Updates 2020-05-12

Welcome back, Folks!

Today is Patch Tuesday for May 2020.

The next build of Windows 10 will be released in only two weeks. If you don’t want to be the guinea pig I strongly suggest you update to v1909 as soon as possible if you’re running an older build. This will grant you a reprieve from the new version for a couple months. Let everyone else beta test and you can upgrade when they’ve worked out the bugs.

Furthermore, yesterday was the last day of support for commercial versions of Windows 10 prior to v1809 (build 17763). If you’re running an older version upgrade to v1909 ASAP to maintain security updates for your device.

This Month in Technology

Send a text, get root.

Even more bad news for Apple devices, as Google’s Project Zero has discovered “numerous new vulnerabilities” on all Apple hardware, and all Apple devices with Thunderbolt ports are vulnerable to an unpatchable security exploit.

But it’s not just Apple. Samsung is patching recent devices from their Galaxy line, though every Galaxy device they produced over the last 7 years is vulnerable to a similar “perfect 10” vulnerability in image parsing.

Ghost and LineageOS were hacked using known vulnerabilities in SaltStack that were left unaddressed. Fortunately it doesn’t look like any serious damage was done.

Pitney Bowes has been hacked again.

Watering holes (places that aggregate data from many accounts and services) will always be prime targets. If you’re not increasing your defense-in-depth posture at your watering hole, expect to be repeatedly violated. Ask LabCorp.

Government-approved monopolies are far too frequently granted exceptions others are not. PG&E, despite causing the fires that killed over a hundred people and destroyed over 25,000 homes and triggering the current insurance crisis in California, has had their $200 million fine waived.

Racists take aim at technology, banning the use of names of colors in the UK.

If you support the lockdown, is it because you hate science or just math?ย Face masks increase your risk, not the other way around. There’s no such thing as perfect safety.

I wonโ€™t try to make a distinction between the junk science you worship and actual science. Youโ€™re too far gone for that.

The lockdown is proving more lethal than the coronavirus as suicides exceed COVID-19 deaths in Australia.

Now for the good news:

A massive 10,000+ device botnet is dying out. Sadly, this isn’t one of the truly evil ones that was used for severe malicious actions, but rather just for downloading Anime.

Let’s Get Busy

Now back to our regularly scheduled program. Thanks to the unstopping barrage of updates pushed during “weekly update quarantine”, Patch Tuesday this month is not that bad. The typical computer should see roughly 1.2 GB in updates today. Let’s get started.

Microsoft released updates for Windows, .NET, Internet Explorer, Servicing Stack, and MSRT (~800 MB). This includes security updates. A reboot is required.

Adobe Flash Player 32.0.0.371 is a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Catalina (10.15) means that macOS Sierra (10.12) and older are no longer supported. If you can not install at least macOS High Sierra (10.13) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (1909) is a pretty small update so will install quickly. Windows 10 pushes you to get the latest Windows 10 release every 6 months. If you don’t let it finish and you’re on a slow connection, this process kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.8.95 is a security update. Use Menu, Help, About to install the most current version.
https://brave.com/

Google Chrome 81.0.4044.138 is a security update. Use Menu, Help, About to install the most current version.

Microsoft Edge 81.0.416.72 is a security update. Use Menu, Help, About to install the most current version.
https://www.microsoft.com/en-us/edge/business/download

Firefox 76.0.1 follows shortly after 76.0 which is a security update. 76.0.1 resolves several compatibility issues. Use Menu, Help, About to install the most current version.

Firefox ESR 68.8.0 is a security update. Use Menu, Help, About to install the most current version.

SeaMonkey 2.53.2 is a security update.
https://www.seamonkey-project.org/releases/

Vivaldi 3.0.1874.38 is a security update. Use Menu, Help, About to install the most current version.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 68.8.0 is a security update. Use Menu, Help, About to install the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

Trillian 6.3.0.4 resolves several bugs. This is not a security update.
https://www.trillian.im/

Npcap 0.9991 resolves several bugs and improves compatibility. This is not a security update.
https://nmap.org/npcap/

Zoom 5.0.24046.0510 improves local privacy. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

Picard 2.3.2 resolves several bugs and improves compatibility. This is not a security update.
https://picard.musicbrainz.org/

Game Updates

These are unlikely to be of interest to most people.

Nintendo Switch 10.0.2 resolves a pairing bug and improves stability. This is not a security update.

Tekkit Server 1.2.9i disables mod update checks resolving a crash bug. This is not a security update.
http://www.technicpack.net/modpack/tekkitmain

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Reader DC 20.009.20063 is a security update. Use Help, Check for updates to install the most current version.

Adobe Acrobat 2020.009.20063, 2017.011.30171, and 2015.006.30523 are security updates. Use Help, Check for updates to install the most current version.

