 improves mesh and configuration controls. This is not a security update.
https://www.tp-link.com/us/support/download/archer-ax55/v1/#Firmware

goxlr-utility 1.1.4 resolves several compatibility and reliability bugs. This is not a security update.
https://github.com/GoXLR-on-Linux/goxlr-utility/

UniFi Network Server 8.4.62 resolves several bugs. This is not a security update.
https://www.ui.com/download/releases/network-server

VIISAN OfficeCam 7.2.2.0 doesn’t provide a change log so should be treated as a security update.
https://www.viisan.com/en/download/type1.html

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.70.123 is a security update. Use Help, About to install the most current version.
https://brave.com/

Google Chrome 129.0.6668.100 is a security update. Use Help, About to install the most current version.
https://www.google.com/chrome/

Microsoft Edge 129.0.2792.79 is a security update. Use Help, About to install the most current version.
https://www.microsoft.com/en-us/edge/business/download

Firefox 131.0 is a security update. Use Help, About to install the most current version.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 128.3.0 is a security update. Use Help, About to install the most current version.
https://www.mozilla.org/en-US/firefox/organizations/all/

Vivaldi 6.9.3447.51 is a security update. Use Help, About to install the most current version.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Mailspring 1.14.0 is a security update.
https://getmailspring.com/

ProtonMail (Android) 4.0.22.1 resolves a major stability bug. This is not a security update.
https://proton.me/mail/download

Spark 3.17.9.86866 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.17.9.86865 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 128.3.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 8.1.0 resolves dozens of bugs and improves stability. This is a security update.
https://anydesk.com/en/downloads

AnyDesk (macOS) 8.1.2 is a security update.
https://anydesk.com/en/downloads

BrowsingHistoryView 2.58 resolves an export bug. This is not a security update.
https://www.nirsoft.net/utils/browsing_history_view.html

curl 8.10.1 resolves over a dozen bugs. This is not a security update.
https://curl.haxx.se/windows/

Dropbox 209.4.3661 does not provide a detailed change log so should be treated as a security update.
https://www.dropbox.com/

Facebook Messenger 215.6.0.24.211 is a security update.
https://www.messenger.com/download

FileZilla Server 1.9.2 resolves a bug in the update engine. This is not a security update.
https://filezilla-project.org/

Google Drive 98.0 is a security update.
https://drive.google.com/start

MeshCentral 1.1.32 is a security update.
https://meshcentral.com/info/downloads.html

Microsoft Teams 1.7.00.26062 improves onboarding flow and allows external presenters to join from mobile platforms. This is not a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 30.0.0 is a major update, updating libraries, minimum requirements, and resolving more than a hundred bugs. This is a security update.
https://nextcloud.com/

Npcap 1.80 resolves several bugs. This is not a security update.
https://nmap.org/npcap/

Rclone 1.68.1 improves compatibility and resolves several bugs. This is not a security update.
https://rclone.org/

Signal 7.27.0 adds several new display options for media, groups and restores ability to search stored messages from groups you’re no longer part of. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.18.2 adds ability to search for emoji. This is not a security update.
https://signal.org/android/apk/

Technitium DNS Server 13.0.2 resolves protocol bugs. v13 adds several other new DNS features and controls including ZONEMD, RP, Catalog Zones and improved logging. This is not a security update.
https://technitium.com/dns/

Telegram 5.6.1 resolves dozens of bugs. This is not a security update.
https://telegram.org/

Telegram (Android) 11.1.3 resolves dozens of bugs. This is not a security update.
https://telegram.org/apps

Zoom 6.2.3.47507 resolves several bugs. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.10 resolves a couple bugs and improves lip sync. This is not a security update.
https://en.3tene.com/

Bitwig Studio 5.2.4 resolves over 20 bugs. This is not a security update.
https://www.bitwig.com/download/

