Updates 2025-03-11

Happy St. Patrick’s Day, Folks!

Today is Patch Tuesday for March, 2025.

It’s as safe as it’s going to be to upgrade to Windows 11 24H2 or macOS 15/Sequoia.

If your Windows 10 (or older) computer can not be upgraded to Windows 11, or if you used a registry or installation bypass to install an older version of Windows 11 on it that is no longer supported, then it’s time for you to start looking for a replacement computer. Actually, the time was 6 weeks ago. Pickin’s are thin right now. 🙁

There were 575+ major hacks, and over 300 application updates this month. Even so, it’s a relatively minor month, with about 2.5 GB of updates for most users.

This Month in Technology

1inch, 1X Internet, 365labs, Access2Jobs, 49,000 Access Management Systems AMS), ACDC Express, Acqua Development, ACTi Corporation, Adrenalina, Adval Tech, Advantage Home Construction Insurance, Aeonsparx, AJ Taylor Electrical Contractors, Alabama Ophthalmology Associates, Albion Online, Alf DaFrè, All4Labels, Allied Tenesis, AllTrust, Allworx, Ally Financial, Almost Famous Clothing, Amalgamated Sugar, Amerman Ginder, an American political action committee (PAC), Andover Family Medicine, Android, Angel One, Anne Arundel County, Apache Atlas, Apache EventMesh, Apache Ignite, Apache Pinot, Apache Tomcat, ¡appa!, Apparel Group, Apple Safari, Archie Cochrane Ford, Arcusin, Armed Forces of the Philippines, Artistic Family Dental, Ashlar-Vellum Cobalt, Aspire Rural Health System, Aurora Boardworks, Aurora Public Schools, Australian National University, Autodesk Navisworks, Autohaus Kießling, Autoschade Pippel, Avery Products Corporation, Aya Healthcare, Azamara Cruises, Baltimore Country Club, Bangladesh Navy, Bank of America, Barhite & Holzinger Inc, Bassford Remele PA, Bay Cove Human Services, Belgium State Security Service (VSSE), Bell Ambulance, BeniPlus, Benjamin Consulting Services, Benton Police Department, Berg Engineering Consultants, Berkeley Research Group, Best Collateral, Bethany Lutheran Church, Better Auth, BH Aircraft Company, Biagi Bros, Inc, Bikur Rofeh, Birch Medical LLC, Birdsall Muller LLC, Bis Industries, Black Basta ransomware gang, Black Star, BluAgent Technologies, Blue & Co, Blue Planet, Blue Shield of California, Bosowa Berlian Motor, Boys and Girls Clubs of the Tennessee Valley, British Virgin Islands London Office, Bulgaria’s Supreme Administrative Court, Bulldog Oilfield Services, Bulverde Glass, Burdick Painting, Burlington Hydro, Bybit, Cache Valley ENT, Cafe Zupas, Callico Distributors, Cardiology of Virginia, Carolina Arthritis Associates, Carruth Compliance Consulting, Castle Rock Construction, CCL Products India, CCT Technologies, CDS in Texas, Central District Health Department, Central New York Cardiology, Central Texas Pediatric Orthopedics, Charleston Area Medical Center, Chicago Doorways, Chicago Public Schools, Chimu Agropecuaria, Ciba Cobertura Medica, City of McKinney, City Of Roseburg, City of Tarrant, City of Van, Turkey, City Plumbing & Electric Supply, Claris Vision Holdings, Clawson Honda, Cleveland Municipal Court, Cocospy, Color Dating, Colorado River Adventures, Columbus Division of Fire, Comercializadora S&E Perú, Command & Conquer Generals: Zero Hour, Community Care Alliance, Commvault Webserver, Compound Solutions, Connekted, Consultants in Pain Medicine, Convert Solar, Couri Insurance Agency, CPS Solutions, Craft CMS, Crayfish, Cricadda, Cronos Europa, Crossroads Trading Company, Cyncly Company, Dacas Argentina, Daniels Homes, Datavant Group, Delta Electronics CNCSoft-G2, Delta Electronics ISPSoft, Detroit PBS, Digital Technology Co, Dinizulu Law Group, DISA Global Solutions, Django, DocsGPT, DOGE, Donna G Rogers, CPA, Doxbin, DRClaims FL, Dynamic Closures, DZL, EAC Consulting, Edesur Dominicana, Edimax IC-7100 IP, El Corte Inglés, Elastic Kibana, Elite Advanced Laser Corporation, Endless Mountains Health Systems, Engikam, Erie Management Group, Essex County OB/GYN Associates, Euranova, Ewald Consulting, Executive Agenda, EzyLegal, F&V Capital Management, Fairhaven Shipyard Companies, FANTIN group, Fickling & Company, Fillmore County Hospital, Financial Services of America, Finastra, Finck Cigar, First Defense Fire Protection, First Federal Savings & Loan, Flat Earth Sun, Moon and Zodiac App, Flightsim Studio, FlowiseAI, Fort St. John, Fortinet FortiWeb, Franklin County, Friendship House, FTECH R&D, G&M Direct Hire, G&S Electric LLC, Gala Tech, Garantex, Genea, Georgian Government, GitLab, Goldstein Law Group, Google Chrome, Google Chrome extension platform, Government of Brazil, Government of Pakistan, Grafitec, Greencastle-Antrim Senior High School, Greenwood Village South, Gregory & Appel Insurance, Grubhub, Grupo Baston Aerossol, GS Retail, Haggin Oaks Golf, Hall Law Group, Hammond Trucking & Excavation, Hancock Public School, Hanson Cold Storage, Hatolna, HCRG Care Group, HealthRev Partners, LLC, Heartland Health Center, Help Me Grow Yolo, Heritage South Credit Union, Hewlett Packard, Hewlett Packard Enterprise, Hickory Law, Hillcrest Convalescent Center, Inc, Hipshipper, Hirsch Enterphone MESH, Hisingstads Bleck, Holiday Comfort Inn, Hollandia Dairy, Home Assistant, HomeTeamNS, Houston Symphony, HP LaserJet Pro MFP 3301fdw, Humboldt Independent Practice Association, iCloud, Indian Ministry of Culture, INDIC Electronics, Indonesian Firefighting Services, Infini, InfoReach, Inland Empire Distribution Systems, Innovative Renal Care, Insight Partners, Insyst GmbH, Interjet, INTERLINK Health Services, Internet Corporation for Assigned Names and Numbers (ICANN), 86,000 Internet of Things devices, InternetWay, Inversiones Clinica Del Meta, InvestHK, Investing.com, IRS, Island Realty, IT-IQ Botswana, Italian Government, iTP Partners, Ivanti Connect Secure (ICS), Ivanti Endpoint Manager, Ivanti Policy Secure (IPS), Ivanti Secure Access Client (ISAC), Jaguar Land Rover, Jaime Schwartz MD, Jefferson Elementary School District, Jerue Companies, Jewish Child Care Association of New York, Jildor Shoes, Johnson’s Nursery, JP Express, Juniper Networks Session Smart Router (SSR) devices, Kelsey-Seybold Clinic, Kendall Auto Group, Kensington Glass Arts, Keystone Pacific Property Management, Kings River Union Elementary, Klesk Metal Stamping, Krisala Developer, Krispy Kreme, Kronick Moskovitz Tiedemann & Girard, Kuwaiti Government, Kyocera International, Inc, La Unión, Label Studio, LandAirSea, LANIT, Laravel, Las Cruces, Laurens School District 56, Law Diary, Leadership Strategies, Leading Edge Specialized Dentistry, Leantime, Leeds United, Legacy Professionals, Legal Aid Society of Salt Lake, Lexmark, Lietvaris, Ligentia, LINKGROUP, LINTEC & LINNHOFF Holdings, Linux Kernel, Lost & Found, Loyola University Maryland, LRT, Lucee, Lucent Health Solutions, Lumen Technologies, Luminus Management, M-1 Toolworks, Mac Jee, Mackay Memorial Hospital, Magnolia Manor, Mainline Information Systems, Makai, Manning Publications, Mars Hydro, Martin Energy Group Services, Matagorda County, Medefer, Medusind, Inc, Meet and Chill, Memorial Hospital and Manor, MercadoLibre, Mercury Paper Inc, Mercy Supply, Merkanti Bank, Meta E2 F, Metro Supply Chain Group, Metropolitan Borough of Gateshead, Microsoft Edge, Microsoft Sharepoint, Microsoft Windows Debugger, Microsoft Windows Installer Service, Microsoft Windows KDC Proxy, Microsoft’s partner website, Minaris Medical America, Ministry of Agriculture, Indonesia, Ministry of Defence, India, Ministry of Foreign Affairs, Ukraine, Ministry of Health of Palau, Minnesota Exteriors, Minnesota Orthodontics, Mission, Texas, Missouri Department of Conservation, MITRE Caldera, MNJ Technologies Direct, Monroe Transportation Services, Moodle, Mosley Glick O’Brien, MOVITOOLS MotionStudio, Moxa PT Switches, MTN Group, Muller Insurance, Mundelein Park & Recreation District, My New Jersey Dentist, mySCADA, Naphix, Naples Heritage Golf & Country Club, NASCAR, National AirVibrator, National Presto Industries, Navien, NBA, Neaton Auto Products Manufacturing, Nebraska Irrigation, Nelson & Townsend, CPA’s, Neopoly, Netcom-World, New Era Enterprises, Inc, New Era Life Insurance Companies, Newton & Associates, Next TI, NHS Tayside, NI DAQExpress, Nichino Ryokka Co, NioCorp Developments Ltd, Nippon Steel, Niva Bupa, North American Fire Hose, Northern Management, NorthWest Arkansas Community College, Novi Community School District, NTT Communications Corporation, Numotion, Nuna Baby Essentials, NVIDIA Container Toolkit, NVW Newco, LLC, Oberlin Cable Co-op, Obex Medical, Omni United, Ondunova, Openreso, OpenSSH, Orange Group Romania, Ottawa Family Physicians, Oxidized Web, PACE, Pacific Honda Company, Pacific Rehabilitation Centers, Paddington Bear, PAN-OS firewalls, Paragon Partition Manager, Parallels Desktop, Paratus, Park Place Pediatric Dentistry, payapps.com, Paysera, PDF-XChange Editor, Pebble, Pedensia Graphics Distribution, Penn-Harris-Madison, Perrin Performance, Persante Health Care, Pervedant, Peter Glenn Ski Sport, Petstop, Phoenix Rehabilitation and Nursing Center, Polish Space Agency (POLSA), Portland Schools, PostgreSQL, PostHog ClickHouse, Pound Road Medical Centre, Power Pages, PPS Services Group, Praxis Eins, Precision Orthopedics and Sports Medicine, Primary Health-SMMPP & U.S. HEALTHWORKS-SMMPP, Princeton Hydro, PS, Pump.fun X account, QBurst, Quality Home Health Care, Radco Industries, Rainbow District School Board, Ray Fogg Corporate Properties, Raymond Lifestyle, Raymond Limited, RCDPRO, Reading Cooperative Bank, Reddit, Regency Media, Rennes University, Renton School District, Restorix Health, RFA Decor, Riverdale Country School, Rivers Casino Philadelphia, a prominent Riyadh-based real estate and construction firm, RJ IT Solutions, ROCK SOLID Stabilization & Reclamation, Roswell Park Comprehensive Cancer Center, Rowe Tactical, Rubrik, Ruby on Rails, RxSight, RZD, S3-Proxy, Safe-Strap Company, Saracen Properties, Sault Ste. Marie Tribe of Chippewa Indians, Schmiedetechnik Plettenberg GmbH & Co, SCLARC, Scott County, Iowa, Scottish Qualifications Authority, Seabank Group, Semyonishna, Shetland Islands Council, Shields Facilities Maintenance, Shinn Fu Company of America, Siegel Group, Signal, SimonMed Imaging, Sittab, SMC Corporation of America, Soco Systems, Solar Data Systems, SolarWinds, Somnia, SonicWall firewalls, Sorare, Sorbonne University, South African Weather Service, SPEED Co, Spring Management OK, LLC, Spyic, Spyzie, SSK Plastic Surgery, St. Andrew’s Resources for Seniors System, Star Solution Services, State Bar of Texas, Stateside Seattle, Sterling BMW, Storenvy, Story Environmental, Stram Center for Integrative Medicine, StubHub, Sublette County, WY, Summit Home Health, Sunflower Medical Group, PA, Sunnking Sustainable Solutions, SushiCo, Synelixis Solutions, System Pavers, T J Machine & Tool, T-Mobile, TensorFlow, Thai Metal Aluminium, The Agency, The Grove at Valhalla Rehabilitation and Nursing Center, The Northwestern Illinois Association, The Pension Specialist, The Phoenix Rehabilitation and Nursing Center, The Siegel Group, The Smeg Group, The Townsley Law Firm, Therma Seal Insulation Systems, Thong Sia, Thornton Engineering, Tie Down Engineering, TikTok, Title 9 Sports, Inc, TOT Mobile, Town Counsel Law & Litigation, TP-Link routers, Transak, Transkid, Trident Maritime Systems LLC, Trimble SketchUp, Tugwell Pump & Supply, Turning Point of Central California, UFCW Local 135, Unimicron, United Community Health Center, US Coast Guard, US Dept Of Defense, US Dept of Housing and Urban Development (HUD), Utsunomiya Central Clinic, Vector Engineering, VectraRx Mail Pharmacy Services, Vela Server, Vermeer Mexico, Versant Technologies, Via Credit Union, Vicky Foods, Virginia Attorney General’s office, Vičiūnai Group, VMware ESX, Volt, Vue, Wayne County, Michigan, WDNA, Webex for BroadWorks, Weed Man Canada, Wendy Wu Tours, Whitman Hospital & Medical Clinics, Wilkinson Rogers, Williamsburg-James City Schools, Window World of Raleigh, WJCC Public Schools, Woman’s Athletic Club of Chicago, WordPress Chaty Pro plugin, WordPress Essential Addons for Elementor plugin, WordPress Jupiter X Core plugin, Workforce Group, Wylie Steel Fabricators, Xactus, Xen hypervisor, Xerox VersaLink C7025, XWiki, Yahoo, Yorke & Curtis, YouTube, Zacks Investment Research, Zimbra, ZITADEL, zkLend, and Zurich Insurance have reported hacking or compromises this month.

Flight Radar 24,Mastercard, Microsoft 365, Outlook.com, X/Twitter, and ZServers/XHost (yay!) have suffered from outages this month.

Last months updates broke AutoCAD 2022, Classic Outlook (again), Microsoft 365, Outlook Drag & Drop, Windows 11 SSH, and Windows Server 2025. Microsoft did release an out-of-cycle BIOS update to fix crash bugs in ASUS devices that has persisted since October.

In other news…

Apple’s AI sucks at transcription. And they’ve disabled end-to-end encryption for users in the UK.

Microsoft is never going to give up trying to get your files into OneDrive so they can use them to feed their AI. After this, their next step will be to “accidentally” turn it on in a month or two then apologize for it later. “Oops.” Microsoft has announced they’re killing off Skype in only a couple months. An ad-supported version of Microsoft Office/365 is currently in beta.

Microsoft accounts are being targeted by an insane “password spraying” attack over the last month or so. Due to the way their authentication works, where all it takes is your email address to send you an email or text with a passcode to log you in, it’s resulting in hundreds or even thousands of messages to Microsoft account holders with these one time pin numbers.

As Microsoft launches their new 24/7 screen capture and content collection service, Recall, they are removing the Location History feature in Windows.

Many websites are now “fingerprinting” your browser to uniquely identify “you” – and the net effect is that it actually allows malicious actors to impersonate you really well.

ReliaQuest has released information about how a “tsunami of phishing messages” followed by a massive deluge of spam in order to allow hackers the cover they needed to hijack their network. It’s a great birds-eye view of how this kind of thing works. The lesson here: Don’t simply ignore a massive uptick in phishing messages or spam.

A series of vulnerabilities exist in undocumented functions in the Espressif bluetooth chips used in over a billion devices.

YouTubers are being targeted with threats of copyright strikes if they don’t spread malware. And you thought the content was bad already.

Now for the good news:

The EFF has released a tool to detect cellular spying.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is relatively minor this month. The typical computer should see roughly 2.5 GB in updates today. Let’s get started.

Microsoft released 39 updates to address 72 vulnerabilities in .NET, ASP.NET Core & Visual Studio, Azure Agent Installer, Azure Arc, Azure CLI, Azure PromptFlow, Kernel Streaming WOW Thunk Service Driver, Microsoft Edge, Microsoft Local Security Authority Server (lsasrv), Microsoft Management Console, Microsoft Office, Microsoft Office Access, Microsoft Office Excel, Microsoft Office Word, Microsoft Streaming Service, Microsoft Windows, Remote Desktop Client, Synaptics, Inc., Visual Studio, Visual Studio Code, Windows Common Log File System Driver, Windows Cross Device Service, Windows DNS Server, Windows exFAT File System, Windows Fast FAT Driver, Windows File Explorer, Windows Hyper-V, Windows Kernel Memory, Windows Kernel-Mode Drivers, Windows MapUrlToZone, Windows Mark of the Web (MOTW), Windows NTFS, Windows NTLM, Windows Remote Desktop Services, Windows Routing and Remote Access Service (RRAS), Windows Subsystem for Linux, Windows Telephony Server, Windows USB Video Driver, Windows Win32 Kernel Subsystem, and MSRT. This includes security updates. A reboot is required.

Apple released updates for iOS 18.3.2, iPadOS 18.3.2, macOS Sequoia 15.3.2, Safari 18.3.1, tvOS 18.3.1, and visionOS 2.3.2. This includes security updates. Use Apple Software Update to install the most current versions.

iOS 18.3.2 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 18.3.2 are security updates. Use Settings, General, Software Update to install the most current update.

tvOS 18.3.1 is a security update. Use System, Software Update to install the most current version.

visionOS 2.3.2 is a security update. Use System, Software Update to install the most current version.