Atom 1.46.0 resolves several bugs. This is not a security update.
https://atom.io/

Adobe DNG Software Development Kit (SDK) 1.5.1 is a security update.
Win: https://supportdownloads.adobe.com/product.jsp?product=120&platform=Windows
Mac: https://supportdownloads.adobe.com/product.jsp?product=120&platform=Macintosh

Security Software Updates

One or more of these is likely to be of interest to most people.

RogueKiller 14.4.2 resolves a crash bug and updates service. This is not a security update.
https://www.adlice.com/download/roguekiller/

TinyWall 3.0.4 resolves several bugs. This is not a security update.
https://tinywall.pados.hu/

Capture Updates

These are unlikely to be of interest to most people.

ScreenToGif 2.24 resolves several bugs and adds two-pass FFmpeg option. This is not a security update.
https://github.com/NickeManarin/ScreenToGif/releases/latest

SnagIt 2020.1.2 resolves several crash bugs and improves compatibility. This is a security update.
https://download.techsmith.com/snagit/enu/snagit.exe

Converter Updates

These are unlikely to be of interest to most people.

MKVToolnix 46.0.0 resolves several bugs. This is not a security update.
https://www.fosshub.com/MKVToolNix.html

HandBrake 1.3.2 resolves several bugs. This is not a security update.
https://handbrake.fr/

Utility Updates

These are unlikely to be of interest to most people.

1Password for Mac 7.5 adds password sharing by link, and resolves several bugs. This is a security update.
https://1password.com/downloads/mac/

DesktopOK 7.17 adds silent install support, resolves several bugs, and updates language files. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

Etcher 1.5.87 resolves several bugs and improves compatibility. This is not a security update.
https://www.balena.io/etcher/

GoodSync 11.1.8 improves compatibility. This is not a security update.
https://12pd.com/click?goodsync

IsMyHdOK 2.15 improves drive type detection. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

MS ISO Downloader 8.36 updates libraries and adds new disk images. This should be treated as a security update.
https://www.heidoc.net/joomla/technology-science/microsoft/67-microsoft-windows-and-office-iso-download-tool

OSFMount 3.0.1006 resolves several bugs. This is not a security update.
https://www.osforensics.com/tools/mount-disk-images.html

PointerStick 4.01 updates language files. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

PowerToys 0.17.0 adds native automatic update and updates FancyZones behavior. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

PSAppDeploy 3.8.2 resolves several bugs. This is a security update.
https://psappdeploytoolkit.com/

WifiChannelMonitor 1.60 updates the internal MAC addresses file. This is not a security update.
https://www.nirsoft.net/utils/wifi_channel_monitor.html

WinScan2PDF 5.33 improves WIA compatibility and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 3.6.3.0 resolves a caching bug. This is not a security update.
https://developer.android.com/studio

Node.js 14.2.0 improves error handling and monitoring with assertions, and resolves several bugs. This is a security update.
https://nodejs.org/en/

Visual Studio Code 1.45 improves accessibility, color, syntax, and semantic highlighting, performance, and GitHub integration. This is not a security update.
https://code.visualstudio.com/

Web Package Updates

These are likely to be of interest only to web developers.

OpenCart 3.0.3.3 replaces all PayPal extensions with PayPal Commerce platform. This is not a security update.
https://www.opencart.com/

Adminer 4.7.7 is a security update.
https://www.adminer.org/en/

OpenPetra 2020.04 resolves several bugs, adds Sponsorship module, improves initial setup and updates libraries. This is a security update.
https://www.openpetra.org/

Autoptimize 2.7.1 resolves several bugs. This is not a security update.

Social Post Feed 2.14.1 resolves a bug in notices. This is not a security update.

Postie 1.9.51 removes functions from logon screen. This is not a security update.

Redirection 4.7.2 resolves several bugs. This is not a security update.

NextScripts Social Networks Auto-Poster 4.3.15 improves compatibility. This is not a security update.

Top Commentators Widget 1.6 removes deprecated functions. This is not a security update.

WooCommerce 4.1.0 updates dependencies, resolves several bugs. This is a security update.

WP Mail SMTP 2.0.1 improves compatibility. This is not a security update.

Show IDs 1.1.4 improves compatibility with WordPress 5.4.1.

That’s all for now folks. Keep it clean out there. ๐Ÿ˜‰

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2020-04-30

We just had to get one last update cycle in for “the April that would never end.”

It’s not Patch Tuesday, but updates to OpenSSL have prompted security updates for almost every browser as well as application updates to many others have triggered an out-of-cycle update.

This Month/Week in Technology

If you can’t trust the CDC not to taint the tests, you can’t trust the SBA with your privacy in their loan process, you can’t trust Apple with your data, you can’t trust your “home automation” to not expose your entire home to hackers, you can’t trust the CIA not to abuse their authority in the mainstream media and academia, you can’t trust the FBI to follow their own rules when making requests of the secret FISA courts, you *really* can’t trust your antivirus software not to put you at even greater risk of exploitation, you can’t trust anyone not to reuse passwords, and you can’t trust advertising publishers to keep their ad platforms safe for their target audience, then why should you ever even consider giving Google and Apple 24/7, permanent, extensive monitoring of everywhere you go and everyone you ever have contact with? I don’t. Even if Apple and Google were above reproach (and they’re not), the inevitable abuse by any platform like this makes Orwell’s worst dreams look tame in comparison.