Grayjay 264 adds auto-play toggle, allows you to control rotation sensitivity, reverse rotation, and resolves several bugs and compatibility issues. This is not a security update.
https://grayjay.app/index.html

iTunes 12.13.3.2 is a security update.
https://www.apple.com/itunes/download/

Plex Desktop 1.102.0.230 resolves a couple bugs and adds an advertising consent notice. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Home Theater 1.67.1.233 updates web engine. This should be treated as a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Media Server 1.41.0.8994 adds support for external subtitles, improved ad detection, and resolves several bugs. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.31.04 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

Nintendo Switch 19.0.0 improves stability. This is not a security update.
https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/system%20updates/p/989

PS5 2024.920 improves stability. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2024.09.17 changes the terms of use and resolves several bugs. This is not a security update.
https://store.steampowered.com/news/app/593110

SteamOS SteamDeck Update 2024.10.03 improves Wi-Fi 7 compatibility. This is not a security update.
https://store.steampowered.com/news/app/1675200/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Animate 23.0.8 and 24.0.5 are security updates.
https://helpx.adobe.com/security/products/animate/apsb24-76.html

Adobe Commerce 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 1.4.2-p3, 1.3.5-p8, 1.3.4-p10, and 1.3.3-p11 are security updates.
https://helpx.adobe.com/security/products/magento/apsb24-73.html

Magento Open Source 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, and 2.4.4-p11 are security updates.
https://helpx.adobe.com/security/products/magento/apsb24-73.html

Adobe Dimension 4.0.4 is a security update.
https://helpx.adobe.com/security/products/dimension/apsb24-74.html

Adobe FrameMaker 2020.7 and 2022.5 are security updates.
https://helpx.adobe.com/security/products/framemaker/apsb24-82.html

Adobe InCopy 19.5 and 18.5.4 are security updates.
https://helpx.adobe.com/security/products/incopy/apsb24-79.html

Adobe InDesign 19.5 and 18.5.4 are security updates.
https://helpx.adobe.com/security/products/indesign/apsb24-80.html

Adobe Lightroom 7.5, 13.5.1, and 12.5.2 are security updates.
https://helpx.adobe.com/security/products/lightroom/apsb24-78.html

Adobe Substance 3D Painter 10.1.0 is a security update.
https://helpx.adobe.com/security/products/substance3d_painter/apsb24-52.html

Adobe Substance 3D Stager 3.0.4 is a security update.
https://helpx.adobe.com/security/products/substance3d_stager/apsb24-81.html

Audacity 3.6.4 doesn’t have a change log so should be treated as a security update.
https://www.audacityteam.org/download/

Blender 4.2.2 resolves dozens of bugs. This is a security update.
https://www.blender.org/download/

Calibre 7.19.0 improves performance and resolves several bugs. This is not a security update.
https://calibre-ebook.com/

Ghostscript 10.04.0 is a security update.
https://www.ghostscript.com/releases/gsdnld.html

GnuCash 5.9 resolves several bugs. This is not a security update.
https://www.gnucash.org/

Kdenlive 24.08.1 resolves dozens of bugs. This is not a security update.
https://kdenlive.org/

Krita 5.2.6 resolves over 50 bugs and improves reliability and stability. This is not a security update.
https://krita.org/en/download/

LibreOffice Fresh 24.8.2 resolves almost 200 bugs. This is a security update.
https://www.libreoffice.org/

Manager 24.10.8.1879 adds business templates, FDX support, and resolves several bugs. This is not a security update.
https://www.manager.io/

Nextcloud Desktop 3.14.1 resolves a dozen bugs. This is not a security update.
https://nextcloud.com/

Notepad++ 8.7 updates libraries, resolves over a dozen bugs. This is a security update.
https://notepad-plus-plus.org/

PDF Candy Desktop 3.13 doesn’t provide a change log so should be treated as a security update.
https://pdfcandy.com/

PDF-XChange Editor 10.4.1.389 is a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

QuickBooks Pro 2022 20240726-R17_34 doesn’t provide a change log so should be treated as a security update.
https://downloads.quickbooks.com/app/qbdt/products

QuickBooks Pro 2023 20240726-R14_39 doesn’t provide a change log so should be treated as a security update.
https://downloads.quickbooks.com/app/qbdt/products

Security Software Updates

One or more of these is likely to be of interest to most people.