Google ChromeOS 133.0.6943.146 and Google ChromeOS LTS 126.0.6478.265 and 132.0.6834.211 are security updates. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sequoia (15.x) means that macOS Monterey (12.x) and older are no longer supported. If you can not install at least macOS Ventura (13) on your Mac then you should immediately remove your device from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v24H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it. If not, switch to Linux (Mint is nice) or replace your computer.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with a SaferPC Subscription and we will install updates each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 25.3.1 adds support for new hardware, feature and performance improvements, and resolves several bugs. This is not a security update.
https://www.amd.com/en/support

Crucial Storage Executive 11.01 does not provide a change log so should be treated as a security update.
https://www.crucial.com/support/storage-executive

Intel Driver and Support Assistant 25.1.9.6 is a security update.
https://www.intel.com/p/en_US/support/detect

VIISAN OfficeCam 7.2.7.0 doesn’t provide a change log so should be treated as a security update.
https://www.viisan.com/en/download/type1.html

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.76.74 is a security update.
https://brave.com/

Google Chrome 134.0.6998.88 is a security update.
https://www.google.com/chrome/

Firefox 136.0.1 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 128.8.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Vivaldi 7.1.3570.60 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

DavMail Gateway 6.3.0 improves compatibility and resolves several bugs. This is a security update.
https://davmail.sourceforge.net/

Spark 3.21.3.100475 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.21.3.100474 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 136.0.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 9.0.4 resolves several crash bugs. This is not a security update.
https://anydesk.com/en/downloads

AnyDesk (macOS) 9.0.0 is a major update adding several new features and resolves compatibility and stability bugs. This is not a security update.
https://anydesk.com/en/downloads

curl 8.12.1 improves tests and resolves several bugs. This is not a security update.
https://curl.haxx.se/windows/

Dropbox 219.4.4463 resolves several stability bugs. This is not a security update.
https://www.dropbox.com/

FreeFileSync 14.2 resolves a crash bug. This is not a security update.
https://www.freefilesync.org/download.php

Google Drive 105.0 resolves several bugs. This is not a security update.
https://drive.google.com/start

Grocy Desktop 2.13.0 improves compatibility. This is not a security update.
https://github.com/grocy/grocy-desktop

MeshCentral 1.1.42 resolves several bugs. Note that this version has conflicts with Windows 7 and 2008R2 so do not enable update on these platforms. This is not a security update.
https://meshcentral.com/info/downloads.html

Microsoft Teams 1.8.00.4966 enables AI by default, feature improvements and now consumes Skype links. Skype is dead. This is not a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 31.0.0 updates libraries and resolves dozens of bugs. This should be treated as a security update.
https://nextcloud.com/

Npcap 1.81 adds several new features and performance improvements. This is not a security update.
https://nmap.org/npcap/

Rclone 1.69.1 improves compatibility and resolves several bugs. This is not a security update.
https://rclone.org/

Signal 7.45.1 resolves several bugs. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.36.2 adds chat history migration support. This is not a security update.
https://signal.org/android/apk/

Technitium DNS Server 13.4.3 improves reliability and performance. This is not a security update.
https://technitium.com/dns/

Telegram 5.12.3 resolves several bugs. This is not a security update.
https://telegram.org/

WinSCP 6.3.7 is a security update.
https://winscp.net/eng/index.php

Zoom 6.3.11.60501 resolves several bugs. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.15 improves clothing and other interactions. This is not a security update.
https://en.3tene.com/

Bitwig Studio 5.3.2 resolves several bugs. This should be treated as a security update.
https://www.bitwig.com/download/

darktable 5.0.1 resolves dozens of bugs. This is not a security update.
https://www.darktable.org/

Grayjay 285 improves sync and resolves several bugs. This is not a security update.
https://grayjay.app/index.html

iTunes 12.13.6.1 adds support for new iOS and iPadOS versions. This does not provide a detailed change log so should be treated as a security update.
https://www.apple.com/itunes/download/

KaraFun Player 3.5.3 improves offline mode and remote. This is not a security update.
https://www.karafun.com/karaoke-windows/

Plex Desktop 1.108.1.307 doesn’t provide a change log so should be treated as a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Media Server 1.41.5.9522 improves ad detection feature, performance and resolves a bunch of bugs. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.62.01 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

PS5 2025.225 improves performance and stability. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2025.03.10 resolves several bugs and improves stability. This is not a security update.
https://store.steampowered.com/news/app/593110

SteamOS SteamDeck Update 2025.03.04 is a security update.
https://store.steampowered.com/news/app/1675200/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Illustrator 28.7.5 and 29.3 are security updates.
https://helpx.adobe.com/security/products/illustrator/apsb25-17.html

Adobe InDesign 19.5.3 and 20.2 are security updates.
https://helpx.adobe.com/security/products/indesign/apsb25-19.html

Adobe Reader DC 25.001.20432, 24.001.30235 and 20.005.30763 are security updates.
https://get.adobe.com/reader

Adobe Substance 3D Designer 14.1.1 is a security update.
https://helpx.adobe.com/security/products/substance3d_designer/apsb25-22.html

Adobe Substance 3D Modeler 1.20.10 is a security update.
https://helpx.adobe.com/security/products/substance3d-modeler/apsb25-21.html

Adobe Substance 3D Painter 11.0 is a security update.
https://helpx.adobe.com/security/products/substance3d_painter/apsb25-18.html

Adobe Substance 3D Sampler 5.0 is a security update.
https://helpx.adobe.com/security/products/substance3d-sampler/apsb25-16.html

Aronium 1.45 resolves several bugs. This is not a security update.
https://aronium.com/

Artweaver 8.0.3 resolves several bugs. This is not a security update.
https://www.artweaver.de/

Audacity 3.7.2 resolves over a dozen bugs. This is not a security update.
https://www.audacityteam.org/download/

Calibre 7.26.0 resolves several bugs. This is not a security update.
https://calibre-ebook.com/

Columns++ 1.2 improves parsing and adds additional escapes and search options. This is not a security update.
https://github.com/Coises/ColumnsPlusPlus

Kdenlive 24.12.3 resolves over a dozen bugs. This is not a security update.
https://kdenlive.org/

Kindle for PC 2.7.70978 doesn’t provide a change log so should be treated as a security update.
https://www.amazon.com/kindleforpc

LibreOffice 24.8.5 resolves over 60 bugs. This is a security update.
https://www.libreoffice.org/

LibreOffice Fresh 25.2.1 resolves over 75 bugs. This is a security update. The “Fresh” line is beta software and should be avoided in favor of the standard release.
https://www.libreoffice.org/

Manager 25.3.11.2151 improves inventory feature. This is not a security update.
https://www.manager.io/

Nextcloud Desktop 3.16.0 resolves dozens of bugs. This is not a security update.
https://nextcloud.com/

Notepad++ 8.7.8 resolves several bugs. This is not a security update.
https://notepad-plus-plus.org/

Paint.net 5.1.5 adds JPEG XL support, updates libraries and resolves several bugs. This is not a security update.
https://www.getpaint.net/

PDF-XChange Editor 10.5.2.395 is a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

Operating System Updates

These are for specific Linux flavors and alternative operating systems and, sadly, are unlikely to be of interest to most people.

Tails 6.13 is a security update.
https://tails.net/install/download/index.en.html

Security Software Updates

One or more of these is likely to be of interest to most people.

IISCrypto 4.0.18 adds support for Windows Server 2025, improved logging, controls, profiles and resolves a couple bugs. This is not a security update.
https://www.nartac.com/Products/IISCrypto/Download

JShelter 0.20 resolves several bugs. This is not a security update.
https://jshelter.org/install/

KeePass 2.58 improves cosmetics, controls and adds several new import and export capabilities. This is not a security update.
https://keepass.info/

MalwareBytes Desktop Security 5.2.7.167 resolves several bugs. This is not a security update.
https://www.malwarebytes.org/antimalware/

OnionShare 2.6.3 updates libraries, resolves several bugs, improves compatibility, and log capability. This is not a security update.
https://onionshare.org/

OpenSSL 3.4.1 is a security update.
https://slproweb.com/products/Win32OpenSSL.html

ProtonVPN 3.5.3 improves stability. This is not a security update.
https://github.com/ProtonVPN/win-app/releases/latest

RogueKiller 16.1.1 resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

Stinger 13.0.0.300 adds new detections. This should be treated as a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

Capture Updates

These are unlikely to be of interest to most people.

Open Broadcaster Software 31.0.2 resolves several crash and stability bugs. This is not a security update.
https://obsproject.com/

SnagIt 25.0.0 updates libraries, adds “step capture”, smart redaction, removal of background noise and customizable sharing. Unfortunately, it also now attempts to install SQL Server Compact Edition which has been unsupported for over three years with outstanding security vulnerabilities. It also introduced a crash bug when exporting to PNG format. This is a security update. Kinda sad isn’t it: Fix a few vulnerabilities and intentionally add even more? Sigh.
https://www.techsmith.com/screen-capture.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.3.7 adds support for new hardware and improves stability. This is not a security update.
https://www.dvdfab.cn/download.htm

HandBrake 1.9.2 resolves a couple bugs. This is not a security update.
https://handbrake.fr/

StreamFab 6.2.2.5 resolves several bugs and improves compatibility. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 3.0.1.0 resolves several bugs and adds support for newer hardware. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Education updates

One or more of these are likely to be of interest to most people.

Zotero 7.0.13 resolves a couple bugs. This is not a security update.
https://www.zotero.org/

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.10.64 resolves several bugs and improves default behaviors. This is not a security update.
https://1password.com/downloads/

balenaEtcher 2.1.0 adds support for new platforms and ability to disable analytics. This is not a security update.
https://etcher.balena.io/

Beyond Compare 5.0.6.30713 resolves several bugs. This is not a security update.
https://www.scootersoftware.com/download

BgInfo 4.33 doesn’t provide a change log so should be treated as a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/bginfo

Bitwarden 2025.2.1 improves user interface and adds 2FA for unrecognized devices. This is not a security update.
https://bitwarden.com/

Carbonite 6.5.1 improves compatibility. This is not a security update.
https://account.carbonite.com/

CCleaner 6.33.11465 resolves a couple bugs. This is not a security update.
https://www.ccleaner.com/

DesktopOK 11.63 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.4.2.0 resolves several bugs and improves console support. This is not a security update.
https://dngrep.github.io/

ESEDatabaseView 1.77 improves database reading. This is not a security update.
https://www.nirsoft.net/utils/ese_database_view.html

Fing 3.8.1 resolves several bugs. This is not a security update.
https://www.fing.com/products/fing-desktop-download-windows

GoodSync 12.8.5 resolves several bugs and improves compatibility. This is not a security update.
https://www.goodsync.com/

grepWin 2.1.8 resolves a couple bugs. This is not a security update.
https://github.com/stefankueng/grepWin/releases/latest

GSmartControl 2.0.2 resolves several bugs. This is not a security update.
https://gsmartcontrol.shaduri.dev/

Homedale 2.18 adds Thai language support. This is not a security update.
https://www.the-sz.com/products/homedale/

HWiNFO 8.22 adds support for newer hardware. This is not a security update.
https://www.hwinfo.com/download/

IsMyHdOK 4.21 improves hardware detection and compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

LessMSI 2.7.0 adds several new translations. This is not a security update.
https://lessmsi.activescott.com/

MultiMonitorTool 2.20 adds scaling capabilities. This is not a security update.
https://www.nirsoft.net/utils/multi_monitor_tool.html

NTLite 2025.03.10344 improves component selection and resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

OSForensics 11.1.1003 improves triage, hash sets, and other improvements. This is not a security update.
https://www.osforensics.com/download.html

osquery 5.16.0 resolves a couple bugs and improves python, deb and rpm package support. This is not a security update.
https://osquery.io/downloads

PowerToys 0.89.0 adds transcoding to advanced paste, improves stability and resolves over a dozen bugs. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

PSAppDeploy 4.0.6 resolves dozens of bugs. This is not a security update.
https://psappdeploytoolkit.com/

RoboForm 9.6.5 removes Security Center from installed app and resolves several bugs. This is not a security update.
https://www.roboform.com/

Starwind V2V Converter 9.623 improves compatibility and resolves several bugs. This is not a security update.
https://www.starwindsoftware.com/starwind-v2v-converter

TeamViewer 15.63.5 resolves several bugs and improves logging. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/

Ventoy 1.1.05 improves compatibility and resolves a couple bugs. This is not a security update.
https://www.ventoy.net/en/index.html

WinGet 1.10.340 improves stability. This is not a security update.
https://github.com/microsoft/winget-cli/releases/latest

WinRAR 7.10 resolves over a dozen bugs and improves MOTW propagation. This should be treated as a security update.
https://www.rarlab.com/

WizFile 3.11 improves threading, user interface and resolves several bugs. This is not a security update.
https://antibody-software.com/wizfile/

WizTree 4.25 improves CSV import and export and resolves a 32-bit compatibility bug. This is not a security update.
https://www.diskanalyzer.com/

XnConvert 1.104.0 adds command line file and list options. This is not a security update.
https://www.xnview.com/en/xnconvert/

ZoomText 2025.2502.63.400 adds ARM64 support and live text view. This is not a security update.
https://support.freedomscientific.com/Downloads/ZoomText

Developer Updates

These are unlikely to be of interest to most people.

.NET Runtime 9.0.3 is a security update.
https://dotnet.microsoft.com/en-us/download/dotnet

Android Studio 2024.3.1.13 resolves dozens of bugs. This is not a security update.
https://developer.android.com/studio

GDevelop 5.5.226 updates libraries and resolves several bugs. This is not a security update.
https://gdevelop.io/download

GitHub Desktop 3.4.18 updates libraries and resolves several bugs. This is not a security update.
https://desktop.github.com/

Go 1.24.1 is a security update.
https://go.dev/

Godot 4.4 adds dozens of new features and improvements. This is not a security update.
https://godotengine.org/

Inno Setup 6.4.1 improves autocompletion and tooltips, and resolves several bugs. This is not a security update.
https://www.jrsoftware.org/isdl.php

Microsoft Visual C++ 2022 Redistributable 14.42.34438.0 is a security update.
https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist

Node.js 18.20.7 resolves over a dozen bugs. This is not a security update.
https://nodejs.org/en/

Node.js 23.9.0 updates dependencies and resolves dozens of bugs. This is not a security update.
https://nodejs.org/en/

Rustup 1.28.1 resolves several bugs. This is not a security update.
https://www.rust-lang.org/

SQLite 3.49.1 resolves several bugs. This should be treated as a security update.
https://www.sqlite.org/download.html

Visual Studio Code 1.98.1 resolves several bugs. This is not a security update.
https://code.visualstudio.com/

Web Package Updates

These are likely to be of interest only to web developers.

Adminer 5.0.4 resolves dozens of bugs and improves various language integrations. This is not a security update.
https://www.adminer.org/en/

Grocy 4.4.2 improves Open Food Facts integration and resolves several bugs. This is not a security update.
https://github.com/grocy/grocy

HumHub 1.17.1 improves registration controls and resolves several bugs. This is not a security update.
https://www.humhub.com/en

Joomla 4.4.12 is a security update.
https://www.joomla.org/

Joomla 5.2.5 is a security update.
https://www.joomla.org/

Piwigo 15.4.0 resolves over a dozen bugs. This is not a security update.
https://piwigo.org/

bbPress 2.6.12 is a security update.
https://wordpress.org/extend/plugins/bbpress/

Conditional Widgets 3.3 updates documentation and improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/conditional-widgets/

Contact Form 7 6.0.5 resolves a couple bugs. This is not a security update.
https://wordpress.org/extend/plugins/contact-form-7/

Duplicator 1.5.12 improves compatibility and resolves several bugs. This is not a security update.
https://wordpress.org/plugins/duplicator/#developers

Redirection 5.5.2 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/redirection/

Sucuri Security 1.9.9 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/sucuri-scanner/

WP Cerber Security 9.6.7.3 resolves several bugs and improves performance. This is not a security update.
https://wpcerber.com/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2025-01-14

Happy New Year, Folks!

Today is Patch Tuesday for January, 2025.

It’s as safe as it’s going to be to upgrade to Windows 11 24H2 or macOS 15/Sequoia.

If your Windows 10 (or older) computer can not be upgraded to Windows 11, or if you used a registry or installation bypass to install an older version of Windows 11 on it that is no longer supported, then it’s time for you to start looking for a replacement computer.
Windows 10 now has only 9 months of support left and I am already seeing availability issues for new computers.

There were 600+ major hacks, and over 300 application updates this month. It’s a “normal” month, with about 4 GB of updates for most users.