Now for the good news:

Intel has finally opened up their graphic drivers so you can use them on OEM hardware.

Let’s Get Busy

Apple released iOS 13.4.1 for iPhone SE (2nd generation) and watchOS 6.2.1 for Apple Watch Series 1 and 2. These are security updates. Use Settings, General, Software Update to install the most current version.

Fedora 32-1.6 provides several new features, now uses nftables by default, improves regular maintenance routines, and updates libraries. This is a security update.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If youโ€™re using this hardware โ€“ these updates are for you.

Display Driver Uninstaller 18.0.2.4 adds ability to remove only NVCP and resolves several bugs. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

Intel Driver and Support Assistant 20.4.17 resolves several bugs. This is not a security update.
https://www.intel.com/p/en_US/support/detect

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.8.86 is a security update. Use Menu, Help, About to install the most current version.

Google Chrome 81.0.4044.129 is a security update. Use Menu, Help, About to install the most current version.

Microsoft Edge 81.0.416.68 is a security update. Use Menu, Help, About to install the most current version.

Vivaldi 3.0.1874.33 is a security update. Use Menu, Help, About to install the most current version.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Mailspring 1.7.6 resolves several bugs. This is not a security update.
https://getmailspring.com/

OutlookAttachView 3.35 adds option to control Enter Key Action. This is not a security update.
https://www.nirsoft.net/utils/outlook_attachment.html

Internet Updates

One or more of these are likely to be of interest to everyone.

FileZilla Client 3.48.0 is a security update.
https://filezilla-project.org/

FreeFileSync 10.23 resolves several bugs. This is not a security update.
https://www.freefilesync.org/download.php

Google Earth 7.3.3 improves Street View, plus code support, and resolves several bugs. This is a security update.
https://earth.google.com/

WinSCP 5.17.5 is a security update.
https://winscp.net/eng/index.php

Zoom 5.0.23502.0430 improves encryption, abuse reporting, privacy controls, and resolves several bugs. This is a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

VLC Media Player 3.0.10 is a security update.
https://www.videolan.org/vlc/

Game Updates

These are unlikely to be of interest to most people.

Steam 2020.04.28 resolves several bugs. This is not a security update.
https://www.steampowered.com/platform/update_history/index.php?skin=0&id=0

Office Updates

One or more of these are likely to be of interest to most people.

LibreOffice 6.3.6 resolves 80 bugs. This is not a security update.
https://www.libreoffice.org/

Notepad++ 7.8.6 resolves several bugs. This is not a security update.
https://notepad-plus-plus.org/

Illustrator 24.1.2 is a security update.
https://www.adobe.com/creativecloud/catalog/desktop.html

Adobe Bridge 10.0.4 is a security update.
https://www.adobe.com/products/bridge.html

Security Software Updates

One or more of these is likely to be of interest to most people.

OpenSSL 1.1.1g is a security update.

RogueKiller 14.4.1 is a security update.
https://www.adlice.com/download/roguekiller/

Capture Updates

These are unlikely to be of interest to most people.

ScreenToGif 2.23.2 resolves a couple minor bugs. This is not a security update.
https://github.com/NickeManarin/ScreenToGif/releases/latest

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 11.0.8.6 adds support for new encodings, improves upscaling and enlarger. This is not a security update.
https://www.dvdfab.cn/download.htm

Utility Updates

These are unlikely to be of interest to most people.

Dell Command Update 3.1.2 is a security update.
https://www.dell.com/support/article/us/en/04/sln311129/dell-command-update?lang=en

RoboForm 8.7.0 resolves several bugs. This is not a security update.
https://12pd.com/click?rf

1Password for Windows 7.4.767 resolves several bugs. This is a security update.
https://1password.com/downloads/windows/

DesktopOK 7.01 adds command-line support, mapping support for alt-drag, and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

Easy2Boot 2.02 updates libraries, dependencies, and resolves a bug in Make USB. This is not a security update.
https://www.fosshub.com/Easy2Boot.html

Etcher 1.5.83 adds workflows to Flash from URL and improves the cosmetics. This is not a security update.
https://www.balena.io/etcher/

GoodSync 11.1.6 adds RDC tunneling support, explorer actions, account management improvements, and resolves several bugs. This is not a security update.
https://12pd.com/click?goodsync

MS ISO Downloader 8.35 adds support for new Windows, Office, and Dell images. This is not a security update.
https://www.heidoc.net/joomla/technology-science/microsoft/67-microsoft-windows-and-office-iso-download-tool