JShelter 0.19.1 improves Manifest V3 compatibility and performance. This is not a security update.
https://jshelter.org/install/

KeePass 2.57.1 is a security update.
https://keepass.info/

MalwareBytes Anti-Malware 5.5.4 doesn’t provide a change log so should be treated as a security update.
https://www.malwarebytes.org/antimalware/

RogueKiller 15.18.3 updates libraries and resolves several bugs. This should be treated as a security update.
https://www.adlice.com/download/roguekiller/

SecurityCheck 2024.9.22 doesn’t provide a change log so should be treated as a security update.
https://www.bleepingcomputer.com/download/securitycheck/dl/123/

Stinger 13.0.0.197 is a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

SuperAntiSpyware 10.0.1268 adds support for new browsers, applications, unicode compatibility and resolves several bugs. This is a security update.
https://www.superantispyware.com/download.html

uBlock Origin 1.60.0 adds several new features and resolves a couple bugs. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

Operating System Updates

These are for specific Linux flavors and alternative operating systems and, sadly, are unlikely to be of interest to most people.

QubesOS 4.2.3 is a security update.
https://www.qubes-os.org/downloads/

Tails 6.8 is a security update. 6.8 also signals the merger of Tails and the Tor Project.
https://tails.net/install/download/index.en.html

Zorin OS 17.2 improves customization, updates libraries, and resolves several bugs. This is not a security update.
https://zorin.com/os/mirrors/

Capture Updates

These are unlikely to be of interest to most people.

SnagIt 24.2.4 resolves stability bugs. This is not a security update. This is not a security update.
https://www.techsmith.com/screen-capture.html

VideoCacheView 3.10 improves compatibility with Google Chrome. This is not a security update.
https://www.nirsoft.net/utils/video_cache_view.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.2.7 adds support for new encodings. This is not a security update.
https://www.dvdfab.cn/download.htm

MakeMKV 1.17.8 improves defect tolerance and resolves several bugs. This is not a security update.
https://www.makemkv.com/download/

StreamFab 6.2.0.0 improves compatibility and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 2.0.3.5 adds FLAC support and resolves sseveral bugs. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Education updates

One or more of these are likely to be of interest to most people.

Zotero 7.0.7 resolves several bugs. This is not a security update.
https://www.zotero.org/

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.10.46 adds QR code authentication, Wi-Fi QR code sharing, accessibility improvements, and resolved several bugs. This is not a security update.
https://1password.com/downloads/

AOMEI Partition Assistant 10.5.0 adds Boot Repair, improves Migrate OS and resolves bugs in the optical media creation flow. This is not a security update.
https://www.diskpart.com/

Bitwarden 2024.9.2 improves PDF attachment handling and improves Secrets Manager. This is not a security update.
https://bitwarden.com/

CCleaner 6.28.11297 adds support for new applications. This is not a security update.
https://www.ccleaner.com/

CPU-Z Installer 2.11 improves mainboard detection and adds new hardware support. This is not a security update.
https://www.cpuid.com/softwares/cpu-z.html

Deskflow 1.17.0 is a complete rebrand of the upstream Synergy source, pushing the public code base into a useful utility. This is the first one, though, so I’d hold off a little while. This is not a security update.
https://deskflow.org/

DesktopOK 11.44 improves copmatibility. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.2.84.0 improves cache plug-in to use hash data to reduce network chatter, encoding improvements, and resolves several bugs. This is not a security update.
https://dngrep.github.io/

email-oauth2-proxy 2024-09-12 adds option to use password as credentials, improves documentation and resolves several bugs. This is not a security update.
https://github.com/simonrob/email-oauth2-proxy

Everything Toolbar 1.5.1 improves compatibility, adds RTL support, keyboard shortcuts and resolves several bugs. This is not a security update.
https://github.com/stnkl/EverythingToolbar/

ExplorerPatcher 22621.3880.66.6 improves compatibility and adds support for Windows 11 v24H2. This is not a security update.
https://github.com/valinet/ExplorerPatcher/