This Month in Technology

A Bar A Ranch, A Sensitive Touch Home Health, AAA Environmental, Abrasive Supply Corporation, Access TeleCare, Accolent ERP Software, AEP Texas, Aetna ACE, Akantha, Akumin, Inc, Albert Paper Company, Albion College, Alexandria University, Allen Carr’s Easyway, Allendale Long-Term Care Home, Alliance for Creativity and Entertainment, Allianz Life Insurance Company, Allied Packing And Rubber Inc, AllyScripts, LLC, Alphastar Home Health Care, Alta Resources Corp, American Addiction Centers, American Associated Pharmacies, American Trust Company, Americhek, Anna Jaques Hospital, AnnieMac, AnyDesk, Aosense, Apache HugeGraph-Server, Apache MINA, Apache Tomcat, Apache Traffic Control, ApolloGames, Apple macOS camera, Archie Cochrane Ford, Ardyss, Arena Technical Resources, Argentina Airport, Arista NG Firewall, Arixa Capital Advisors LLC, Arrotex Pharmaceuticals, Artistic Family Dental, Artivion, Ascension Health, Ascension Living, Asheville City Schools, Ashlar-Vellum Graphite, Astaphans, AT&T, Atos, AudioPrints, Autodesk Navisworks Freedom, AutomationDirect C-More, Auxis, Avana Electrotek, Aviatrix Controller, Avira Prime, Avstar Fuel Systems, 4,000 backdoored backdoors, Badger Popcorn And Concession Supply Company, Bangkok Medical Software HOSxP XE, Bank of America, Bank Rakyat Indonesia, Barber Specialties, Bartholomew Consolidated School Corporation, BASC.edu.ph, BayMark Health Services, BCM One, Belen Consolidated Schools, Betterdoor.com, Bettisworth North, Beverly, BeyondTrust, BigCommerce, Billet Precision, Biomedical Caledonia, Bitdefender Virus Scanner, BitView, Black Oak Casino Resort (yes, that one), Blome International, Bluegrass Ingredients, BlueZ Classic HID, Bonneville School District 93, Boone County School District, Borrego Health, Boston University Framingham Heart Study, Brant Catholic school board, Brazilian government, Brighton Jones, Brockton Neighborhood Health Center, Brooklyn Art Library, BrownPacking, Byte Federal Bitcoin ATM platform, Cairo Governorate Education Portal, California Correctional Health Care Services, Cariad, Carrollton Orthopaedic Clinic, Casio, CED Solutions Computer IT Training Centers, Cell C, Center for Child Development, INC, Central Valley Meat Co Inc, Chain And Rope Suppliers LTD, Charlie’s Tax Service, Charter, Christ The Redeemer School, CIRCA, Cisco, City of Corvallis, City of Noblesville, City of West Haven, City of Winston-Salem, Cleo Harmony, Cleo LexiCom, Cleo VLTrader, College Hospital Costa Mesa, Collezione, Colombia court system, Community Alliance, Compliance Solutions Inc, Conceptions Reproductive Associates of Colorado, ConnectOnCall, COROB, Costex, Cottrell Fletcher & Cottrell PC, CR&R Environmental Services, CREFSP, Crimson Wine Group, Crown Mortgage Company, Cyberhaven, D&G Enviro-Group, D-7 Roofing, 250,000 Danish consumer records, DAP Health, Davis Products Company Inc, DBM Global Inc, Delap & Waller, Delhi Public Primary School Itarsi, Dell Avamar, Dell’s Update Package Framework, Delta Electronics CNCSoft-G2, Delta Electronics DRASimuCAD, DEphoto, DigiEver DS-2105 Pro DVRs, Dignity Health Lassen Medical Clinic, Discord, District 65, DMM Bitcoin, Dobie Road, Douglas County Department of Health and Human Services, Downey Hospital, Dragonfly Health, Drivestream, Drupal, Drywall Partitions, Duke Energy, DuxHumanHealth, Dynasty Healthcare Company, E-Tank, Eastern Idaho Public Health, Economy Restaurant Equipment And Supply Company, Effortless Office, Eindhoven University of Technology, Ekonika, Energy Capital Credit Union, Enugu State Government, EPS-MTOSB, Espreso TV, European Space Agency, EVAS Group, Evidn, Ex-Times, Exostar, Facebook, Family Help & Wellness, Farline, Farnesina, Federal Bank of India, Fireproof Contractors Inc, Flamco, FlashFiber, FoodMap, Fortinet Wireless Manager, Forum Architecture & Interior Design, Four-Faith routers, Foxit PDF Reader, Frameworks, Fraunhofer IAO, Free Telecom Raises, Freightliner of Savannah, French Citizens, French Tennis Federation, Fukoku Co, Fullmer Construction, FunFun688, Gammal Tech, Geisinger, General Digital, General Dynamics, Genie Healthcare, GeoVision GV-ASManager, Gerber Life Insurance, GFI Archiver, GFI KerioControl, Gilbarco Veeder-Root Orpak, Giordano, DelCollo, Werb & Gagne, LLC, GLAMIRA, Golden Age Home Health Inc, Golden Hills School, Good Neighbors Credit Union, Good Samaritan Hospital, Google Chrome, GPM Lawn Sprinkler Supply, Granite School District, Gravy Analytics, Great Star Tools USA, Green Bay Packers store, Greene Supply Company, Grocy, Grupo Buddemeyer, Guardian.com, Gunnar Prefab, Habib’s, Halton Long Term Care, Hammons Supply Company, Hapn, Happy Magic Trick Shop, Harley-Davidson, Hartson-Kennedy Inc Group Benefit Plan, HealthEquity, Inc, Heavy Construction Systems Specialists, LLC, Helena Public Schools, HemenBahis, Heritage Bank, Hi-Raise Constructions Holding, Hide-A-Way Lake Club, Holton Public Schools, Hong Kong Food and Environmental Hygiene Department, Hong Kong Insurance Authority, Hong Kong Urban Renewal Authority, Hopamedia, Horizon Oil, Howell Township Public Schools, HRB Tax Group, Inc, Huaxia School, Hunter Taubman Fischer & Li, Huntington Hotel Group, Hyperice, I, Librarian, IHIO, Ikav Global Energy, Illinois Bone & Joint Institute, LLC, Illinois Department of Human Services, Illumina’s iSeq 100 DNA gene sequencer, Imperial Valley Respite, In-Home Attendant Services, INBAL, Indian government websites, 3.69 million Indian property records, Indianapolis Public Schools, Indonesia Government, InfoCert, Informaticarecoleta, Instagram, Insured Recovery, International Coffee & Tea, LLC, Internxt VPN, Inverclyde Council, Israel Defense Forces, Italian banks and government agencies, Italian Foreign Ministry, Ivanti Avalanche, Ivanti Connect Secure, Izmocars, Japan Airlines, Jared Beschel and Associates, Jay Enn Corporation, Jet Edge, Jim Thompson, JRT Automatisation, Kadokawa Corporation, Kadokawa, Kaizen Pharmaceuticals, Kansas City Hospice, Inc, KBanknow, Keeco, LLC, Kenton County School District, Kern Services, Khalil Center, Kilgore Industries, Kiswire, Kitsap Mental Health Services, global Know Your Customer (KYC) account data, Krispy Kreme, Kyndryl, LA Financial Federal Credit Union, Lake Shore Public Schools, Lancaster City Schools, Laramie County Library System, Las Palmas Del Sol Healthcare, Latitude, LCPtracker, Inc, Le Coq Sportif, Lebanese Intelligence Dept, LegalNurse, Lelivrescolaire, Lexington Diagnostic Center, Leyman Manufacturing, Linux Kernel Bluetooth, LKQ Corporation, Lokdal, Luxion KeyShot Viewer, Luxury Yacht Group, Lyons Specialty Co, macOS SIP, Madhya Pradesh’s child welfare agency, over 3,000,000 mail servers, ManageEngine Analytics Plus, Manens-Tifs SpA, Manitou Springs School District, Martin Sprocket & Gear, Inc, Maverick Constructors, MC2 Data, McCormick & Priore, McCray Lumber, McDonald’s, McFarlane, Medusind, Meezan Bank, Megaexit, Menorah Life, Inc, Metalmatrix Clamps, MetLife, mi.edu, Microsoft Azure Data Factory, Microsoft Azure MFA, Microsoft Edge, Microsoft PC Manager, Microsoft Purview, Microvision, Mission Bancorp, MLP Tax & Financial Services, Modern Automotive Network, Modern Dental Group Limited, Mohawk Valley Cardiology, Moneytor, Montreal North, Mossad, Moxa, MSI, MyGiftCardSupply, Nara, Nash Brothers Construction, Nathan American Academy, National Atomic Energy Commission, National Commission of Markets (Spain), National Library of Peru, Natomas Unified School District, Nikki-Universal, Nirjai, Niva Bupa Insurance Group, Nodex, Nominet, North Los Angeles County Regional Center, Northern Lights Electric, Northwest Asthma & Allergy Center, Norwalk La Mirada Unified School District, Norwex USA, Inc, Novati Constructions, Nuclei, NY & WY Orthpaedics Specialists, Obltelecom, OL Products, Omaha Surgical Center, OmniRide, Omnitravel, One Airline, OneBlood, Onecare, OpenWrt, Oppo, Ott Cone & Redpath, PA, Pacific Pulmonary Medical Group, Paessler PRTG Network Monitor, Palo Alto Networks Expedition, Panda Security Dome, ParrotTalks, Path of Exile 2, Patriarche Office of Architecture, Peikko, Pembina Trails School Division, Peruvian University of Applied Sciences, Peugeot Dealership, PharmaNewsOnline, PHG CPAs, Philippine Statistical Association Inc, PhoneMondo, PIH Health, Pinger USA, PingMoney, Pinno Construction, Pittsburgh Regional Transit, Platinum Celebs, Positive Behavior Supports Corporation, PowerSchool (this affects potentially millions of school districts across the globe), PracticeSuite, Press Color, ProCaps Laboratories, Progress Software WhatsUp Gold, Psychogen, PT Pertamina, PT PINS Indonesia, Qualcomm chips, Qualinet, Rainy River public school, Ramos Law, Rancho Santa Fe School District, Randolph Brooks Federal Credit Union, Randys Transmissions, Rapido, Realme, Regional Care, Inc, Relate Infotech, Reliance Connects, Rent-2-Own, ReutOne, Revolution Beauty, Rhode Island’s RIBridges, Richmond University Medical Center, River Region Cardiology, Riverina Medical, Rivers Casino Philadelphia, RM Group, Rockwell Automation Arena Simulation, Rocky Mountain Gastroenterology Associates, RocSearch, Rosreestr, Rozavam, Rspack, Ruby, Ruijie Networks, Rumpke Consolidated Companies, Inc & Affiliates Benefits Plan, Rutherford County Schools, Rydox, SAIC in Brazil, Samsung Devices, schenkYOU, Schneider Electric, Scholastic, Scottish rail network, SeaLandAire Technologies, Self Esteem Brands, LLC, SENATI, Senior Citizens, Inc, Senior Dating, SERGAS Group, Sheyenne Tooling & Manufacturing, Sidney Health Center, Siemens User Management Component, Simcoe Muskoka Catholic School, Skoda cars, Skopos, Slawson Companies, Slovakian land registry, SmartLynx Airlines SIA, Smith Tank & Steel, Solaris Pharma, SolGeo AG Baugelogie and Geotechnik, SonicWALL NSv, Sony XAV-AX8500, Sophos Firewall, Sparkling Smiles Family Dentistry, Spectrum, SpeedLine Solutions, Spelpaus, Sri Lanka Government Printing Department, Sri Lanka Police, SRP Federal Credit Union, Stanford University, Starbucks, Starkville-Oktibbeha Consolidated School District (SOCSD), State Registers of Ukraine, STIIIZY, Stillwater Area Public Schools, Summit Medical Group, PLLC, Sunflower Medical Group, Suno India, SuperDraft, Supreme Court of India, Surface Combustion, Swedish Gambling Authority, Synology, T Smiles Dental, T.Hasegawa USA, T1, Tahoe Truckee Sierra Disposal Co Inc, Talentely, Tarnaise des Panneaux SAS, Tayfa Denizcilik, Tecta America Corporation, Teedy, Telcel, Telecom Namibia, Telefónica, Tenable Nessus update system, Tesla Wall, Teton Orthopaedics, Texas Tech University Health Sciences Center, Thailand Department of Mineral Fuels, Tharisa, The Baker Center for Children and Families, The Coffee Bean & Tea Leaf, Thomas Cook, Thomas J. Henry Law, Tibber, Tibbo Aggregate Network Manager, Toscano Law, Total Patient Care LLC, Town of Ponoka, Town of Webster, Trend Micro Apex One, Trend Micro Deep Security, Trev Deeley Motorcycles, Trifecta, TruBridge, Inc, True World Holdings LLC, Trussville City Schools, Try.gov.hk, Tumeny Payments Limited, Tungsten Automation Power PDF, Turks and Caicos, Tycon Medical Systems, UGKK, Unisource Information Services, United Nations International Civil Aviation Organization (ICAO), University of Baghdad, University of Tasmania, US Committee on Foreign Investments, US EPA, 261,000 US insurance agents, 350,000 US mobile homeowners, US SSA, US Treasury, US Veteran Affairs, UT Southwestern Medical Center (fourth time in 18 months), Uvoice, Valio, Vallianz, Value Dental Center, Vaultwarden, Venki Supravizio BPM, Venntel, Veritas Enterprise, Verizon, Verosa LLC, VESD, Vickers Engineering, Village Community School, Village Fertility Pharmacy Group, VIP, VisionPoint Eye Center, VO Baker, VPNCity, VW Group, Wacom Center WTabletServicePro, Walker County Schools, Warid Telecom, Water Utilities Corporation, Waterstones, Watertown Public Schools, Watsonville Community Hospital, Webmin, Weininger Metall System GmbH, Western Montana Mental Health Center, Westerville City Schools, WhatsApp, Whittier Hospital, WilsonSD, Windows Active Directory Domain Controllers, Windstream, WireGuard Portal, Wood County, Word & Brown Insurance Administrators, Inc, World Leadership Academy, WSO2 API Manager, WY88 Casino, Xanthops, Xstrahl eBt Therapy Equipment, Xtream, XWiki, Yaaka, Yat Siu, Yonéma, YorkTest Laboratories, Young Life, Young Living Essential Oils, Youngs Counseling, PLLC, Youth Eastside Services, ZAGG Inc, and Zeifmans have reported hacking or compromises this month.

Docomo, Facebook, Instagram, MI6, Microsoft Multi-Factor Authentication (MFA) – effectively blocking access to MS 365, Proton, Threads, and WhatsApp have suffered from outages this month.

Last months updates broke Windows updates on new installations, Windows 11 Start Menu, Office 365 activation system, Windows 11 HDR, and Windows Bitlocker.

Microsoft is going to force-install “new” Outlook on Windows PCs within the next month.

“When exposing a crime is treated as committing a crime, you are being ruled by criminals.” — Edward Snowden

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is not that bad this month. The typical computer should see roughly 4 GB in updates today. Let’s get started.

Microsoft released 70 updates to address 164 vulnerabilities in .NET, .NET Framework, Active Directory Domain Services, Active Directory Federation Services, Azure Marketplace SaaS Resources, BranchCache, Internet Explorer, IP Helper, Line Printer Daemon Service (LPD), Microsoft AutoUpdate (MAU), Microsoft Azure Gateway Manager, Microsoft Brokering File System, Microsoft Digest Authentication, Microsoft Edge, Microsoft Graphics Component, Microsoft Office, Microsoft Office Access, Microsoft Office Excel, Microsoft Office OneNote, Microsoft Office Outlook, Microsoft Office Outlook for Mac, Microsoft Office SharePoint, Microsoft Office Visio, Microsoft Office Word, Microsoft Purview, Microsoft Windows Search Component, Power Automate, Reliable Multicast Transport Driver (RMCAST), Servicing Stack Updates, System Center, Visual Studio, Windows BitLocker, Windows Boot Loader, Windows Boot Manager, Windows Client-Side Caching (CSC) Service, Windows Cloud Files Mini Filter Driver, Windows COM, Windows Connected Devices Platform Service, Windows Cryptographic Services, Windows Digital Media, Windows Direct Show, Windows DWM Core Library, Windows Event Tracing, Windows Geolocation Service, Windows Hello, Windows Hyper-V NT Kernel Integration VSP, Windows Installer, Windows Kerberos, Windows Kernel Memory, Windows MapUrlToZone, Windows Mark of the Web (MOTW), Windows Message Queuing, Windows NTLM, Windows OLE, Windows PrintWorkflowUserSvc, Windows Recovery Environment Agent, Windows Remote Desktop Services, Windows Secure Boot, Windows Security Account Manager, Windows Smart Card, Windows SmartScreen, Windows SPNEGO Extended Negotiation, Windows Telephony Service, Windows Themes, Windows UPnP Device Host, Windows Virtual Trusted Platform Module, Windows Virtualization-Based Security (VBS) Enclave, Windows Web Threat Defense User Service, Windows Win32K – GRFX, Windows WLAN Auto Config Service, and MSRT. This includes security updates. A reboot is required.

Apple released updates for iOS 18.2, iOS 18.2.1, iPadOS 17.7.3, iPadOS 18.2, iPadOS 18.2.1, macOS 15.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, Safari 18.2, tvOS 18.2, visionOS 2.2 and watchOS 11.2. This includes security updates. Use Apple Software Update to install the most current versions.

iOS 18.2.1 is a security update. Use Settings, General, Software Update to install the most current update.

iPadOS 17.7.3 and 18.2.1 are security updates. Use Settings, General, Software Update to install the most current update.

watchOS 11.2 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 18.2 is a security update. Use System, Software Update to install the most current version.

visionOS 2.2 is a security update. Use System, Software Update to install the most current version.

Google ChromeOS 131.0.6778.241 and Google ChromeOS LTS 126.0.6478.261 are security updates. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sequoia (15.x) means that macOS Monterey (12.x) and older are no longer supported. If you can not install at least macOS Ventura (13) on your Mac then you should immediately remove your device from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v24H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it, but I recommend you continue to use Windows 10 until early 2025 before you consider switching to it.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with a SaferPC Subscription and we will install updates each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Daemon Tools Lite 12.2.0 resolves several bugs. This is not a security update.
https://www.daemon-tools.cc/products/dtLite

UniFi airMAX NanoStation 5AC Loco 8.7.15 is a security update.
https://www.ui.com/download/software/loco5ac

UniFi Network Server 9.0.108 adds zone-based firewall, CyberSecure, Network Application API and resolves several bugs. Thsi is not a security update.
https://www.ui.com/download/releases/network-server

VIISAN OfficeCam 7.2.5.0 doesn’t provide a change log so should be treated as a security update.
https://www.viisan.com/en/download/type1.html

Wacom Driver 6.4.8-6 improves compatibility and resolves several bugs. This is not a security update.
https://www.wacom.com/en-us/support/product-support/drivers

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.73.105 is a security update.
https://brave.com/

Google Chrome 131.0.6778.264 is a security update.
https://www.google.com/chrome/

Firefox 134.0.1 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 128.6.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

SeaMonkey 2.53.20 is a security update.
https://www.seamonkey-project.org/

Vivaldi 7.0.3495.29 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Mailspring 1.15.0 is a security update.
https://getmailspring.com/

Spark 3.19.2.94903 improves AI controls, user interface improvements and resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.19.2.94902 improves AI controls, user interface improvements and resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 128.6.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

curl 8.11.1 resolves dozens of bugs. This is not a security update.
https://curl.haxx.se/windows/

DNSDataView 1.76 adds DMARC support. This is not a security update.
https://www.nirsoft.net/utils/dns_records_viewer.html

Dropbox 214.4.5217 resolves several bugs. This is not a security update.
https://www.dropbox.com/

Google Drive 102.0 resolves several bugs. This is not a security update.
https://drive.google.com/start

Grocy Desktop 2.11.0 updates Grocy and Barcode Buddy to their latest releases and resolves several bugs. This is not a security update.
https://github.com/grocy/grocy-desktop

MeshCentral 1.1.38 resolves several bugs. This is not a security update.
https://meshcentral.com/info/downloads.html

Microsoft Teams 1.7.00.33761 adds brand filtering and web-based screen controls. This is not a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 30.0.4 updates libraries and resolves several bugs. This is not a security update.
https://nextcloud.com/

Omada Software Controller 5.15.6.7 adds support for additional hardware, SAML SSO support, DSL Gateway configuration and improvces RADIUS support. This is not a security update.
https://www.tp-link.com/us/support/download/omada-software-controller/

Pocketnet-Core 0.22.11 improves jury and moderation, and resolves several bugs. This is not a security update.
https://pocketnet.app/