PSAppDeploy 3.8.1 adds Repair as action type, execute-process-as-user, several new features, compatibility improvements and bug fixes. This is not a security update.
https://psappdeploytoolkit.com/

Rufus 3.10 improves compatibility, device detection, updates drivers, and resolves several bugs. This is not a security update.
https://rufus.ie/en_IE.html

TeamViewer 15.5.3 adds message search, conditional access servers for fallback options, and resolves several bugs. This is not a security update.
https://www.teamviewer.com/en/download/windows/

WinScan2PDF 5.31 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

CPU-Z 1.92 adds support for new hardware. This is not a security update.
https://www.cpuid.com/softwares/cpu-z.html

NTLite 1.9.0.7455 adds new controls and resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

Coreinfo 3.5 doesn’t provide a changelog so should be treated as a security update.
https://live.sysinternals.com/

LiveKD 5.63 doesn’t provide a changelog so should be treated as a security update.
https://live.sysinternals.com/

Process Explorer 16.32 doesn’t provide a changelog so should be treated as a security update.
https://live.sysinternals.com/

Sysmon 11.0 adds file delete and archive monitoring, additional options to control behavior, improved log support and reliability improvements. This is not a security update.
https://live.sysinternals.com/

Developer Updates

These are unlikely to be of interest to most people.

Node.js 14.1.0 is a new major version adding several new features, libraries and bug fixes. Unfortunately, the previous build (14.0.0) broke stream support for many packages. This version resolves that bug. This is a security update.
https://nodejs.org/en/

Node.js 13.14.0 resolves several bugs. This is a security update.
https://nodejs.org/en/

Node.js 12.16.3 updates libraries. This is a security update.
https://nodejs.org/en/

Redemption 5.23.0.5664 adds support for in-memory objects, several new objects, collection-level assignments, and resolves several bugs. This is not a security update.
http://www.dimastr.com/redemption/

MySQL ConnectorNet 8.0.20 resolves several bugs. This is not a security update.
https://dev.mysql.com/downloads/connector/net/

Web Package Updates

These are likely to be of interest only to web developers.

WordPress 5.4.1 is a security update.
https://wordpress.org/

ScreenConnect 20.3.28091.7419 improves relay action scheduling, resolves several bugs. This is not a security update.
https://www.connectwise.com/software/control/download

Magento 2.3.4-p2, 2.3.5-p1, 1.14.4.5, 1.9.4.5 are security updates.
https://helpx.adobe.com/security/products/magento/apsb20-22.html#solution

Joomla 3.9.18 is a security update.
https://www.joomla.org/

HumHub 1.5.1 resolves several bugs. This is not a security update.
https://www.humhub.com/en/download

MailEnable 10.30 resolves several bugs. This is not a security update.
https://www.mailenable.com/

Nextcloud Server 18.0.4 resolves dozens of bugs and updates libraries. This should be treated as a security update.
https://nextcloud.com/

phpList 3.5.3 is a security update.
https://www.phplist.org/

YOURLS 1.7.9 improves compatibility, API signature algorithm, accessibility, and resolves several bugs. This is not a security update.
https://yourls.org/

Akismet 4.1.5 disables the notice and updates WP requirements. This is not a security update.

Antispam Bee 2.9.2 improves compatibility, and resolves several bugs. This is not a security update.

BuddyPress 5.2.0 is a security update.

Custom Facebook Feed 2.14 resolves several bugs. This is not a security update.

myStickymenu 2.4 resolves several bugs and adds font color control. This is not a security update.

Postie 1.9.50 improves diagnostics. This is not a security update.

W3 Total Cache 0.13.3 resolves a minification bug. This is not a security update.

WP Mail SMTP 2.0.0 changes PHP requirements (7+) and resolves several bugs. This is not a security update.

That’s all for now folks. Keep it clean out there. ๐Ÿ˜‰

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2020-04-14

Welcome back, Folks!

Today is the real Patch Tuesday for April 2020.

The next build of Windows 10 is just around the corner. If you don’t want to be the guinea pig I strongly suggest you update to v1909 as soon as possible if you’re running an older build. This will grant you a reprieve from the new version for a couple months. Let everyone else beta test and you can upgrade when they’ve worked out the bugs.

This Month in Technology

France content publishers have won a tiny victory against Google. The French competition authority now requires Google (and presumably other news publishers) to pay for republication rights when including a snippet of content. Google simply removed the snippet and now publishes only the title and URL.

A scale 10.0 vulnerability in VMWare has placed most corporate and cloud offerings at severe risk of data compromise.

The latest build of the Switch operating system now lets you move downloaded games to an SD card and remap buttons.

Mozilla’s new privacy-first stance doesn’t apply to their own new telemetry collection.

Now for the good news:

Commissioner Carr of the FCC points out that US internet speed are up 70% since the repeal of Net Neutrality.