Fido 1.60 adds support for Windows 11 v24H2 and removes v23H2. This is not a security update.
https://github.com/pbatard/Fido/releases

Fing 3.7.1 improves Network Insights and resolves several bugs. This is not a security update.
https://www.fing.com/products/fing-desktop-download-windows

FoneTool 2.9.0 resolves several bugs. This is not a security update.
https://www.fonetool.com/download.html

Git SCM 2.46.1 resolves several bugs and improves documentation. This is not a security update.
https://git-scm.com/

GoodSync 12.7.6 improves logging and compatibility. This is not a security update.
https://www.goodsync.com/

Homedale 2.13 adds channel utilization reporting, Wi-Fi 7 (802.11be) support and filtering improvements. This is not a security update.
https://www.the-sz.com/products/homedale/

HWiNFO 8.12 adds support for newer hardware and resolves several bugs. This is not a security update.
https://www.hwinfo.com/download/

HWMonitor 1.55 adds support for newer hardware and battery information. This is not a security update.
https://www.cpuid.com/softwares/hwmonitor.html

IsMyHdOK 4.11 adds support improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

Kingston SSD Manager 1.5.4.9 doesn’t provide a change log so should be treated as a security update.
https://www.kingston.com/us/support/technical/ssdmanager

LessMSI 2.2.0 adds Italian language support. This is not a security update.
https://lessmsi.activescott.com/

MultiMonitorTool 2.11 resolves a mapping bug. This is not a security update.
https://www.nirsoft.net/utils/multi_monitor_tool.html

NTLite 2024.9.10073 resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

OSForensics 11.0.1014 resolves over a dozen bugs including performance and reliability issues. This is not a security update.
https://www.osforensics.com/download.html

PointerStick 6.44 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

PowerToys 0.85.1 improves stability. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

ScreenConnect 24.2 should be avoided. It has had rollout “paused” due to stability issues four times already. Just wait for 24.3 or 24.4 to be stable.
https://screenconnect.connectwise.com/download

TeamViewer 15.58.5 resolves several bugs and implements new cosmetics. This is a security update.
https://www.teamviewer.com/en-us/download/windows/

TestDisk 7.3 doesn’t provide a change log so should be treated as a security update.
https://www.cgsecurity.org/wiki/TestDisk_Download

XnConvert 1.101.0 doesn’t provide a change log so should be treated as a security update.
https://www.xnview.com/en/xnconvert/

Developer Updates

These are unlikely to be of interest to most people.

.NET Runtime 8.0.10 is a security update.
https://dotnet.microsoft.com/en-us/download/dotnet

Android Studio 2024.2.1.9 resolves dozens of bugs. This is not a security update.
https://developer.android.com/studio

GDevelop 5.4.213 adds ability to change opacity within properties panel, tilemap improvements, and resolves several bugs. This is not a security update.
https://gdevelop.io/download

GitHub Desktop 3.4.6 resolves several bugs. This is not a security update.
https://desktop.github.com/

Go 1.23.2 resolves several bugs. This is not a security update.
https://go.dev/

Node.js 20.18.0 updates libraries, resovles several bugs and adds experimental support for network inspection. This is not a security update.
https://nodejs.org/en/

Node.js 22.9.0 updates libraries, adds support for stack trace, disables V8, and resolves dozens of bugs. This is not a security update.
https://nodejs.org/en/

Python 3.13.0 resolves over a dozen bugs. This is a security update.
https://www.python.org/downloads/windows/

Visual Studio Code 1.94 improves Explorer Find, adds filtering options to Source Control Graph, and resolves several bugs. This is not a security update.
https://code.visualstudio.com/

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 7.1.2 is a major update, changing style, performance, stability, hardware compatibility and adding many options. It also initially broke older guests and this release fixes that as well as a dozen other bugs. This is not a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

Duplicator 1.5.11 improves compatibility and resolves several bugs. This is not a security update.
https://wordpress.org/plugins/duplicator/#developers

Sucuri Security 1.9.5 improves analysis. This should be treated as a security update.
https://wordpress.org/extend/plugins/sucuri-scanner/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/