Pocketnet-GUI 0.9.107 resolves a dozen bugs. This is not a security update.
https://pocketnet.app/

Rclone 1.69.0 is a security update.
https://rclone.org/

Signal 7.37.0 improves visual feedback and macOS compatibility. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.28.4 adds chat folders and group grouping. This is not a security update.
https://signal.org/android/apk/

Syncthing 1.29.2 improves stability and resolves several bugs. This is not a security update.
https://syncthing.net/

Technitium DNS Server 13.3 resolves several bugs, including stability and denial of service. This should be treated as a security update.
https://technitium.com/dns/

Telegram 5.10.3 resolves several bugs. This is not a security update.
https://telegram.org/

Zoom 6.3.6 resolves several bugs, including a fix for a defect in the automatic update system, and makes cosmetic changes. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

darktable 5.0.0 is a major update, including over 1,700 changes, 500 camera model improvements, user interface improvements, performance improvements and much more. This is not a security update.
https://www.darktable.org/

Grayjay 278 adds and removes Apple Podcasts, and resolves several several bugs. This is not a security update.
https://grayjay.app/index.html

KaraFun Player 3.4.6.81 improves stability and resolves several bugs. This is not a security update.
https://www.karafun.com/karaoke-windows/

Plex Desktop 1.106.0.276 adds Share button and resolves several bugs. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Home Theater 1.69.0.264 updates libraries. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Media Server 1.41.3.9314 is a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.51.02 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

SteamOS SteamDeck Update 2024.12.12 is a security update.
https://store.steampowered.com/news/app/1675200/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Animate 23.0.10 and 24.0.7 are security updates.
https://helpx.adobe.com/security/products/animate/apsb25-05.html

Adobe Illustrator for iPad 3.0.8 is a security update.
https://helpx.adobe.com/security/products/illustrator-mobile-ios/apsb25-04.html

Adobe Photoshop 26.2 and 25.12.1 are security updates.
https://helpx.adobe.com/security/products/photoshop/apsb25-02.html

Adobe Reader DC (Mac) 24.004.20272 resolves several bugs. This is not a security update.
https://get.adobe.com/reader

Adobe Reader DC 24.005.20320 is a security update.
https://get.adobe.com/reader

Adobe Substance3D Designer 14.1 is a security update.
https://helpx.adobe.com/security/products/substance3d_designer/apsb25-06.html

Adobe Substance3D Stager 3.1.0 is a security update.
https://helpx.adobe.com/security/products/substance3d_stager/apsb25-03.html

Audacity 3.7.1 doesn’t provide a change log so should be treated as a security update.
https://www.audacityteam.org/download/

Calibre 7.24.0 adds read-aloud and resolves several bugs. This is not a security update.
https://calibre-ebook.com/

ColdFusion 2021.18 and ColdFusion 2023.12 are security updates.
https://helpx.adobe.com/security/products/coldfusion/apsb24-107.html

GnuCash 5.10 resolves dozens of bugs. This is not a security update.
https://www.gnucash.org/

Kdenlive 24.12.1 adds ASS subtitle support, resolves a bunch of bugs, and updates libraries and dependencies. This is not a security update.
https://kdenlive.org/

LibreOffice 24.8.4 resolves over 50 bugs. This is a security update.
https://www.libreoffice.org/

LibreOffice Fresh 24.8.4 resolves over 50 bugs. This is a security update.
https://www.libreoffice.org/

Manager 25.1.14.2025 improves inventory costing and controls. This is not a security update.
https://www.manager.io/

Nextcloud Desktop 3.15.3 resolves several bugs. This is not a security update.
https://nextcloud.com/

Notepad++ 8.7.5 resolves over a dozen bugs and regressions. This is not a security update.
https://notepad-plus-plus.org/

Paint.net 5.1.2 improves performance and reduces resource requirements, resolves several bugs. This is not a security update.
https://www.getpaint.net/

PDF-XChange Editor 10.5.0.393 resolves dozens of bugs. This is a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

QuickBooks Pro 2022 20241217-R18_40 resolves a crash bug. This is not a security update.
https://downloads.quickbooks.com/app/qbdt/products

QuickBooks Pro 2023 20241217-R15_29 resolves a crash bug. This is not a security update.
https://downloads.quickbooks.com/app/qbdt/products

Scribus 1.6.3 resolves over a dozen bugs. This is not a security update.
https://www.scribus.net/

Operating System Updates

These are for specific Linux flavors and alternative operating systems and, sadly, are unlikely to be of interest to most people.

ChromeOS 131.0.6778.241 is a security update.
https://chromereleases.googleblog.com/search/label/Stable%20updates+ChromeOS

iOS 18.2 and iOS 18.2.1 are security updates.
https://support.apple.com/kb/HT204204

iPadOS 18.2 and iPadOS 18.2.1 are security updates.
https://support.apple.com/kb/HT204204

macOS 15.2 is a security update.
https://support.apple.com/kb/HT201541

Tails 6.11 is a security update.
https://tails.net/install/download/index.en.html

tvOS 18.2 is a security update.
https://support.apple.com/kb/HT202716

watchOS 11.2 is a security update.
https://support.apple.com/kb/HT204641

Security Software Updates

One or more of these is likely to be of interest to most people.

Chainsaw 2.11.0 improves MFT parsing. This is not a security update.
https://github.com/countercept/chainsaw

MalwareBytes Desktop Security 5.2.4.157 rebrands from “Anti-Malware,” improves notification behavior, and now requires autorun for the VPN Kill Switch capability. This is not a security update.
https://www.malwarebytes.org/antimalware/

ProtonVPN 3.5.0 improves stability and reliability in censored countries. Thsi is not a security update.
https://github.com/ProtonVPN/win-app/releases/latest

Stinger 13.0.0.254 improves detection. This is not a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

uBlock Origin 1.62.0 improves syntax and reliability and resovles several bugs. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.3.4 improves NVIDIA AI conversion. This is not a security update.
https://www.dvdfab.cn/download.htm

IsoBuster 5.5.1 adds dozens of new features, new media formats and mappings, and resolves several bugs. This is not a security update.
https://www.isobuster.com/download.php

StreamFab 6.2.1.3 updates engine, improves compatibility, and resolves several bugs. Thsi is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 3.0.0.1 is a major update and improves upscaling, performance and resolves a couple bugs. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.10.56 resolves over a dozen bugs. This is not a security update.
https://1password.com/downloads/

GadgetPack 38.0 rebrands from 8GadgetPack, adds Windows 11 support, updates graphics and cosmetics, and resolves a couple bugs. This is not a security update.
https://gadgetpack.net/

Agent Ransack 2022.3503 resolves several bugs. This is not a security update.
https://www.mythicsoft.com/agentransack/download/

AOMEI Partition Assistant 10.7.0 adds 1-click space fix and resolves several bugs. This is not a security update.
https://www.diskpart.com/

BatteryHistoryView 1.06 improves compatibility. This is not a security update.
https://www.nirsoft.net/utils/battery_history_view.html

Bitwarden 2024.12.1 resolves several bugs and improves compatibility. This is not a security update.
https://bitwarden.com/

CCleaner 6.31.11415 improves cleanup. Thsi is not a security update.
https://www.ccleaner.com/

CPU-Z Installer 2.13 adds support for newer hardware. This is not a security update.
https://www.cpuid.com/softwares/cpu-z.html

Cygwin 3.5.5 resolves over a dozen bugs. Thsi si not a security update.
https://cygwin.com/

DesktopOK 11.51 updates definition file options and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.2.121.0 updates libraries and resolves a couple bugs. This is not a security update.
https://dngrep.github.io/

ESEDatabaseView 1.76 resolves several bugs. This is not a security update.
https://www.nirsoft.net/utils/ese_database_view.html

FileLocator Pro 2022.3503 resolves several bugs. This is not a security update.
https://www.mythicsoft.com/filelocatorpro/download

Fing 3.8.0 improves Network Insights feature and resolves several bugs. This is not a security update.
https://www.fing.com/products/fing-desktop-download-windows

GoodSync 12.8.0 resolves several bugs. This is not a security update.
https://www.goodsync.com/

HWiNFO 8.20 improves hardware support and resolves several bugs. This is not a security update.
https://www.hwinfo.com/download/

LessMSI 2.4.0 adds xo option to extract and overwrite. This is not a security update.
https://lessmsi.activescott.com/

NTLite 2025.01.10258 updates Windows 11 24H2 support and resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

Open-Shell 4.4.195 improves Windows 11 24H2 support and resolves several bugs. This is not a security update.
https://github.com/Open-Shell/Open-Shell-Menu

PingInfoView 3.20 adds dark background support and alternating row colors. This is not a security update.
https://www.nirsoft.net/utils/multiple_ping_tool.html

PointerStick 6.46 adds a new pointer option and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

PowerToys 0.87.1 improves stability and resolves issues in many of the included tools. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

PSAppDeploy 4.0.4 resolves dozens of bugs. This is not a security update.
https://psappdeploytoolkit.com/

TeamViewer 15.61.4 resolves several bugs. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/

WifiInfoView 2.96 updates the internal MAC database. This is not a security update.
https://www.nirsoft.net/utils/wifi_information_view.html

WinScan2PDF 9.19 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

ZoomIt 9.0 adds live draw support. This is not a security update.
https://learn.microsoft.com/en-us/sysinternals/downloads/zoomit

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 2024.2.2.13 resolves dozens of bugs. This is not a security update.
https://developer.android.com/studio

GDevelop 5.5.221 improves 3D physics tracking and resolves several bugs. This is not a security update.
https://gdevelop.io/download

GitHub Desktop 3.4.12 resolves a merge bug. This is not a security update.
https://desktop.github.com/

Inno Setup 6.4.0 updates libraries and resolves dozens of bugs. This is not a security update.
https://www.jrsoftware.org/isdl.php

Node.js 22.13.0 updates dependencies and resolves dozens of bugs. This is not a security update.
https://nodejs.org/en/

Node.js 23.6.0 updates dependencies and resolves dozens of bugs. This is not a security update.
https://nodejs.org/en/

SQLite 3.48.0 adds several new features, syntax support, and performance and memory improvements. This is not a security update.
https://www.sqlite.org/download.html

Visual Studio Code 1.96.2 resolves several bugs. This is not a security update.
https://code.visualstudio.com/

Web Package Updates

These are likely to be of interest only to web developers.

Grocy 4.3.0 improves stock management, grouping, recipes, userfields, and resolves several bugs. This is not a security update.
https://github.com/grocy/grocy

HumHub 1.17.0 resolves over a dozen bugs. This is not a security update.
https://www.humhub.com/en

Joomla 5.2.3 is a security update.
https://www.joomla.org/

OpenCart 4.1.0.0 makes over six hundred changes and updates libraries. This should be treated as a security update.
https://www.opencart.com/

Piwigo 15.3.0 resolves a stability bug. This is not a security update.
https://piwigo.org/

Autoptimize 3.1.13 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/autoptimize/

Contact Form 7 6.0.3 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/contact-form-7/

Sucuri Security 1.9.7 adds CSP reporting header support. This is not a security update.
https://wordpress.org/extend/plugins/sucuri-scanner/

Theme My Login 7.1.10 resolves several bugs, including a nonce issue. This should be treated as a security update.
https://wordpress.org/extend/plugins/theme-my-login/

WP Cerber Security 9.6.5 removes dependency on wordpress.org, adds several new widgets and improves role support. This is not a security update.
https://wpcerber.com/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2024-09-10

Welcome back, Folks!

Today is Patch Tuesday for September, 2024.

We’re one month closer to the next build of Windows 11 and the next release of macOS, both due in mere weeks. A new major version of Office (aka Microsoft 365) is due at the same time, as well.

When the new build of Windows 11 is released all versions of Windows 11 prior to 23H2 will no longer be supported. Upgrade to 23H2 now if you have not done so yet, then do not upgrade to 24H2 when it is released. Let everyone else be the guinea pigs.

When the new build of macOS is released all versions of macOS prior to 13/Ventura will no longer be supported. If you can’t upgrade your Mac to Ventura you need to switch it to Linux or replace it.

Windows 10 now has only 13 months of support left. If your computer can not be upgraded to Windows 11 either start planning for a switch to Linux or replacing your computer.

There were 310+ major hacks, and over 200 application updates this month.
It’s a relatively small month, with only about 2.0 GB of updates for most users.

This Month in Technology

ABC Parts International, Acadian Ambulance, Adina Design, Advanced Medical Management, LLC, Aioi Nissay Dowa Insurance, Air International Thermal Systems, Akeela, Alabama Cardiology Group, Alcampo, Allergy Medical Group of the North Area, Inc, Ambulnz Holdings, AMD, American Clinical Solutions, an “industrial company” in Somerset County, NJ, an Israeli IT company, Android, Angus Council, Apache OFBiz (Open For Business), Apache Tomcat, Applause, Arden Claims Service, Argentine Air Force, Armour Coatings, Around the Clock Companies, Artifact Uprising LLC, Asus RT-N15U, Australian Cancer Research Foundation, Autel Maxicharger, AutoCanada, Avis, AVTECH CCTV cameras, 15,000 AWS Load Balancers, Azure Health Bot, Baird Mandalas Brockstedt LLC, Baker Places, Inc, Banham Poultry, Bank Rakyat, Baptist Health Medical Center Drew County, Bar2, Barrie, Behavioral Health Alliance of Rural Pennsylvania, Beng Kuang Marine, Benson Kearley IFG, Biggin Hill’s Charles Darwin School, bitcoin hardware wallets (Dark Skippy), Blain Jacobson DMD, CAGS, Blooms Today, Boutiqaat, BPOTech, Bromley GP, BVI Electricity Corporation, Caja Los Andes, CannonDesign, Canvey Island Infant School, Carehands, Carespring Healthcare, Catholic Charities CYO of The Archdiocese of San Francisco, CBIZ Benefits & Insurance Services, Cellular Plus, Centers for Medicare & Medicaid Services, Chevrolet, Chris Leong, CinemaTech, Cisco Identity Services Engine, Cisco Smart Licensing Utility, City of Columbus, OH, City of Flint, MI, City of St. Helena, CA, Clabots, Communication Federal Credit Union, Compex Legal Services Inc, Confidant Health, Connex health portal, Consilium Staffing, Consulting Radiologists LTD, Covenant Care California, LLC, Crain Group, Dahua cameras, Data Bilgi Islem, Davidoff Hutcher & Citron LLP, DBA ATC Home Care, Deutsche Flugsicherung (DFS), Dibcase, Dick’s Sporting Goods, DimeCuba, Dingding Talk, Disney Cruise lines, Disneyland, Domino’s Pizza Singapore, Durex India, Ecovacs, EnglishCentral, Enroll Confidently, Inc, Eric Rossi CPA LLC, Erie Meats, EV infrastructure, Exotel, Explore Talent, External Secrets Operator, Facial Pain Center, Farmers’ Rice Cooperative, Fish Nelson & Holden, FlightAware, Florida Department of Health, Fortra FileCatalyst Workflow, Fota Wildlife Park, Free Russia Foundation, Futurity First Insurance Group, GDB International, GeoServer Project, GitHub Enterprise Server, GiveWP WordPress Plugin, Google Chrome, Gramercy Surgery Center, Granville Recreation District, Greater Manchester Council, Grid Subject Matter Experts, Halliburton, Highline Public Schools, Hospital Sisters Health System, HP Security Manager, HPE HP-UX, IBM webMethods Integration Server, ICWI, Imetame, Imperial Sprinkler, LLC, Infosys McCamish Systems LLC, Institut National des Langues Luxembourg, iPhone, Isuzu Motors International Operations (Thailand), Ivanti Virtual Traffic Manager, Jangho Group, JAS Forwarding, Jenkins, Jewish Home Lifecare, Katz Nannis + Solomon, PC, Keene School District, Kentucky Corrections Department, Keycloak, Keystone Pacific Property Management, Kingdom Trust, King’s Choice, KlockMetal, Kootenai Health, Lake Washington Institute of Technology, Lakeland’s Watson Clinic, LAPOR, Laybuy, LDLC, Leal.co, LiteSpeed Cache WordPress Plugin, Lookiero, Los Angeles County Department of Mental Health, Market Moveis, McDonald’s Instagram, Medical Center Barbour, MedicaMall, Metro Pacific Tollways Corporation, Microchip Technology, Micron Crucial MX500, Microsoft Copilot Studio, Microsoft Entra ID, Microsoft OneNote, Microsoft Outlook, Microsoft Teams, Microsoft Word, Mid-Columbia Center for Living, Mifare Smart Cards, Mill Creek Lumber, Mitsubishi Chemical Group, Mitsui Sumitomo Insurance, Mohawk Valley Cardiology PC, Monobank, Musely AI, Muzu.co, MyFreightWorld, National Oceanic and Atmospheric Administration (NOAA), National Public Data, National Research Council of Italy, NHS Grampian, Okanogan Behavioral HealthCare, Oldham Council, Omicron Granite & Tile, Oregon Zoo, Orion, Packaging Corporation of America, Parker Development Company, ParkTree Community Health Center, Park’N Fly, Patelco Credit Union, PBC Companies, Pi Camera, Planned Parenthood of Montana, Plastix Marketing, Pocahontas Medical Clinic, Policy Administration Solutions, Port of Seattle, PostgreSQL, Prasarana Malaysia, Precom, Progress Software LoadMaster, ProPark Mobility, Public Agency Retirement Services (PARS), Quilvest Capital Partners, Radar/Dispossessor, Radiological Society of North America, RapidCMS, RCG, Regent Caravans, Relevvo, Retail Data, Rhithm Wellness App, Riverside Resort & Casino, Roberto Verino Difusion, Roblox Developers, Rochester Honkers, Rödl Management, SAP, Schlatter Industries, Scott Pharma Solutions, Sea-Tac Airport, Seirus Innovation, SenangPay Malaysia, Service Access & Management, ServiceBridge, Siam Cement Group, Sibanye-Stillwater, siParadigm, Slack, Slim CD, Software Engineering Associates, Solana, SolarWinds Web Help Desk, Sompo Japan Insurance, SonicWall SonicOS, South Carolina State University, South Orange County Community College District, Southwest Family Medicine Associates, Spanish Athletics Federation, Specialty Networks, Sport 2000, Sri Lankan Farmers Community, St. Clair County, IL, Stein Fibers, Stoxkart, Stripe CLI, Strive Medical, Strong Current Enterprises, Supreme Court of Philippines, SWISSCZ, Swissphone DiCal-RED, Tabb Inc, Tamil Nadu Labour Department Data, Taxellent Accounting Services Inc, Tewkesbury Council, Texas Centers for Infectious Disease Associates, Texas Dow Employees Credit Union, The Bakersfield Californian, The SMS Group, ThinkPHP, Thompson Davis & Co, TIAA, Toaping, Tokio Marine & Nichido Fire Insurance, Toronto District School Board, Town of Plymouth, CT, Toyota, toyyibPay, Traccar GPS System, Tracki, Traderie, Transport for London, TRENDnet TEW, Trionfo Solutions, Turkish government, Turning Point of Central California, Inc, UConn Health, UK National Crime Agency, UK Political Party Donation Platforms, Ukrainian government, Unicoin, United Services Automobile Association (USAA), United Urology Group, United Way of Connecticut, Inc, Universal Pure, University of Toronto, US Federal Bureau of Investigation (FBI), US Lottery Corporation, US Marshals Service, US Merchants Financial Group, Inc, US Transportation Security Administration (TSA), Valisana, Veeam services, VeriSource Services, Inc, Verkada, Versa Director, VMware ESXi, VMware VCenter Server, VOP CZ, Wayne Wright, LLP, WazirX, Welcome Health, WellLife Network, Western Electrical Contractors Association, WhatsApp, WinRAR, WPS Office, XPERT Business Solutions GmbH, Young Consulting, YubiKey 5, Zee Media, and Zyxel have reported hacking or compromises this month.