Let’s Get Busy

Now back to our regularly scheduled program. Thanks to the unstopping barrage of updates pushed during “weekly update quarantine”, Patch Tuesday this month is pretty light. The typical computer should see roughly 900 MB in updates today. Let’s get started.

Microsoft released updates for Windows, Internet Explorer, and MSRT (~600 MB). This includes security updates. A reboot is required.

Apple released updates for macOS Catalina 10.15.4 and watchOS 6.2.1. This includes security updates. Use Apple Software Update to install the most current versions. Be aware that the 10.15.4 update is known to brick some Apple hardware, so I recommend waiting for 10.15.5, due in about 10 days.

watchOS 6.2.1 is a security update. Use the Watch app on your iPhone to install the most current version.

Adobe Flash Player 32.0.0.363 is a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Catalina (10.15) means that macOS Sierra (10.12) and older are no longer supported. If you can not install at least macOS High Sierra (10.13) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (1909) is a pretty small update so will install quickly. Windows 10 pushes you to get the latest Windows 10 release every 6 months. If you don’t let it finish and you’re on a slow connection, this process kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Browser Updates

One or more of these are likely to be of interest to everyone.

Microsoft Edge 81.0.416.53 is a security update. Use Menu, Help, About to install the most current version.
https://www.microsoft.com/en-us/edge/business/download

Brave 1.7.92 is a security update.
https://brave.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 68.7.0 is a security update. Use Menu, Help, About to install the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

Zoom 4.6.20559.0413 is a security update. Click the user icon, Check for updates to install the most current version.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

Unreal Media Server 14.0 adds support for live HEVC (h265) video, output to UMS and MPEG2-TS players, streaming HTML5 video elements, and resolves several bugs. This is not a security update.
http://www.umediaserver.net/umediaserver/download.html

Office Updates

One or more of these are likely to be of interest to most people.

Artweaver 7.0.5 improves hardware compatibility, and resolves several bugs. This is not a security update.
https://www.artweaver.de/

IcoFX 3.4 improves hostory and semitransparent export, and resolves several bugs. This is not a security update.
https://icofx.ro/

Adobe ColdFusion 2016.15 and 2018.9 are security updates.
https://helpx.adobe.com/coldfusion/kb/coldfusion-2016-update-15.html
https://helpx.adobe.com/coldfusion/kb/coldfusion-2018-update-9.html

Adobe After Effects 17.0.6 is a security update. Use Creative Cloud Desktop to install the most current version.

Adobe Digital Editions 4.5.11.187303 is a security update.
https://www.adobe.com/solutions/ebook/digital-editions/download.html

Adobe Camera Raw 12.2.1 doesn’t provide a changelog and download links don’t work. It could be a security update, but doesn’t look like it’s actually available yet.

Adobe DNG Converter 12.2.1 adds support for newer hardware. This is not a security update.
https://supportdownloads.adobe.com/detail.jsp?ftpID=6913
https://supportdownloads.adobe.com/detail.jsp?ftpID=6915

Security Software Updates

One or more of these is likely to be of interest to most people.

IISCrypto 3.2 adds a Protocols Enabled control. This is not a security update.
https://www.nartac.com/Products/IISCrypto/Default.aspx

Capture Updates

These are unlikely to be of interest to most people.

ScreenToGif 2.23.1 resolves a relative path bug. This is not a security update.
https://github.com/NickeManarin/ScreenToGif/releases/latest

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 11.0.8.4 adds support for new encodings, performance improvements, and improved scaling with newer hardware. This is not a security update.
https://www.dvdfab.cn/download.htm

Utility Updates

These are unlikely to be of interest to most people.

DesktopOK 6.93 improves Tools. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

GoodSync 10.11.5 resolves several bugs. This is not a security update.
https://12pd.com/click?goodsync

TeamViewer 15.4.8332 doesn’t have a published changelog so should be treated as a security update.
https://www.teamviewer.com/en/download/windows/

Developer Updates

These are unlikely to be of interest to most people.

Visual Studio Code 1.44 improves accessibility, adds preserved undo/redo beyond application closure, remote checkout into containers, timeline view, settings sync and more. This is not a security update.
https://code.visualstudio.com/

Java 8u251 is a security update. If you are not 110% sure you require Java, it’s best to remove it. Java and JavaScript are not the same thing and few desktop applications actually require Java.
https://www.java.com/en/download/manual.jsp

Web Package Updates

These are likely to be of interest only to web developers.

myStickymenu 2.3.9 fixes a bug in the notification bar. This is not a security update.

Postie 1.9.46 resolves a notification bug. This is not a security update.

That’s all for now folks. Keep it clean out there. ๐Ÿ˜‰

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2020-04-01

Happy April Fools’ Day, Folks!

It’s not Patch Tuesday, but updates from Microsoft, Apple, Google, and others have triggered an out-of-cycle update.

This Month/Week in Technology

The FCC announced that by July 2021 every US phone company (landline and mobile) must adopt STIR/SHAKEN which will massively reduce the amount of robocalls and phone spam people receive and ensure that call blocking features work as intended.

Microsoft has rebranded Office 365 to Microsoft 365 and is launching more features and cross-platform monitoring across the system. Is this the next step towards Windows-as-a-Service?

Dell and HP Enterprise have issued updates for the runtime bug in certain Enterprise solid-state drives (SSDs) that will begin bricking them in only a couple months.

The latest to jumping on the virus-free-trial bandwagon is Plex.

The country of Georgia has been hacked, with data on almost every citizen being posted online.

How bad are companies at dealing with ransomware? Most corporations and governments just give in and negotiate the ransom. Others pay insurance through companies like Chubb, a cyber-insurer for this type of thing. Can a company insure itself?

For a couple days, the latest builds of iOS and macOS wouldn’t let you search for a “+” sign. This is more common than you might think, and one of the pieces of advice in my Selecting the Perfect Domain” guide.

#3 Don’t use any strange characters

CloudFlare’s 1.1.1.1 public DNS resolver received glowing marks in a recent study. While it’s very private and fast, it doesn’t provide built-in security as does OpenDNS, though.

Now for the good news:

Even the scientist most cited for his chicken-little response to COVID-19 has reversed course and said he over-estimated lethality and virulence.

Let’s Get Busy

Microsoft released an out-of-cycle update to address connectivity problems for VPN users. If you’re using a VPN, use Windows Update to install the most current version.

Apple released security updates for iCloud for Windows 7.18 and iCloud for Windows 10.9.3. Use Apple Software Update to install the most current versions.

Google Chrome OS 80.0.3987.158 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If youโ€™re using this hardware โ€“ these updates are for you.

Display Driver Uninstaller 18.0.2.3 improves cleanup. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

Browser Updates

One or more of these are likely to be of interest to everyone.

Google Chrome 80.0.3987.162 is a security update. Use Menu, Help, About to get the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

WinSCP 5.17.3 is a security update.
https://winscp.net/eng/index.php

Game Updates

These are unlikely to be of interest to most people.

Steam 2020.03.26 resolves several bugs. This is not a security update.

PlayStation PS3 4.86 improves system performance. This is not a security update.
https://www.playstation.com/en-us/support/system-updates/ps3/

Office Updates

One or more of these are likely to be of interest to most people.

Krita 4.2.9 adds Airbrush and Ratio controls to the Color Smudge brush, and resolves 70 bugs. This is not a security update.
https://krita.org/en/download/krita-desktop/

Security Software Updates

One or more of these is likely to be of interest to most people.

RogueKiller 14.4.0 resolves several bugs, improves compatibility and adds warnings to certain scans.
https://www.adlice.com/download/roguekiller/

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 11.0.8.2 adds support for new encodings. This is not a security update.
https://www.dvdfab.cn/download.htm

Utility Updates

These are unlikely to be of interest to most people.

RoboForm 8.6.8 improves data synchronization, Windows Hello integration, and resolves several bugs. This is not a security update.
https://12pd.com/click?rf

GoodSync 10.11.4 resolves several bugs and improves compatibility. This is not a security update.
https://12pd.com/click?goodsync

DesktopOK 6.91 improves compatibility with the next build of Windows. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

NetworkInterfacesView 1.20 adds option to open device properties window with F2. This is not a security update.
https://www.nirsoft.net/utils/network_interfaces.html

PSAppDeploy 3.8.1 adds Repair action and new installation controls, and resolves several bugs. This is not a security update.
https://psappdeploytoolkit.com/

MS ISO Downloader 8.34 adds several new ISOs. This is not a security update.
https://www.heidoc.net/joomla/technology-science/microsoft/67-microsoft-windows-and-office-iso-download-tool

WinScan2PDF 5.25 resolves a TWAIN bug under Windows 10 x64. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 3.6.2.0 resolves over a dozen bugs. This is not a security update.
https://developer.android.com/studio/index.html

Node.js 13.12.0 improves build notarization for macOS, upgrades libraries, adds option to disable proto to CLI, moves diagnostic reports to stable, and now allows URL in worker constructor. This is not a security update.
https://nodejs.org/en/

Web Package Updates

These are likely to be of interest only to web developers.

OpenPetra 2020.03 resolves the PDF printing bug, as well as several other bugs. This is not a security update.
https://www.openpetra.org/

WordPress 5.4 improves the block editor, adds Social Icons and Buttons, gradients to Buttons and Cover block, color options to Group, Columns, and Rich Text, improved consistency, as well as many developer and privacy improvements. This is not a security update.
https://wordpress.org/

Postie 1.9.45 resolves an email notification bug. This is not a security update.
https://wordpress.org/extend/plugins/postie/

Custom Facebook Feed 2.13 adds a Block. This is not a security update.
https://wordpress.org/extend/plugins/custom-facebook-feed/

That’s all for now folks. Keep it clean out there. ๐Ÿ˜‰

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2020-03-24

Hi, Folks!