HalliburtonTransport for London, and McLaren Health have suffered from outages this month.

Last months updates broke BitLockerdual-boot (Windows + Linux), Outlook, Word, and Windows.

The National Public Data breach (leak, to be more accurate) has had an interesting turn of events, where they are now claiming that they’ve removed the entire database from their platform (it’s still available everywhere else). Opting out via their platform is dismissed and they offer no resolution. Not that one could be had.

A novel side-channel attack dubbed “RAMBO” (Radiation of Air-gapped Memory Bus for Offense) generates electromagnetic radiation from a device’s RAM to send data from air-gapped computers.

Microsoft has finally removed the defective and half-baked WinRE update causing daily and sometimes hourly errors because it couldn’t install on many devices.

Twitch force-enabled VTubers’ cameras without their consent.

Now for the good news:

The US appeals court had ruled geofence warrants are unconstitutional.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is pretty small this month. The typical computer should see roughly 2 GB in updates today. Let’s get started.

Microsoft released 41 updates to address 79 vulnerabilities in Azure CycleCloud, Azure Network Watcher, Azure Stack, Azure Web Apps, Dynamics Business Central, Microsoft AutoUpdate, Microsoft Dynamics 365, Microsoft Graphics Component, Microsoft Management Console, Microsoft Office Excel, Microsoft Office Publisher, Microsoft Office SharePoint, Microsoft Office Visio, Microsoft Outlook for iOS, Microsoft Streaming Service, Power Automate, SQL Server, Windows Admin Center, Windows AllJoyn API, Windows Authentication Methods, Windows DHCP Server, Windows Hyper-V, Windows Installer, Windows Kerberos, Windows Kernel-Mode Drivers, Windows Libarchive, Windows Mark of the Web (MOTW), Windows MSHTML Platform, Windows Network Address Translation (NAT), Windows Network Virtualization, Windows PowerShell, Windows Remote Access Connection Manager, Windows Remote Desktop Licensing Service, Windows Security Zone Mapping, Windows Setup and Deployment, Windows Standards-Based Storage Management Service, Windows Storage, Windows TCP/IP, Windows Update, Windows Win32K – GRFX, Windows Win32K – ICOMP, and MSRT. This includes security updates. A reboot is required.

Apple released updates for tvOS 17.6.1 and watchOS 10.6.1. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

watchOS 10.6.1 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 17.6.1 is a security update. Use System, Software Update to install the most current version.

Google Chrome OS 126.0.6478.252, 127.0.6533.132 and 128.0.6613.133 are security updates. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sonoma (14.x) means that macOS Big Sur (11.x) and older are no longer supported. If you can not install at least macOS Monterey (12) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v23H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it, but I recommend you continue to use Windows 10 until early 2025 before you consider switching to it.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 24.8.1 adds support for several games, including Concord, for what that’s worth and resolves several bugs.. This is not a security update.
https://www.amd.com/en/support

Crucial Storage Executive 10.07 doesn’t provide a change log so should be treated as a security update.
https://www.crucial.com/support/storage-executive

UniFi Network Server 8.4.59 adds support for Passpoint/Hotspot 2.0, Packet Capture, AP Analyzer, Pro AV and advanced IGMP snppting. This is not a security update.
https://www.ui.com/download/releases/network-server

Wacom Driver 6.4.7-3 resolves several bugs. This is a security update.
https://www.wacom.com/en-us/support/product-support/drivers

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.69.162 is a security update.
https://brave.com/

Firefox 130.0 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Google Chrome 128.0.6613.84 is a security update.
https://www.google.com/chrome/

Microsoft Edge 128.0.2739.67 is a security update.
https://www.microsoft.com/en-us/edge/business/download

SeaMonkey 2.53.19 is a security update.
https://www.seamonkey-project.org/

Vivaldi 6.9.3447.41 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

ProtonMail (Android) 4.0.19.1 resolves several bugs. This is not a security update.
https://proton.me/mail/download

Spark 3.17.6 is a security update.
https://sparkmailapp.com/

Spark (macOS) 3.17.6 is a security update.
https://sparkmailapp.com/

Thunderbird 128.2.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 8.0.14 adds ability for custom clients to disable tray options. This is not a security update.
https://anydesk.com/en/downloads

Dropbox 206.4.6506 doesn’t provide a detailed change log so should be treated as a security update.
https://www.dropbox.com/

Facebook Messenger 215.4.0.14.211 is a security update.
https://www.messenger.com/download

FileZilla Server 1.9.1 is a security update.
https://filezilla-project.org/

Google Drive 96.0 now alerts users to stalls and resolves several bugs. This is not a security update.
https://drive.google.com/start

MeshCentral 1.1.29 resolves dozens of bugs. This is not a security update.
https://meshcentral.com/info/downloads.html

Microsoft Teams 1.7.00.21751 adds reaction support to Town Hall feature. This is not a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 29.0.6 resolves dozens of bugs. This is not a security update.
https://nextcloud.com/

Rclone 1.68.0 adds several new backends, improves S3 support, and resolves dozens of bugs. This is not a security update.
https://rclone.org/

Signal 7.23.0 improves performance. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.15.4 doesn’t provide a detailed change log so should be treated as a security update.
https://signal.org/android/apk/

Syncthing 1.27.12 is a security update.
https://syncthing.net/

Telegram 5.5.3 resolves several bugs. This is not a security update.
https://telegram.org/

Telegram (Android) 11.0.0 doesn’t provide a detailed change log so should be treated as a security update.
https://telegram.org/apps

Trillian 6.5.0.45 resolves several bugs.
https://www.trillian.im/

WinSCP 6.3.5 is a security update.
https://winscp.net/eng/index.php

Zoom 6.1.11.45504 resolves several bugs. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.9 resolves several bugs. This is not a security update.
https://en.3tene.com/

Bitwig Studio 5.2.3 improves hardware support and resolves a key binding error. This is not a security update.
https://www.bitwig.com/download/

Grayjay 262 adds recommendations, improved comment system, and resolves several bugs. This is not a security update.
https://grayjay.app/index.html

Kodi 21.1 is a security update.
https://kodi.tv/

Plex Desktop 1.100.1.221 resolves a season poster display bug. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Home Theater 1.66.1.215 updates the web TV client. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Media Server 1.40.5.8921 is a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.23.01 doesn’t provide a detailed change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

PS5 2024.829 adds URL sharing, improves performance and hardware support. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Acrobat 24.003.20112, 24.001.30187 and 20.005.30680 are security updates.
https://helpx.adobe.com/security/products/acrobat/apsb24-70.html

Adobe Acrobat Reader 24.003.20112 and 20.005.30680 are security updates.
https://helpx.adobe.com/security/products/acrobat/apsb24-70.html

Adobe After Effects 24.6 and 23.6.9 are security updates.
https://helpx.adobe.com/security/products/after_effects/apsb24-55.html

Adobe Audition 24.6 and 23.6.9 are security updates.
https://helpx.adobe.com/security/products/audition/apsb24-54.html

Adobe ColdFusion 2023.10 and 2021.16 are security updates.
https://helpx.adobe.com/security/products/coldfusion/apsb24-71.html

Adobe Illustrator 28.7.1 and 27.9.6 are security updates.
https://helpx.adobe.com/security/products/illustrator/apsb24-66.html

Adobe Media Encoder 24.6 and 23.6.9 are security updates.
https://helpx.adobe.com/security/products/media-encoder/apsb24-53.html

Adobe Photoshop 24.7.5 and 25.12 are security updates.
https://helpx.adobe.com/security/products/photoshop/apsb24-72.html

Adobe Premiere Pro 24.6 and 23.6.9 are security updates.
https://helpx.adobe.com/security/products/premiere_pro/apsb24-58.html

Audacity 3.6.3 resolves several bugs. This is not a security update.
https://www.audacityteam.org/download/

Blender 4.2.1 doesn’t provide a detailed change log so should be treated as a security update.
https://www.blender.org/download/

Calibre 7.17.0 adds paper-edition page number support, editing, and resolves several bugs. This is not a security update.
https://calibre-ebook.com/

Formatta Filler 8.19.04 doesn’t provide a change log so should be treated as a security update.
https://www.phreesia.com/filler-ifiller/

Kdenlive 24.08.0 improves user interface for easing modes, effect groups, transform, and curve, as well as several bug fixes. This is not a security update.
https://kdenlive.org/

Kindle for PC 2.5.70951 doesn’t provide a change log so should be treated as a security update.
https://www.amazon.com/kindleforpc

LibreOffice 24.2.6 resolves over 40 bugs. This is a security update.
https://www.libreoffice.org/

LibreOffice Fresh 24.8.0 resolves over 400 bugs. This is a security update. The “Fresh” line is beta software and should be avoided by most people.
https://www.libreoffice.org/

Manager 24.9.9.1845 adds a business template gallery and support for Financial Data Exchange (FDX). This is not a security update.
https://www.manager.io/

Nextcloud Desktop 3.13.3 resolves almost 100 bugs. This is not a security update.
https://nextcloud.com/

PDF-XChange Editor 10.4.0.388 resolves dozens of bugs. This is a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

QuickBooks Pro 2022 20240726-R17_22 doesn’t provide a detailed change log so should be treated as a security update.
https://downloads.quickbooks.com/app/qbdt/products

QuickBooks Pro 2023 20240726-R14_25 doesn’t provide a detailed change log so should be treated as a security update.
https://downloads.quickbooks.com/app/qbdt/products

Scribus 1.6.2 resolves several bugs. This should be treated as a security update.
https://www.scribus.net/

Security Software Updates

One or more of these is likely to be of interest to most people.

Chainsaw 2.10.0 resolves several bugs and adds Key/Value container support.
https://github.com/countercept/chainsaw

FSS 2024.8.15 doesn’t provide a detailed change log so should be treated as a security update.
https://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/

MalwareBytes Anti-Malware 5.1.10.127 resolves several bugs. This is not a security update.
https://www.malwarebytes.org/antimalware/

OpenSSL 3.3.2 is a security update.
https://slproweb.com/products/Win32OpenSSL.html

ProtonVPN (macOS) 4.4.0 resolves several bugs and improves stability. This is not a security update.
https://protonvpn.com/download

RogueKiller 15.18.2 resolves several bugs. This is not a secuirty update.
https://www.adlice.com/download/roguekiller/

SecurityCheck 2024.8.24 doesn’t provide a detailed change log so should be treated as a security update.
https://www.bleepingcomputer.com/download/securitycheck/dl/123/

Stinger 13.0.0.190 adds support for new detections. Thsi is not a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

Tails 6.7 is a security update.
https://tails.net/install/download/index.en.html

VT-CLI 1.0.1 adds support for Chocolatey, updates actions and resolves several bugs. This is not a security update.
https://github.com/VirusTotal/vt-cli/releases/latest

YARA 4.5.2 is a security update.
https://github.com/VirusTotal/yara/

Capture Updates

These are unlikely to be of interest to most people.

Open Broadcaster Software 30.2.3 resolves several bugs. This is a security update.
https://obsproject.com/

ScreenToGif 2.41.1 updates translatons and resolves a couple bugs. This is not a security update.
https://github.com/NickeManarin/ScreenToGif/releases/latest

SnagIt 24.2.2 adds support for HDR image capture and exporting to Camtasia, and resolves a PDF export bug. This is not a security update.
https://www.techsmith.com/screen-capture.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.2.6 adds support for new encodings and resolves compatibility issues with some hardware. This is not a security update.
https://www.dvdfab.cn/download.htm

PDF Creator 5.3.0 adds OneDrive integration, improved sharing support, and updated libraries. This is a security update.
https://www.pdfforge.org/pdfcreator

StreamFab 6.1.9.7 resolves dozens of bugs and adds a couple new sources. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 2.0.3.3 adds GPU support, ability to remove the scene background, and resolves a few bugs. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Education updates

One or more of these are likely to be of interest to most people.

Zotero 7.0.3 adds rich text markup in titles, improves compatibility, and resolves several bugs. This is not a security update.
https://www.zotero.org/

Utility Updates

These are unlikely to be of interest to most people.

1Password for Mac 8.10.44 adds filtering support, visual and accessibility improvements, and resolves several bugs. This is not a security update.
https://1password.com/downloads/mac/

1Password for Windows 8.10.45 adds filtering support, visual and accessibility improvements, improves compatibility, and resolves several bugs. This is not a security update.
https://1password.com/downloads/windows/

AOMEI Partition Assistant 10.4.2 improves reliability and stability, and resolves several bugs. This is not a security update.
https://www.diskpart.com/

balenaEtcher 1.19.22 replaces Flowzone inputs. This is not a security update.
https://etcher.balena.io/

Beyond Compare 5.0.2.30045 resolves over a dozen bugs. This is not a security update.
https://www.scootersoftware.com/download

Bitwarden 2024.8.2 adds support for autofill cards and identities using keyboard shortcuts, biometrics on Linux, and password-protected exports
https://bitwarden.com/

CalyxOS Device Flasher 1.0.10 doesn’t provide a detailed change log so should be treated as a security update.
https://calyxos.org/install/

CCleaner 6.27.11214 resolves several bugs. This is not a security update.
https://www.ccleaner.com/

Cygwin 3.5.4 resolves several bugs. This is a security update.
https://cygwin.com/

Dell Command Update 5.4.0 improves reliability and stability. This is not a security update.
https://www.dell.com/support/article/us/en/04/sln311129/dell-command-update?lang=en

DesktopOK 11.35 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.2.59.0 adds several new display options, improved performance and translations, and updates libraries. This is a security update.
https://dngrep.github.io/

Everything Toolbar 1.4.1 resovles a sort order bug. This is not a security update.
https://github.com/stnkl/EverythingToolbar/

ExplorerPatcher 22621.3880.66.5 resolves adds Windows 10 Taskbar Style support (with extra steps) and Windows 11 24H2 compatibility. This is not a security update.
https://github.com/valinet/ExplorerPatcher/

FolderChangesView 2.37 is a cosmetic update. This is not a security update.
https://www.nirsoft.net/utils/folder_changes_view.html

GoodSync 12.7.5 resolves dozens of bugs. This is not a security update.
https://www.goodsync.com/

HWiNFO 8.10 adds support for newer hardware. This is not a security update.
https://www.hwinfo.com/download/

InstalledAppView 1.09 adds dark mode support. This is not a security update.
https://www.nirsoft.net/utils/installed_app_view.html

Kingston SSD Manager 1.5.4.6 doesn’t provide a detailed change log so should be treated as a security update.
https://www.kingston.com/us/support/technical/ssdmanager

Mac Migration Assistant 3.0.1.0 doesn’t provide a detailed change log so should be treated as a security update.
https://support.apple.com/en-us/HT204087

NConvert 7.192 doesn’t provide a detailed change log so should be treated as a security update.
https://www.xnview.com/en/nconvert/

NTLite 2024.8.10045 adds support to disable MSA and resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

OSForensics 11.0.1010 resolves over a dozen bugs. This is not a security update.
https://www.osforensics.com/download.html

osquery 5.13.1 resolves a bug. This is not a security update.
https://osquery.io/downloads

PowerToys 0.84.1 resolves several bugs and improves behavior of many apps. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

PSAppDeploy 3.10.2 resolves a dozen bugs. This is not a security update.
https://psappdeploytoolkit.com/

ripgrep 14.1.1 resolves a couple bugs. Thsi is not a security update.
https://github.com/BurntSushi/ripgrep/releases/latest

ScreenConnect 24.2.10.8991 resolves several bugs. This is a security update.
https://screenconnect.connectwise.com/download

SearchMyFiles 3.30 adds support to search by owner. This is not a security update.
https://www.nirsoft.net/utils/search_my_files.html

TeamViewer 15.57.5 resolves several bugs. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/

WifiInfoView 2.94 adds dark mode support. This is not a security update.
https://www.nirsoft.net/utils/wifi_information_view.html

WinScan2PDF 8.93 improves hardware support and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 2024.1.2.12 resolves dozens of bugs. This is not a security update.
https://developer.android.com/studio

GameMaker Studio 2024.8.1.171 adds dozens of features. This is not a security update.
https://www.yoyogames.com/en/gamemaker

GDevelop 5.4.211 improves stability and resolves several bugs. This is not a security update.
https://gdevelop.io/download

GitHub Desktop 3.4.5 adds support for custom editors and shells and resolves several bugs. This is not a security update.
https://desktop.github.com/

Go 1.23.1 is a security update.
https://go.dev/

Godot 4.3 updates libraries, adds thousands of improvements, and resolves hundreds of bugs. This is not a security update.
https://godotengine.org/

Godot 3.6 updates libraries and resolves dozens of bugs. This is not a security update.
https://godotengine.org/

MySQL Server 8.0.39 resolves several bugs. This is not a security update.
https://dev.mysql.com/downloads/installer/

Node.js 20.17.0 resolves dozens of bugs and updates libraries. This is not a security update.
https://nodejs.org/en/

Node.js 22.8.0 resolves dozens of bugs and updates libraries. This is not a security update.
https://nodejs.org/en/

Python 3.12.6 is a security update.
https://www.python.org/downloads/windows/

Unreal Engine 5.4 improves layered control rigs, adds new gizmos, constraints improvements, cosmetic improvements, and resolves several bugs. This is not a security update.
https://unrealengine.com/en-US/

Visual Studio Code 1.93 improves IntelliSense, column resizing, source control, Copilot integration and resolves several bugs. This is not a security update.
https://code.visualstudio.com/

Web Package Updates

These are likely to be of interest only to web developers.

HumHub 1.16.2 resolves dozens of bugs. This is not a security update.
https://www.humhub.com/en

Joomla 5.1.4 is a bug fix release shortly after a security update.
https://www.joomla.org/

MailEnable 10.49 resolves over a dozen bugs. This is a security update.
https://www.mailenable.com/

WordPress 6.6.2 resolves over a dozen bugs. This is not a security update.
https://wordpress.org/

BuddyPress 14.1.0 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/buddypress/

Conditional Widgets 3.2 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/conditional-widgets/

My Sticky Bar 2.7.7 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/mystickymenu/

Sucuri Security 1.9.4 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/sucuri-scanner/

Theme My Login 7.1.9 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/theme-my-login/

WPBakery 7.9 resolves over a dozen bugs and improves compatibility. This is not a security update.
https://wpbakery.com/

WP Cerber Security 9.6.3 adds ability to scan for and resolve third-party plugin issues, and resolves several bugs. This is not a security update.
https://wpcerber.com/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

 

Updates 2024-07-09

Today is Patch Tuesday for July, 2024.

There were 330+ major hacks, and over 360 application updates this month. It’s an average month, with about 3.0 GB of updates for most users.

This Month in Technology

3GL Technology Solutions, 50 Cent, Acrotech Biopharma Inc, Adobe Commerce and Magento, Advance Auto Parts, AEG Presents, LLC, Affirm, Agrani Bank, Agropur, Airtel, AJE Group, Alabama Education Department, Altoona Logan Township Mobile Medical Emergency Department Authority, Ambulnz Holdings, LLC, AMD, Amper Group, Amtrak, Android, Ann & Robert H. Lurie Children’s Hospital of Chicago, ANY.RUN, Apple, Arcis Golf, Árvakur, ASI, Association of Texas Professional Educators, Aultman Hospital, Authy, Baltimore 311 callers, Behavioral Health Response, Belle Tire, Benefit Management, Better Business Bureau, Bharat Sanchar Nigam Limited (BSNL), Bol d’air France, BootCDN, Bootcss, Brainworks Software, Bunger Steel, Cambridge University Press & Assessment, Canara Bank, CareDx, Inc, CDK Global (twice), Center for Digestive Health, Center for Human Capital Innovation, Change Healthcare, Channel 7 News Australia, Chicha San Chen, Chroma Color, Circle K Atlanta, CISA Chemical Security Assessment Tool (CSAT), Cisco Nexus switches, Cisco NX-OS, City of Cleveland, Ohio, City Of Coon Rapids, City of Helsinki, Finland, City of Newburgh, NY, Class Advisors, Coca Cola, Cognizant Open Insurance Policy Administration, CoinStats, Conference USA, Consulting Radiologists Ltd, Creative Realities, Credit Suisse, CredRight, Critchfield & Johnston, Crown Equipment, CTG Brands, CTSystem, Cukierski Associates LLC, Custom Concrete, D-Link DIR-859, Datamate Bookkeeping & Tax, Inc, DaVita Inc, Daystar, Derby School, Derbyshire County Council, Designed Receivable Solutions, Inc, Deskcenter, DG3 North America, Inc, Diogenet SR, Docker containers, Dordt University, Eagle Materials, Egyptian Health Department, Ejército del Per, Elite Fitness, Elite Limousine Plus Inc, Elyria Foundry, EqualizeRCM, Ernst & Young LLP, Escondido Union High School District, Esquerra Republicana de Catalunya, Ethereum’s mailing list provider, eVeridis, Evolve Bank & Trust, Facebook PrestaShop module, Fareri Associates, FBT Transport, Financial Business and Consumer Solutions, Inc, Florida Department of Health, Fortra FileCatalyst Workflow, Francesco Parisi, French Diplomats, Fédération Internationale de l’Automobile (FIA – Formula 1), GBA GROUP, GCash, Geisinger Healthcare, Ghostscript library, GitLab, GlobalWafers, Globe Life, Goodman Reichwald-Dodge, GoodTemps, Google Chrome, Gorrie-Regan, Grandstream GXP2135, Great Lakes International Trading, Greylock McKinnon Associates, Inc, Grupo Amper, HackerOne, Harvey Construction, HealthEquity, Hedrick Brothers Construction, Hey You, Highland Health Systems, HubSpot, Human Technology Inc, Husky Owners, Hydmech, INDA’s, India’s National Disaster Management Authority (NDMA), India’s Regional Cancer Centre, Indonesia’s National Data Center, Indonesian Directorate General of Civil Aviation, Infosys McCamish Systems, Innerspec Technologies, Innomar Strategies, Intel CPUs (Indirector), Internal Revenue Service (IRS), Internal Security Operations Command (ISOC), Island Transportation Corp, JM Thompson, Jollibee Group, Jordan’s Ministry of Education, Juniper Networks Session Smart Router, Juniper Networks Session Smart Conductor, Juniper Networks WAN Assurance Router, Kadokawa Corporation, Kairos Health Arizona, Inc, Kansas City, Kansas Police Department, KBC Zagreb, Key Benefit, Kinter, Kito Canada, Kraken crypto exchange, Ladco, Lake Medical Group, Landmark Life, Learnosity, Legend Properties, Inc, Len Dubois Trucking, LevelOne WBR-6013, Levi Strauss, Lexibar, Lindex Group, LivaNova, Longview Oral & Maxillofacial Surgery, Los Angeles County Department of Public Health, Louisiana Special School District, Mailcow Mail Server, Manchester City Football, Maryhaven, Mass General Brigham, Maxicare, MD Now Urgent Care, MEL Aviation Ltd, Mercku, MGF Sourcing, Microsoft Azure Machine Learning Services, Microsoft email, Microsoft O365, Microsoft PlayReady DRM, Middletown Township, Mitsubishi Electric Software, ModPlan, Mount Kisco Surgery, Mountjoy, MOVEit, National Identity Management Commission of Nigeria, National Publisher Services LLC, Neiman Marcus, NetOne, Niconico, OCEANAIR, Olson & Co Steel, Opaxe, OpenAI (twice), OpenSSH server, P Kaufmann, Palomar Health Medical Group, Patelco Credit Union, Payne & Jones, Pediatric Urology Associates, Peterbilt of Atlanta, Philippine Health Insurance Corporation, Philippine Maritime Authority, Phoenix SecureCore UEFI firmware, Pinnacle Orthopaedics & Sports Medicine Specialists LLC, Planar, Plavan Commercial Fueling Inc (“P-Fleet”), Polyfill.io, Prairie Athletic Club, Privia Medical Group of Georgia, Progress MOVEit Transfer, Progress Software Corporation WhatsUp Gold, ProMotion Holdings, Providence Mission Heritage Endocrinology, Prudential Financial, PT Latinusa, Puyallup Tribe, Radiology and Imaging Specialists, Rappi, REA Wire, Realtek rtl819x, Rejetto HTTP File Server (HFS), Rider, Roblox Developer Conference, Rockford Public School District, Rockwell Automation’s PanelView Plus, Rolls-Royce, Sacred Heart Community Service, Samaritan Health Services, Inc, Sanyo Shokai, Scout Energy Partners, Scrubs And Beyond, Seagulf Marine Industries, Sensory Spectrum, Sharp printers, Shinnick & Ryan, Shoe Zone, Shopify third-party app, SiriusXM, Sirva, SkinCure Oncology, Sky-light, SkyPartsUSA, SlowMist, Smartweb, Sofidel, SolarWinds Serv-U, South Africa’s National Health Laboratory Service, SouthCoast Health, Special Health Resources, Spike Chunsoft, Staticfile, Steps to Life, Suminoe, Synnovis Pathology, Taj Hotel Group, TeamViewer, TETRA Technologies, Texas Recycling, Texas Retina Associates, The Ambulatory Surgery Center of Westchester, The Northwestern Mutual Life Insurance Company, The Union Labor Life Insurance Company, Ticketmaster LLC, Toshiba printers, Total Fitness, Tp-Link ER7206 Omada Gigabit VPN Router, TPI, TPOCC, Traderie, Transit Mutual Insurance Corporation, Transport Laberge, Trisun Land Services, Truist Bank, Turkish Government Websites, Twilio, UEFA, UK Post Office, US Dermatology Partners, UwU Lend, Vanguard, Vanna AI, Ventura County Credit Union, Victoria Racing Club, VirtualBox, Virum Apotek, Waupaca County, WI, West Clermont Schools, Western Mechanical, Westview Co-op, Wind Composite Services Group, LLC, Windows Wi-Fi driver (still vulnerable!), Wisconsin Department of Health Services, Wise Payments, Woodruff-Sawyer & Co, WordPress.org, World inquest, Yieldstreet, Zadig & Voltaire, Zaire National Health Laboratory Services, Zerto, Zimbabwe Anti-Corruption Commission, and Zotac have reported hacking or compromises this month.

CDK GlobalCloudflare, OVHcloud, and Xbox Live have suffered from outages this month.

Last months updates broke AuthLite on Domain Controllers, Windows Update, Show Desktop preferences, Windows Taskbar, Windows language packs, and Windows virtualization services.

A new proof-of-concept (SnailLoad) demonstrates how to exploit latency to track a victim’s online activity.

Microsoft’s WSUS driver synchronization will be going away along with WordPad.

The Supreme Court has struck down efforts to hold the federal government responsible for their violations of the first amendment. The US federal government has proven itself impotent to investigate SolarWinds for the most significant hack of all time.

Now for the good news:

The EU Commission has put Meta on notice that their “pay or consent” model breaches EU law.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is about average this month. The typical computer should see roughly 3.0 GB in updates today. Let’s get started.

Microsoft released updates to address 143 vulnerabilities in .NET and Visual Studio, Active Directory Federation Services, Active Directory Rights Management Services, Azure CycleCloud, Azure DevOps, Azure Kinect SDK, Azure Network Watcher, Intel, Line Printer Daemon Service (LPD), Microsoft Defender for IoT, Microsoft Dynamics, Microsoft Graphics Component, Microsoft Office, Microsoft Office Outlook, Microsoft Office SharePoint, Microsoft Streaming Service, Microsoft Windows Codecs Library, Microsoft WS-Discovery, NDIS, NPS RADIUS Server, Role: Active Directory Certificate Services; Active Directory Domain Services, Role: Windows Hyper-V, SQL Server, Windows BitLocker, Windows COM Session, Windows CoreMessaging, Windows Cryptographic Services, Windows DHCP Server, Windows Distributed Transaction Coordinator, Windows Enroll Engine, Windows Fax and Scan Service, Windows Filtering, Windows Image Acquisition, Windows Internet Connection Sharing (ICS), Windows iSCSI, Windows Kernel, Windows Kernel-Mode Drivers, Windows LockDown Policy (WLDP), Windows Message Queuing, Windows MSHTML Platform, Windows MultiPoint Services, Windows NTLM, Windows Online Certificate Status Protocol (OCSP), Windows Performance Monitor, Windows PowerShell, Windows Remote Access Connection Manager, Windows Remote Desktop, Windows Remote Desktop Licensing Service, Windows Secure Boot, Windows Server Backup, Windows TCP/IP, Windows Themes, Windows Win32 Kernel Subsystem, Windows Win32K – GRFX, Windows Win32K – ICOMP, Windows Workstation Service, XBox Crypto Graphic Services, and MSRT. This includes security updates. A reboot is required.

Apple released updates for AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

Google Chrome OS 126.0.6478.132 and 120.0.6099.315 are security updates. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sonoma (14.x) means that macOS Big Sur (11.x) and older are no longer supported. If you can not install at least macOS Monterey (12) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v23H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it, but I recommend you continue to use Windows 10 until early 2025 before you consider switching to it.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AirPods Firmware Update 6A326 is a security update.
https://support.apple.com/HT214111

AirPods Firmware Update 6F8 is a security update.
https://support.apple.com/HT214111

AMD Adrenalin 24.6.1 resolves several bugs and improves compatibility. This is not a security update.
https://www.amd.com/en/support

Beats Firmware Update 6F8 is a security update.
https://support.apple.com/HT214111

Nvidia Driver 475.14 is a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

TP-Link Archer AX72 v1.60 240426 is a security update.
https://www.tp-link.com/us/support/download/archer-ax72-pro/#Firmware

UniFi U6 Professional 6.6.73 resolves dozens of bugs. This is not a security update.
https://www.ui.com/download/software/u6-pro

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.67.123 is a security update. Use Menu, Help, About to install the most current version.
https://brave.com/

Firefox 128.0 is a security update. Use Menu, Help, About to install the most current version.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 128.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Google Chrome 126.0.6478.126 is a security update. Use Menu, Help, About to install the most current version.
https://www.google.com/chrome/

Microsoft Edge 126.0.2592.87 is a security update. Use Menu, Help, About to install the most current version.
https://www.microsoft.com/en-us/edge/business/download

Vivaldi 6.8.3381.46 is a security update. Use Menu, Help, About to install the most current version.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

OutlookAttachView 3.53 resolves a stray field at the end of exported data. This is not a security update.
https://www.nirsoft.net/utils/outlook_attachment.html

ProtonMail (Android) 4.0.15 improves security and message header view. This is a security update.
https://proton.me/mail/download

Spark 3.16.7.78552 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.16.7.78551 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 115.12.2 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

Dropbox 202.4.5551 resolves several bugs. This is not a security update.
https://www.dropbox.com/

Facebook Messenger 215.2.0.11.211 is a security update.
https://www.messenger.com/download

FreeFileSync 13.7 adds symlink support and resolves a couple bugs. This is not a security update.
https://www.freefilesync.org/download.php

Google Drive 92.0 doesn’t provide a detailed change log so should be treated as a security update.
https://drive.google.com/start

Microsoft Teams 1.7.00.17051 improves third-party app experience and adds bookable desks. This is not a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 29.0.3 updates dependencies and resolves several bugs. This is not a security update.
https://nextcloud.com/

Rclone 1.67.0 is a security update.
https://rclone.org/

Signal 7.15.0 resolves several bugs. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.10.3 improves linked devices. This is not a security update.
https://signal.org/android/apk/

Syncthing 1.27.9 resolves several bugs and updates dependencies. This is not a security update.
https://syncthing.net/

Technitium DNS Server 12.2.1 resolves a couple bugs. This is not a security update.
https://technitium.com/dns/

Telegram 5.2.3 resolves several bugs. This is not a security update.
https://telegram.org/

Telegram (Android) 10.14.3 updates libraries and resolves several bugs. This is not a security update.
https://telegram.org/apps

Trillian 6.5.0.40 resolves dozens of bugs. This should be treated as a security update.
https://www.trillian.im/

Trillian Mac 6.5.0.43 doesn’t provide a change log so should be treated as a security update.
https://www.trillian.im/

Zoom 6.1.1.41705 resolves several bugs. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.6 resolves a user interface bug. This is not a security update.
https://en.3tene.com/

darktable 4.8.0 adds a color equalizer, canvas enlargement, overlay support, performance improvements and resolves over 50 bugs. This is not a security update.
https://www.darktable.org/

Grayjay 249 adds support for Spotify, YouTube Channel Playlists, Nebula, Odysee, and resolves several bugs. This is not a security update.
https://grayjay.app/index.html

KaraFun Player 2.6.2.0 doesn’t provide a detailed change log so should be treated as a security update.
https://www.karafun.com/karaokeplayer/

Plex Desktop 1.96.0.177 resolves a bug displaying Genre. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Home Theater 1.64.0.170 updates libraries. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Media Server 1.40.3.8555 resolves several bugs and adds automatic 64-bit upgrade to 32-bit installs on 64-bit hardware. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Bedrock) 1.21.2.02 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server/bedrock

Minecraft Server (Java) 1.21 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server

PS5 2024.702 resolves several bugs. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2024-06-20 resolves several bugs. This is not a security update.
https://store.steampowered.com/news/app/593110

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Reader DC 24.002.20895 resolves several bugs. This is not a security update.
https://get.adobe.com/reader

Adobe Premiere Pro 24.5 and 23.6.7 are security updates.
https://helpx.adobe.com/security/products/premiere_pro/apsb24-46.html

Adobe InDesign 19.4 and 18.5.3 are security updates
https://helpx.adobe.com/security/products/indesign/apsb24-48.html

Adobe Bridge 13.0.8 and 14.1.1 are security updates.
https://helpx.adobe.com/security/products/bridge/apsb24-51.html

Artweaver 7.0.17 resolves several bugs. This is not a security update.
https://www.artweaver.de/

Calibre 7.13.0 adds ability to generate a CSV catalog and resolves several bugs. This is not a security update.
https://calibre-ebook.com/

GnuCash 5.8 adds ability to move accounts into sub-accounts of another account. This is not a security update.
https://www.gnucash.org/

Kdenlive 24.05.2 resolves dozens of bugs. This is not a security update.
https://kdenlive.org/

Kindle for PC 2.4.70904 doesn’t provide a change log so should be treated as a security update.
https://www.amazon.com/kindleforpc

Krita 5.2.3 resolves 20 bugs. This is not a security update.
https://krita.org/en/download/

Manager 24.7.7.1713 doesn’t provide a detailed change log so should be treated as a security update.
https://www.manager.io/

Nextcloud Desktop 3.13.2 resolves a couple bugs. This should be treated as a security update.
https://nextcloud.com/

PDF-XChange Editor 10.3.1.387 adds several new settings and resolves dozens of bugs. This is a security update.
https://www.pdf-xchange.com/product/pdf-xchange-editor

QuickBooks Pro 2022 20240529-R16_17 doesn’t provide a detailed change log so should be treated as a security update.
https://downloads.quickbooks.com/app/qbdt/products

QuickBooks Pro 2023 20240529-R13_14 doesn’t provide a detailed change log so should be treated as a security update.
https://downloads.quickbooks.com/app/qbdt/products

Security Software Updates

One or more of these is likely to be of interest to most people.