It’s not Patch Tuesday, but security updates from Apple, Adobe, Google, and many others have triggered an out-of-cycle update.

This Month/Week in Technology

NPM is joining Github. Cool.

Apple was fined $1.2 billion by French antitrust authorities. And you thought the next iPhone was going to be expensive yesterday? They’ll be rolling the expense of the antitrust settlement into your next iDevice.

Security is all about trust. The thing to remember is that just because something claims to be a security application or service doesn’t mean it is. Antivirus and VPNs are no exception. By the way, if you’re still using Avast, you may as well just send your passwords out to random email addresses along with all your other personal data.

Content Delivery Networks (CDNs) are critical for scalable web distribution. Unfortunately, this makes them prime targets for malware distribution as well.

Salesforce customers will soon no longer be able to use Data Backup Recovery. Consider this a reminder that while the cloud might store everything, it’s not always easy to get it back when you’ve lost it.

The US Department of Defense is glacially slow (8+ years) at fixing security issues. Don’t say you weren’t warned. In their wisdom, the FBI says you shouldn’t save your passwords in your browser. Duh.

Even if you don’t, however, your data is stored by most other entities you interact with. For example, every 10 years the US performs the Census and collects a wide variety of information about every household in the country. When the US Census Bureau data is hacked you can find that data online, too. But that’s not even the worst of what’s wrong with the Census this year. Their website uses a script that performs a unique fingerprint of every single device that connects to their site and attempts to load various sensor features to further profile and access features of the device. Coupled with the “unique” login you use when filling out the Census your online activity can be permanently tied to your devices. And yes, this is the same organization that had a major data leak earlier in this paragraph.

The Internet of Things (IoT) is much less secure than you may have thought, no matter how bad you thought it was. 98% of their traffic is sent unencrypted, more than half of devices suffer from critical vulnerabilities that will likely never be patched, IoT devices are often used as a foothold to gain access to your internal networks, and hospitals are some of the worst offenders for employing insecure and unmaintained IoT devices.

Is it any wonder that the Russian FSB was developing an IoT botnet? Another FSB contractor was hacked and their tools were released in much the same way as the CIA Vault7 hack.

Now for the good news:

Comcast has made their public Wi-Fi hotspots available free to everyone and has removed data caps for the next 60 days as a result of the current pandemic. Just make sure you’re using a VPN. ๐Ÿ™‚

Let’s Get Busy

Apple released updates for macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra, Xcode 11.4, Safari 13.1, watchOS 6.2, watchOS 5.3.6, tvOS 13.4, iOS 13.4, iPadOS 13.4, iOS 12.4.6, and iTunes 12.10.5 for Windows. These are security updates. Use the Apple App Store or Apple Software Update to install the most current versions.

iOS 13.4 and 12.4.6 are security updates. Use Settings, General, Software Update to install the most current version.

watchOS 6.2 and 5.3.6 are security updates. Use your updated iPhone to install the most current version through the Watch app.
https://support.apple.com/en-us/HT204641

tvOS 13.4 is a security update. Use Settings, General, Updates to install the most current version.

Adobe Flash Player 32.0.0.344 is a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If youโ€™re using this hardware โ€“ these updates are for you.

nVidia 442.75 resolves several compatibility issues and adds app/game profiles. This is not a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.5.113 is a security update. Use Menu, Help, About to install the most current version.
https://brave.com/

Google Chrome 80.0.3987.149 is a security update. Use Menu, Help, About to install the most current version.

Vivaldi 2.11.1811.49 is a security update. Use Menu, Help, About to install the most current version.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 68.6.0 is a security update. Use Menu, Help, About to install the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

BrowsingHistoryView 2.40 adds a new date/time filter. This is not a security update.
https://www.nirsoft.net/utils/browsing_history_view.html

FileZilla Client 3.47.2.1 resolves several bugs. This is not a security update.
https://filezilla-project.org/

FreeFileSync 10.22 resolves several bugs. This is not a security update.
https://www.freefilesync.org/download.php

Npcap 0.9989 resolves several bugs. This should be treated as a security update.
https://nmap.org/npcap/

Prosody 0.11.5 adds foreground/background flags to replace daemon functionality. This is not a security update.
https://prosody.im/download/start

Media Updates

These are unlikely to be of interest to most people.

iTunes 12.10.5 is a security update. Use Apple Software Update to install the most current version.

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Reader DC 20.006.20042 is a security update. Use Help, Check for Updates to install the most current version.

Adobe Creative Cloud Desktop?5.1 is a security update.
https://www.adobe.com/creativecloud/catalog/desktop.html

Adobe Bridge 10.0.3 is a security update.
https://www.adobe.com/products/bridge.html

Adobe ColdFusion 2016.14 and 2018.8 are security updates.
https://helpx.adobe.com/coldfusion/kb/coldfusion-2016-update-14.html
https://helpx.adobe.com/coldfusion/kb/coldfusion-2018-update-8.html

Adobe Experience Manager 6.3.3.8, 6.4.8.0, and 6.5.4.0 are security updates.
https://helpx.adobe.com/experience-manager/aem-releases-updates.html

Adobe Photoshop 20.0.9 and 21.1.1 are security updates. Use Adobe Creative Cloud Desktop to install the most current versions (after you patch it).