Chainsaw 2.9.1-2 improves CLI and dump support, and fixes macOS builds. This is not a security update.
https://github.com/countercept/chainsaw

FSS 2024.6.20 doesn’t have a change log so should be treated as a security update.
https://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/

JShelter 0.18.1 resolves several bugs. This is not a security update.
https://jshelter.org/install/

RogueKiller 15.17.4 resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

SanDisk PrivateAccess 6.4.11.0 doesn’t provide a change log so should be treated as a security update.
https://support-en.wd.com/app/answers/detailweb/a_id/48025

Stinger 13.0.0.138 adds support for several new detections. This is not a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

Tails 6.4 updates libraries and resolves several bugs. This is a security update.
https://tails.net/install/download/index.en.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.2.0 adds support for new encodings and resolves a compatibility bug. This is not a security update.
https://www.dvdfab.cn/download.htm

HandBrake 1.8.1 resolves several bugs and updates libraries. This is not a security update.
https://handbrake.fr/

StreamFab 6.1.8.7 improves compatibility and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 2.0.2.7 improves compatibility and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.10.35 is a security update.
https://1password.com/downloads/

7-Zip 24.07 improves stability. This is not a security update.
https://www.7-zip.org/

AOMEI Partition Assistant 10.4.1 resolves several bugs. This is not a security update.
https://www.diskpart.com/

Beyond Compare 5.0.0.29773 is a major update, adding dark mode, improved wrapping and table behavior, improved media compare, performance improvements and more. This is not a security update.
https://www.scootersoftware.com/download.php?zz=dl4

Bitwarden 2024.6.4 improves legacy migration, administration and self-hosting. This is not a security update.
https://bitwarden.com/

CCleaner 6.25.11131 resolves several bugs. This is not a security update.
https://www.ccleaner.com/

CPU-Z 2.10 adds support for newer hardware. This is not a security update.
https://www.cpuid.com/softwares/cpu-z.html

DesktopOK 11.29 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.2.29.0 resolves several bugs. This is a security update.
https://dngrep.github.io/

Everything Toolbar 1.3.4 resolves several bugs. This is a security update.
https://github.com/stnkl/EverythingToolbar/

ExplorerPatcher 22621.3527.65.5 improves compatibility and resolves several bugs. This is not a security update.
https://github.com/valinet/ExplorerPatcher/

Fido 1.58 removes Windows 8.1 downloads. This is not a security update.
https://github.com/pbatard/Fido/releases

FolderChangesView 2.36 adds option to Save All Items. This is not a security update.
https://www.nirsoft.net/utils/folder_changes_view.html

FoneTool 2.8.0 adds support for iOS 18, ringtone management and fixes bugs in the ringtone maker. This is not a security update.
https://www.fonetool.com/download.html

Go 1.22.5 is a security update.
https://go.dev/

GoodSync 12.7.2 resolves several bugs. This is not a security update.
https://www.goodsync.com/

grepWin 2.1.3 resolves several bugs. This is not a security update.
https://github.com/stefankueng/grepWin/releases/latest

HWiNFO 8.04 improves hardware support and resolves several bugs. This is not a security update.
https://www.hwinfo.com/download/

ManageWirelessNetworks 1.14 adds option to set connection mode. This is not a security update.
https://www.nirsoft.net/utils/manage_wireless_networks.html

NTLite 2024.7.9997 resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

OSForensics 11.0.1008 resolves several bugs. This is not a security update.
https://www.osforensics.com/download.html

PingInfoView 3.15 resolves IPv6 address parsing and menu configuration. This is not a security update.
https://www.nirsoft.net/utils/multiple_ping_tool.html

PowerToys 0.82.0 improves stability and resolves several bugs. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

ProcessMonitor 4.01 adds color display. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/procmon

Recuva 1.54.120 adds license changes. This is not a security update.
https://www.ccleaner.com/recuva

SetUserFTA 1.8.2 doesn’t provide a change log so should be treated as a security update.
https://setuserfta.com/

Speccy 1.33.75 adds support for new hardware and improves licensing. This is not a security update.
https://www.ccleaner.com/speccy

Starwind V2V Converter 9.509 adds support for new conversions and improves performance. This is not a security update.
https://www.starwindsoftware.com/starwind-v2v-converter

WhyNotWin11 2.6.1.0 resolves several bugs. This is not a security update.
https://github.com/rcmaehl/WhyNotWin11

WinGet 1.8.1791 resolves dozens of bugs. This is not a security update.
https://github.com/microsoft/winget-cli/releases/latest

WinScan2PDF 8.88 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

Developer Updates

These are unlikely to be of interest to most people.

.NET Runtime 8.0.7 is a security update.
https://dotnet.microsoft.com/en-us/download/dotnet

Android Studio 2024.1.1.11 doesn’t provide a detailed change log so should be treated as a security update.
https://developer.android.com/studio

AutoHotkey 2.0.18 resolves a couple bugs. This is not a security update.
https://www.autohotkey.com/download/

GameMaker Studio 2024.6.1 resolves several bugs. This is not a security update.
https://www.yoyogames.com/en/gamemaker

GDevelop 5.4.205 improves performance, adds several new actions and variables, and resolves several bugs. This is not a security update.
https://gdevelop.io/download

GitHub Desktop 3.4.2 resolves several bugs. This is not a security update.
https://desktop.github.com/

Inno Setup 6.3.2 resolves a bug in text parsing. This is not a security update.
https://www.jrsoftware.org/isdl.php

MySQL ConnectorNet 9.0.0 resolves several bugs. This is not a security update.
https://dev.mysql.com/downloads/connector/net/

Node.js 18.20.4 is a security update.
https://nodejs.org/en/

Node.js 20.15.1 is a security update.
https://nodejs.org/en/

Node.js 22.4.1 is a security update.
https://nodejs.org/en/

Visual Studio Code 1.91 adds support for several new features. This is not a security update.
https://code.visualstudio.com/

Web Package Updates

These are likely to be of interest only to web developers.

HumHub 1.16.1 improves compatibility and resolves several bugs. This is not a security update.
https://www.humhub.com/en

ISPConfig 3.2.12 resolves several bugs, improves compatibility, and adds a couple new features. This is not a security update.
https://www.ispconfig.org/ispconfig/download/

Joomla 5.1.2 is a security update.
https://www.joomla.org/

ownCloud Client 5.3.1.14018 resolves a linking bug. This is a security update.
https://owncloud.com/desktop-app/

WordPress 6.5.5 is a security update.
https://wordpress.org/

bbPress 2.6.11 resolves over a dozen bugs. This is not a security update.
https://wordpress.org/extend/plugins/bbpress/

Contact Form 7 5.9.6 resolves a compatibility bug. This is not a security update.
https://wordpress.org/extend/plugins/contact-form-7/

Duplicator 1.5.10 resolves several bugs. This is not a security update.
https://wordpress.org/plugins/duplicator/#developers

My Sticky Bar 2.7.1 resolves a button bug. This is not a security update.
https://wordpress.org/extend/plugins/mystickymenu/

NextScripts Social Networks Auto-Poster 4.4.6 is a security update.
https://wordpress.org/extend/plugins/social-networks-auto-poster-facebook-twitter-g/

Sucuri Security 1.9.1 adds support for configuring the cache-control header. This is not a security update.
https://wordpress.org/extend/plugins/sucuri-scanner/

WPBakery 7.7.2 resolves a couple bugs. This is not a security update.
https://wpbakery.com/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2024-06-11

Welcome back, Folks!

Today is Patch Tuesday for June, 2024.

There were 460+ major hacks, and over 270 application updates this month.
It’s an average month, with about 2.5 GB of updates for most users.

This Month in Technology

4LEAF, Inc, A123Systems, Abbott, AbbVie Inc, ABN Amro, ABS-CBN Broadcasting, Absolute Telecom, AC Financial, AC Propulsion, Inc, Acadia Pharmaceuticals Inc, Access Sports Medicine & Orthopaedics, Accounting Professionals LLC Price Breazeale Chastang, ADCOM911, Adobe Acrobat Reader, Advance Auto Parts, Advance Press, Adventist Health Tulare, Affiliated Dermatologists, Agrani Bank, AirAsia Group, Akdenizchemson, Al-Rajhi Bank, Allied Mechanical Services Inc, Allied Telesis, ALN Medical Management, ALO diamonds, Aloft, Alpha Capital Group, Amazon, AmerisourceBergen Specialty Group, Amgen Inc, Amsterdam Schools, Anchorage Daily News, Anderson Mikos Architects, Android, Archi Hives, Architecture Lejeune Giovanelli, Ardenbrook, ARRL, Ascension Healthcare Network, Association of California School Administrators, Asst Rhodense, Astagiudiziaria, Aston Villa, Astra Daihatsu Motor, Atlas Oil, Atlassian Confluence, Audubon Nature Institute, Ausgrid, Aussizz Group, Avelina, Ayoub Associates CPA Firm, B&G Foods, Banco de Crédito del Perú, Barclays, Bausch Health Companies Inc, Bayer Corporation, BBC Pension Scheme, Berge Bulk, Billericay School, Birmingham Children’s Trust, BlockTower Capital, Bluewater Health, BNB Chain, BreachForums, BreingAir, Brett Slater Solicitors, Brick Court Chambers, Bring Me the Horizon’s website, Bristol Myers Squibb, British Columbia Government, Brockton Area Multi-Services, Brovedani Group, Bruno generators, Bulgarian Ports Infrastructure Company, Café Soluble, California Highway Patrol, California Northstate University, Call 4 Health, Inc, Catch News, CDU, Cencora (11 big pharma companies), Center Line schools, Central Contra Costa Transit Authority, CentroMed, Centurion University, Check Point VPN, Chicago Fire Football Club, Christie’s, Cinterion Modems, Cisco Webex, City of Clarksville, City of Helsinki, City of St. Cloud, Clevo, CoinGecko, College Ahuntsic, Columbus Regional Healthcare System, Comwave Networks, Continuing Healthcare Solutions, Cooler Master, Coplosa, Corr Corr, Corse GSM, Cortina Watch, Costa Edutainment SpA, Cox WiFi routers, Crandall ISD, Credit Central, Crescent Point Energy, Cressex Community School, Crooker, Crossroads Equipment Lease & Finance, LLC, Cryptonary, Cushman Contracting Corporation, Cylance, D-Link EXO AX4800 routers, Daniel E. Fitzgerald, CPA, Decathlon, Delano Adult School, Dendreon Pharmaceuticals LLC, DFINITY, DG3 North America, Inc, DGT traffic authority, Digital Pix & Composites, Discovery Insure, Disney, Dkhoon Emirates, DMM, Dohman, Akerlund & Eddy, Dollmar, Doral, Florida, Dota2, DreamWall, Drive Sally, LLC, Driver Group, DRMS, Dubai government, Dynasafe, E-T-A, Easterseals Central Illinois, Eden Project Ltd, Egyptian Universities, Eigen crypto, Electronic Arts, Elk Grove Unified School District, Elmhurst Group, Elutia, EmailGPT, Embellir, Endo Pharmaceuticals Inc, Ernest Health Facilities, ES Pack Euro, Especialistas Contacto Directo, EU Parliament, Everbridge, Ewing Marion Kauffman School, Excel Security Corp, Experis Technology Group, Facebook, Family Guardian, Faultless Brands, FEI Systems, Fic Expertise, Financial Business and Consumer Solutions (FBCS), Fincasrevuelta, First American, FIRST Heritage Co-operative Credit Union, First Nations Health Authority, First Priority Restoration, Firstmac, Fiskars, Fluent Bit, Form I-9 Compliance, Formosa Plastics, Foxit PDF Reader, FPL Food, France Solar, Frontier Communications, Frotcom International, Fulcrum, Gala Games, Gantan Beauty Industry, Gapbuster Worldwide Pty Ltd, GE HealthCare ultrasound devices, Genentech, Inc, Georgia University System, Gestion Kronos, GitLab, GlaxoSmithKline Patient Health, Google (thousands of times), Google Chrome, Google Document AI Warehouse, Granville Food Care Limited, Graphic Solutions Group Inc, Gravetye Manor, Greater Amsterdam School District, Grupo Cadarso, Guardian Analytics, Guardian Childcare Victoria, Gulp, Hamburg Airport, Hatari Electric Co, HawkEye, Hedbergs, Heineken, Helapet Ltd, Heron Therapeutics, Inc, Hit Promotional Products, HopSkipDrive, Hotel Kiosks, HSBC, Hugging Face Spaces, Iberdrola, IBM Cloud, IBM Neural Compressor AI, Illinois Secretary of State, Incyte Corporation, Indigo ENT Group, Interactive Brokers, Inventum Øst, Iranian Hajj, Iranian Pilgrims, Iress, Isaacs Odinocki, Iseto Corporation, Islamabad’s Safe City Authority, Israel-made industrial devices, Israeli Government and Military Infrastructure, ISTA International GmbH, Ivanti EPMM, IZOMAT Praha, J & N Stone, JAVS Courtroom Recording Software, Johnson & Johnson Patient Assistance Foundation, Inc, Johnson & Johnson Services, Inc, Jordano’s Inc, Jumbo Group, Kaiser Permanente, Keytronic, Klein ISD, Knowmad Mood, Kyber Post-Quantum Key Encapsulation Mechanism (KEM), Lactanet, Lane Gorman Trubitt, Lash Group, Laxmi Capital, Lee Shau Kee School of Creativity, LEMKEN, LenelS2 NetBox, Les Miroirs St Antoine Inc, Levin Porter Associates, Lintas Nusa, LivaNova, Live Nation, London Drugs, London Hospitals, Los Angeles Department of Mental Health (LACDMH), Los Angeles Unified School District (LAUSD), M2EConsulting Engineers, MagicLand, MAH Machine, Mainline Health Systems, Malaysia’s Railway Assets Corporation (RAC), Malone & Co, Malouf Companies, Manurewa Marae, NZ census, Marathon Pharmaceuticals, LLC, Marigin, Mariposa Landscapes Inc, Matusima, McLean Hospital, MediSecure, medQ, Inc, MF Group, Microsoft Exchange Server, Microsoft India, Microsoft Quick Assist, Midwest Covenant Home, Morton Williams, My Daily Choice, Inc, Myersville, Maryland, Mālama I Ke Ola Health Center, National Records of Scotland, Native American Health Center, NATO, Natsume Tax Accountant Corporation, Navvis & Company, LLC, Neovia Company, Netflix Genie, New Boston Dental Care, New Hampshire Public Radio, New York Times, Newfoundland Broadcasting Company Limited, Newman Ferrara, Nidec Motor Corporation, Nissan North America, Inc, Normie Meme Coin, North Texas Municipal Water District, Northeast Rehabilitation Hospital Network, Northern Minerals, Novartis Pharmaceuticals Corporation, Ntv, OakBend Medical, OmniVision, OneVue, OpenSea, Oracle WebLogic Server, Osaka Motorcycle Business Cooperative, OTR, Otsuka America Pharmaceutical, Inc, Oxford Global Resources, LLC, PAN-OS, Panasonic Australia, PandaBuy, Panorama Eyecare, Pantana CPA, Patriot Mobile, Patties Foods, pcTattletale, Peak Design, Pendle Token, PepsiCo, Pezesha, Pfizer Inc, Philippine National Police (PNP), Philips Respironics, PHP, Pope & Conner Consulting, Inc, Providence Hospital, PSG Banatski Dvor, Pulse Connect Secure VPN, QNAP NAS, QNAP QTS, Qualitas, QuoteWizard, R3 Education Inc, Rayner Surgical Inc, RDI-USA, Real Madrid CF, Red Bull, Red Cross, Regeneron Pharmaceuticals, Inc, Regional Obstetrical Consultants, Rex Signature Services, LLC, Richland, Washington, Rio Technology, Riyadh Airport, Robinsons Land, Robson, Rockford Public Schools, Rockwell Automation ICS, Royal Star & Garter, Räddningstjänsten Vä stra Blekinge, Samco, Sandoz Inc, Sanok Rubber Company Spólka Akcyjna, Santa Barbara Systems, Santander, Sav-Rx, Scanda, Schuette Metals, Science Po Paris, Seattle Public Library, Semicore Equipment, Service public de Wallonie, Servicio Móvil, Shirasaki, Shore Regional High School District, Sigmund Espeland AS, SLB Transit Inc, Smith and Caughey’s, Snchez-Betances Sifre & Muñoz-Noya, Snowflake, Solana Meme Coin, SonicWALL SSL-VPN, Sonne Finance, Southwark hospitals, Specialty Market Managers, Sree Hotels, SSI World, St. Landry Parish School, State Grid Corporation of China (SGCC), Sterling Transportation Services, Sumitomo Pharma America, Inc, Sumo, Superior Air-Ground Ambulance Service, Sysmex America, Takeda Pharmaceuticals USA, Inc, Talalay Global, Talley Group, Tamil Nadu, Tech in Asia, Telangana Police, Telefónica, Tesla’s Ultra-Wideband, Thayer Academy, The Egyptian-Sudanese Company, The Kelly Group, ThinkPHP, Ticketek Australia, Ticketmaster, Tietoevry, TikTok, Tinyproxy, Tobii Dynavox, Toshiba America, Town of Westlock, Toyota Philippines, TP-Link Archer C5400X, TRC Talent Solutions, Trib Total Media, TriLiteral, Trionfo Solutions, TruGreen, TSCOP App, UAE Ministry of Education, UK Armed Forces, United Urology Group, Universidad Nacional de Entre Ríos, University of Chicago Medical Center, University of Delhi, University of Hyderabad, University of Siena, US Environmental Protection Agency (EPA), Vannguard Utility Partners, Vasitam, Veeam Backup Enterprise Manager, Velocore, Victoria Eye Center, Victorian Freight Specialists, Vietnam Post, Visa Lighting, VIT Bhopal University, VWholesaleTour, Walmart pension plan, Walser Automotive Group, Walton County, Watt Carmicheal, WD Associates, Wealth Depot LLC, WebTPA, Welsh Rugby Union, Western Dovetail, Western Saw Inc, Western Sydney University, William S Hein & Co, Windows Defender, WIS Sicherheit, WordPress, WP Copymatic, WP Country State City Dropdown CF7 Plugin, WP Dessky Snippets, WP Easy Listing Directories, WP Fluent Forms Contact Form, WP Hash Form Drag & Drop Form Builder, WP LiteSpeed Cache, WP Meta SEO, WP Pie Register, WP Slider Revolution, WP Statistics, WP UserPro Plugin, WP Web Directory Free, WP WooCommerce, WPZOOM, XLink Bitcoin Bridge, Zuber Gardner CPA, and Zyxel NAS have reported hacking or compromises this month.