Adobe Acrobat 2020.006.20042, 2017.011.30166, and 2015.006.30518 are security updates. Use Adobe Creative Cloud Desktop to install the most current versions (after you patch it).

Adobe Genuine Integrity Service 6.6 is a security update. AdobeGCClient does not have a separate installer or updater, and will update as you patch other programs.

Atom 1.45.0 resolves several bugs and updates libraries. This should be treated as a security update.
https://atom.io/

LibreOffice Fresh 6.4.2 resolves over 90 bugs. This is a security update. LibreOffice Fresh is a beta version, and should be avoided for most users.
https://www.libreoffice.org/

Security Software Updates

One or more of these is likely to be of interest to most people.

RogueKiller 14.3.0 updates libraries, improves reliability and scanning behaviors. This is a security update.
https://www.adlice.com/download/roguekiller/

Capture Updates

These are unlikely to be of interest to most people.

ScreenToGif 2.22.1 resolves a couple bugs and updates translations. This is not a security update.
https://github.com/NickeManarin/ScreenToGif/releases/latest

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 11.0.8.1 adds support for new encodings, improves compatibility, and resolves a couple bugs. This is not a security update.
https://www.dvdfab.cn/download.htm

Utility Updates

These are unlikely to be of interest to most people.

1Password for Windows 7.4.759 resolves several bugs and improves compatibility. This is not a security update.
https://1password.com/downloads/windows/

CurrPorts 2.61 resolves a state-monitoring bug. This is not a security update.
https://www.nirsoft.net/utils/cports.html

Etcher 1.5.80 resolves several bugs and updates electron. This should be treated as a security update.
https://www.balena.io/etcher/

Everything 1.4.1.969 improves stability. This is not a security update.
https://www.voidtools.com/

Fing 9.0.0 adds several new feature shortcuts and an Account tab. This is not a security update.
https://community.fing.com/

GoodSync 10.11.2 resolves several bugs. This is not a security update.
https://12pd.com/click?goodsync

IsMyHdOK 2.11 updates language packs and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

TeamViewer 15.4.4445 resolves several bugs and adds the tvopt file format for setting portability. This is not a security update.
https://www.teamviewer.com/en/download/windows/

WSUS Offline 12.0 removes support for Windows 7, Windows Server 2008 R2, Win10 v1703, splits Win10 updates to versioned folders for future updates, and updates supercedence values. This is not a security update.
https://download.wsusoffline.net/

Developer Updates

These are unlikely to be of interest to most people.

Inno Setup 6.0.4 improves compatibility, Restart Manager, and RTF, adds Dark Theme, several fixes and HTTPS on the website. This is not a security update.
https://www.jrsoftware.org/isdl.php

Node.js 13.11.0 updates libraries, improves compatibility, and resolves several bugs. This is not a security update.
https://nodejs.org/en/

StrawberryPerl 5.30.2.1 updates libraries, improves compatibility, and resolves several bugs. This is a security update. You probably shouldn’t be using StrawberryPerl though, since they still aren’t using HTTPS even though they can get it free through LetsEncrypt. Sad.
http://strawberryperl.com/

Web Package Updates

These are likely to be of interest only to web developers.

Drupal 8.8.4 is a security update.
https://drupal.org/download

HumHub 1.4.4 resolves several bugs. This is not a security update.
https://www.humhub.com/en/download

phpMyAdmin 4.9.5 is a security update.
https://www.phpmyadmin.net/

Nextcloud Server 18.0.3 is a security update.
https://nextcloud.com/

phpList 3.5.1 updates libraries and resolves several bugs. This is a security update.
https://www.phplist.org/

Connectwise Control 20.2.27450.7387 resolves several bugs. This is not a security update.
https://www.connectwise.com/software/control/download

Akismet 4.1.4 improves compatibility and activation process. This is not a security update.

Custom Facebook Feed 2.12.4 improves compatibility and resolves several bugs. This is not a security update.

myStickymenu 2.3.8 improves compatibility, reduces announcement nag frequency, and allows custom HTML within notification bar. This is not a security update.

Postie 1.9.44 refactors code for separation of purpose and adds an action for registering shortcodes.

Redirection 4.7.1 resolves several bugs. This is not a security update.

WooCommerce 4.0.1 improves Action Scheduler and resolves several bugs. This is not a security update.

WP Mail SMTP 1.9.0 adds several troubleshooting features, improves documentation, About, and warns when settings are not saved. This is not a security update.

That’s all for now folks. Keep it clean out there. ๐Ÿ˜‰

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/