ARRL, TRAM Barcelona, Internet Archive, Queen Alia International Airport, LastPass, and Copilot have suffered from outages this month.

According to a recent study from Kaspersky, 59% of multi-site business experience monthly outages.

Last months updates broke Windows Taskbar, File Explorer, Windows Server 2019 updates, and Microsoft Outlook again, of course.

AI bots are ridiculously easy to convince to share sensitive information.

Apple is releasing a new password manager for macOS, iOS and iPadOS. But…to get an idea of how concerned Apple is about security, they’ve recently exposed that Wi-Fi on their devices can be used to geolocate any device around the globe.

Google is making it harder and harder to get help.

ICQ, my favorite messaging app from the 90s, has shut down after 28 years.

VBscript is on its deathbed.

FTX paid off whistleblowers.

Now for the good news:

Microsoft has reversed course on Windows Recall and is now making it “optional” even though it isn’t actually resolving most of the security issues or privacy risks.

Let’s Get Busy

Patch Tuesday is about average this month. The typical computer should see roughly 2.5 GB in updates today. Let’s get started.

Microsoft released updates to address 58 vulnerabilities in Azure Data Science Virtual Machines, Azure File Sync, Azure Monitor, Azure SDK, Azure Storage Library, Chrome, Dynamics Business Central, GitHub, Microsoft Dynamics, Microsoft Edge, Microsoft Office, Microsoft Office Outlook, Microsoft Office SharePoint, Microsoft Office Word, Microsoft Streaming Service, Microsoft WDAC OLE DB provider for SQL, Microsoft Windows, Microsoft Windows Speech, Visual Studio, Windows Cloud Files Mini Filter Driver, Windows Container Manager Service, Windows Cryptographic Services, Windows DHCP Server, Windows Distributed File System (DFS), Windows Event Logging Service, Windows Kernel, Windows Kernel-Mode Drivers, Windows Link Layer Topology Discovery Protocol, Windows NT OS Kernel, Windows Perception Service, Windows Remote Access Connection Manager, Windows Routing and Remote Access Service (RRAS), Windows Server Service, Windows Standards-Based Storage Management Service, Windows Storage, Windows Themes, Windows Wi-Fi Driver, Windows Win32 Kernel Subsystem, Windows Win32K – GRFX, Winlogon, and MSRT. This includes security updates. A reboot is required.

Apple released updates for tvOS 17.5.1, iOS 17.5.1, iPadOS 17.5.1, and visionOS 1.2. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

iOS 17.5.1 is a security update. Use Settings, General, Software Update to install the most current update.

iPadOS 17.5.1 is a security update. Use Settings, General, Software Update to install the most current update.

tvOS 17.5.1 is a security update. Use System, Software Update to install the most current version.

visionOS 1.2 is a security update. Use Settings, General, Software Update to install the most current version.

Google Chrome OS 125.0.6422.169 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Sonoma (14.x) means that macOS Big Sur (11.x) and older are no longer supported. If you can not install at least macOS Monterey (12) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v23H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it, but I recommend you continue to use Windows 10 until early 2025 before you consider switching to it.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 24.5.1 improves stability and resolves several bugs. This is not a security update.
https://www.amd.com/en/support

Nvidia Driver 475.06 is a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Samsung DeX 2.4.1.23 doesn’t provide a change log so should be treated as a security update.
https://www.samsung.com/us/apps/dex/

UniFi airMAX NanoStation 5AC Loco 8.7.13 resolves several bugs. This is not a security update.
https://www.ui.com/download/software/loco5ac

UniFi Network Server 8.2.93 adds ACL rules, DNS records, MLO, BGP and Inspection support. This is not a security update.
https://www.ui.com/download/releases/network-server

Wacom Driver 6.4.6-2 adds support for newer hardware, improved reliability, and resolves several bugs. This is not a security update.
https://www.wacom.com/en-us/support/product-support/drivers

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.66.118 is a security update.
https://brave.com/

Firefox 127.0 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 115.12.0 is a security update.
https://www.mozilla.org/en-US/firefox/organizations/all/

Google Chrome 125.0.6422.141 is a security update.
https://www.google.com/chrome/

Microsoft Edge 125.0.2535.92 is a security update.
https://www.microsoft.com/en-us/edge/business/download

Vivaldi 6.7.3329.39 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Spark 3.16.2.75403 adds calendar support. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.16.2.75440 adds calendar support. This is not a security update.
https://sparkmailapp.com/

Thunderbird 115.11.1 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk (macOS) 8.1.0 improves performance and resolves several bugs. This is not a security update.
https://anydesk.com/en/downloads

Facebook Messenger 213.0.0.22.228 is a security update.
https://www.messenger.com/download

Microsoft Teams 1.7.00.13456 resolves several bugs and improves user controls. This is not a security update.
https://teams.microsoft.com/downloads

Mumble 1.5.634 adds over a dozen new features and resolves several bugs. This should be treated as a security update.
https://www.mumble.info/

Signal 7.11.1 resolves several bugs. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 7.8.1 doesn’t provide a detailed change log so should be treated as a security update.
https://signal.org/android/apk/

Telegram 5.1.5 improves stability and resolves several bugs. This is not a security update.
https://telegram.org/

Telegram (Android) 10.13.1 doesn’t provide a detailed change log so should be treated as a security update.
https://telegram.org/apps

Tigase Server 8.4.0 adds RBL support, portable export format, improved user management and resolves dozens of bugs. This should be treated as a security update.
https://github.com/tigase/tigase-server/releases/latest

curl 8.8.0 resolves over 200 bugs. This is not a security update.
https://curl.haxx.se/windows/

Dropbox 200.4.7134 resolves several bugs. This is not a security update.
https://www.dropbox.com/

MeshCentral 1.1.23 resolves dozens of bugs. This should be treated as a security update.
https://meshcentral.com/info/downloads.html

Nextcloud Server 29.0.2 resolves over a dozen bugs. This should be treated as a security update.
https://nextcloud.com/

Omada Software Controller 5.14.20.9 adds several new filters, features and controls. This is not a security update.
https://www.tp-link.com/us/support/download/omada-software-controller/

Syncthing 1.27.8 resolves a couple bugs. This is not a security update.
https://syncthing.net/

Zoom 6.0.11.39959 is a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 4.0.5 improves cosmetics and resolves several bugs. This is not a security update.
https://en.3tene.com/

Grayjay 244 improves compatibility and resolves several bugs.
https://grayjay.app/index.html

Plex Desktop 1.94.1.155 doesn’t provide a detailed change log so should be treated as a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Home Theater 1.62.1.152 doesn’t provide a detailed change log so should be treated as a security update.
https://www.plex.tv/media-server-downloads/#plex-app

VLC Media Player 3.0.21 improves hardware compatibility and resolves several bugs. This is a security update.
https://www.videolan.org/vlc/

Game Updates

These are unlikely to be of interest to most people.

Minecraft Server (Java) 1.20.6 doesn’t provide a change log so should be treated as a security update.
https://www.minecraft.net/en-us/download/server

Nintendo Switch 18.1.0 removes X/Twitter and social media integration and improves stability. This is not a security update.
https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/system%20updates/p/989

PS5 2024.522 improves performance and stability and resolves several bugs. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2024-05-21 resolves several bugs. This is not a security update.
https://store.steampowered.com/news/app/593110

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Acrobat Android 24.5.0.33694 is a security update.
https://helpx.adobe.com/security/products/acrobat-android/apsb24-50.html

Adobe Audition 23.6.6 and 24.4.1 are security updates.
https://helpx.adobe.com/security/products/audition/apsb24-32.html

Adobe ColdFusion 2021.14 and 2023.8 are security updates.
https://helpx.adobe.com/security/products/coldfusion/apsb24-41.html

Adobe Commerce 2.4.0-ext-8, 2.4.1-ext-8, 2.4.2-ext-8, 2.4.3-ext-8, 2.4.4-p9, 2.4.5-p8, 2.4.6-p6 and 2.4.7-p1 are security updates.
https://helpx.adobe.com/security/products/magento/apsb24-40.html

Adobe Commerce Webhooks Plugin 1.5.0 is a security update.
https://helpx.adobe.com/security/products/magento/apsb24-40.html

Adobe Creative Cloud Desktop 6.2.0.554 is a security update.
https://helpx.adobe.com/security/products/creative-cloud/apsb24-44.html

Adobe Experience Manager 2024.5 and 6.5.21 are security updates.
https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html

Adobe FrameMaker Publishing Server 2022.3 is a security update.
https://helpx.adobe.com/security/products/framemaker-publishing-server/apsb24-38.html

Adobe Media Encoder 23.6.6 and 24.4.1 are security updates.
https://helpx.adobe.com/security/products/media-encoder/apsb24-34.html

Adobe Photoshop 24.7.4 and 25.9 are security updates.
https://helpx.adobe.com/security/products/photoshop/apsb24-27.html

Adobe Substance 3D Stager 3.0.2 is a security update.
https://helpx.adobe.com/security/products/substance3d_stager/apsb24-43.html

Calibre 7.12.0 improves conversion, media support and resolves several bugs. This is not a security update.
https://calibre-ebook.com/

Columns++ 1.1.2 improves performance, stability, and reliability, and adds a Timestamps and resolves a couple bugs. This is not a security update.
https://github.com/Coises/ColumnsPlusPlus

Ghostscript 10.03.1 doesn’t provide a change log so should be treated as a security update.
https://www.ghostscript.com/releases/gsdnld.html

Kdenlive 24.05.0 reimplements audio capture, adds group effects and automatic subtitle translation, performance improvements and resolves several bugs. This is not a security update.
https://kdenlive.org/

LibreOffice Fresh 24.2.4 resolves over 70 bugs. This is not a security update.
https://www.libreoffice.org/

Magento Open Source 2.3.7-p4-ext-8, 2.4.4-p9, 2.4.5-p8, 2.4.6-p6 and 2.4.7-p1 are security updates.
https://helpx.adobe.com/security/products/magento/apsb24-40.html

Manager 24.6.11.1637 resolves several bugs but does not have current release notes so should be treated as a security update.
https://www.manager.io/

Notepad++ 8.6.8 resolves several bugs. This is not a security update.
https://notepad-plus-plus.org/

QuickBooks Pro 2022 20240529-R16_8 resolves several bugs. This should be treated as a security update.
https://downloads.quickbooks.com/app/qbdt/products

QuickBooks Pro 2023 20240529-R13_6 doesn’t provide a detailted change log. This should be treated as a security update.
https://downloads.quickbooks.com/app/qbdt/products

Security Software Updates

One or more of these is likely to be of interest to most people.

KeePass 2.57 improves privacy and security or
https://keepass.info/

OpenSSL 3.3.1 is a security update.
https://slproweb.com/products/Win32OpenSSL.html

ProtonVPN (macOS) 4.3.0 improves stability and resolves several bugs. This is not a security update.
https://protonvpn.com/download

RogueKiller 15.17.0 improves detection and resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

Stinger 13.0.0.127 adds new detections and improves others. This is not a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

Tails 6.3 is a security update.
https://tails.net/install/download/index.en.html

uBlock Origin 1.58.0 resolves over a dozen bugs. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

YARA 4.5.1 resolves several bugs. This is not a security update.
https://github.com/VirusTotal/yara/

Capture Updates

These are unlikely to be of interest to most people.

SnagIt 24.1.4 improves compression, video combine, and resolves several bugs. This is not a security update.
https://www.techsmith.com/screen-capture.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 13.0.1.9 improves subtitle support and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/download.htm

HandBrake 1.8.0 updates libraries and resolves dozens of bugs. This is a security update.
https://handbrake.fr/

IsoBuster 5.4.1 adds support for new formats and resolves several bugs. This is not a security update.
https://www.isobuster.com/download.php

MakeMKV 1.17.7 updates license date. This is not a security update.
https://www.makemkv.com/download/

PDF Creator 5.2.2 updates libraries. This is a security update.
https://www.pdfforge.org/pdfcreator

StreamFab 6.1.8.2 improves reliability, compatibility, and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 2.0.2.3 improves performance, quality, and AI integration. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Utility Updates

These are unlikely to be of interest to most people.

1Password 8.10.34 resolves over a dozen bugs. This is not a security update.
https://1password.com/downloads/

7-Zip 24.06 improves reliability and resolves several bugs. This is not a security update.
https://www.7-zip.org/

Agent Ransack 2022.3435 resolves a crash bug. This is not a security update.
https://www.mythicsoft.com/agentransack/download/

Bitcoin 27.0 resolves several bugs and improves performance. This is not a security update.
https://bitcoin.org/en/download

Bitwarden 2024.5.0 adds organization item cloning and begins the manifest v3 compatibility roll-out. This is not a security update.
https://bitwarden.com/

CCleaner 6.24.11060 improves cleanup and resolves several bugs. This is not a security update.
https://www.ccleaner.com/

DesktopOK 11.24 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.2.6.0 adds several new features and updates libraries. This is a security update.
https://dngrep.github.io/

email-oauth2-proxy 2024-05-25 adds JWT and resolves a python compatibility bug. This is not a security update.
https://github.com/simonrob/email-oauth2-proxy

Etcher 1.19.21 resolves dependency bugs. This is not a security update.
https://www.balena.io/etcher/

Fido 1.56 adds 24H1 ISO UEFI support. This is not a security update.
https://github.com/pbatard/Fido/releases

FileLocator Pro 2022.3435 resolves a crash bug. This is not a security update.
https://www.mythicsoft.com/filelocatorpro/download

Fing 3.6.3 improves compatibility and resolves several bugs. This is not a security update.
https://www.fing.com/products/fing-desktop-download-windows

FoneTool 2.7.0 resolves several bugs. This is not a security update.
https://www.fonetool.com/download.html

Free Virtual Serial Ports 6.01.00.1309 adds several more controls. This is not a security update.
https://freevirtualserialports.com/

Git SCM 2.45.2 is a security update.
https://git-scm.com/

Go 1.22.4 is a security update.
https://go.dev/

GoodSync 12.6.9 resolves several bugs. This is not a security update.
https://www.goodsync.com/

grepWin 2.1.1 resolves several bugs. This is not a security update.
https://github.com/stefankueng/grepWin/releases/latest

GUIPropView 1.30 adds two new action commands. This is not a security update.
https://www.nirsoft.net/utils/gui_prop_view.html

NTLite 2024.5.9946 resolves several bugs and improves compatibility. This is not a security update.
https://www.ntlite.com/download/

osquery 5.12.2 is a security update.
https://osquery.io/downloads

PowerToys 0.81.1 resolves several bugs. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

ProcDump 3.3 for Linux improves container support. This is not a security update.
https://github.com/Sysinternals/ProcDump-for-Linux

Process Explorer 17.06 resolves several bugs. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/process-explorer

RoboForm 9.6.1 resolves several bugs. This is not a security update.
https://www.roboform.com/

Rufus 4.5 updates libraries, adds UEFI validation, and resolves several bugs. This is a security update.
https://rufus.ie/en_US/

ScreenConnect 24.1.9.8915 improves compatibility, reliability, and stability, and resolves several bugs. This should be treated as a security update.
https://screenconnect.connectwise.com/download

SetUserFTA 1.8.1 implements a workaround for the new UCPD “security feature”. This is not a security update.
https://kolbi.cz/blog/2017/10/25/setuserfta-userchoice-hash-defeated-set-file-type-associations-per-user/

Ventoy 1.0.99 updates EFI binaries and resolves a couple bugs. This is not a security update.
https://www.ventoy.net/en/index.html

WinRAR 7.01 resolves several bugs. This is not a security update.
https://www.rarlab.com/

WizFile 3.10 adds include and exclude filters, adds more feature controls, and resolves several bugs. This is not a security update.
https://antibody-software.com/wizfile/

Developer Updates

These are unlikely to be of interest to most people.

.NET Runtime 8.0.6 is a security update.
https://dotnet.microsoft.com/en-us/download/dotnet

Android Studio 2023.3.1.20 is a security update.
https://developer.android.com/studio

AutoHotkey 2.0.17 resolves several bugs. This is not a security update.
https://www.autohotkey.com/download/

cx_Freeze 7.1 updates libraries and resolves dozens of bugs. This is not a security update.
https://cx-freeze.readthedocs.io/en/latest/index.html

GitHub Desktop 3.4.1 resolves several bugs. This is not a security update.
https://desktop.github.com/

Inno Setup 6.3.1 improves compatibility and resolves dozens of bugs. This version also removes support for older operating systems. This is not a security update.
https://www.jrsoftware.org/isdl.php

Microsoft Visual C++ 2022 Redistributable 14.40.33810.0 doesn’t provide a change log so should be treated as a security update.
https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist

Node.js 18.20.3 updates dependencies and resolves several bugs. This is not a security update.
https://nodejs.org/en/

Node.js 20.14.0 updates dependencies and resolves several bugs. This is not a security update.
https://nodejs.org/en/

Node.js 22.2.0 updates dependencies and resolves dozens of bugs. This is not a security update.
https://nodejs.org/en/

Python 3.12.4 is a security update.
https://www.python.org/downloads/windows/

SQLite 3.46.0 resolves several bugs. This is not a security update.
https://www.sqlite.org/download.html

Visual Studio Code 1.90 adds several new features. This is not a security update.
https://code.visualstudio.com/

Web Package Updates

These are likely to be of interest only to web developers.

HumHub 1.15.6 resolves several bugs. This is not a security update.
https://www.humhub.com/en

Invision Community 4.7.17 resolves dozens of bugs. This is not a security update.
https://invisioncommunity.com/

Joomla 5.1.1 resolves dozens of bugs. This is not a security update.
https://www.joomla.org/

ownCloud Client 5.3.0.13987 resolves several bugs. This is not a security update.
https://owncloud.com/desktop-app/

WordPress 6.5.4 resolves several bugs. This is not a security update.
https://wordpress.org/

BuddyPress 12.5.1 is a security update.
https://wordpress.org/extend/plugins/buddypress/

Contact Form 7 5.9.5 is a security update.
https://wordpress.org/extend/plugins/contact-form-7/

Multisite Enhancements 1.7.0 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/multisite-enhancements/

Social Post Feed 4.2.5 resolves a couple menu bugs. This is not a security update.
https://wordpress.org/extend/plugins/custom-facebook-feed/

WooCommerce 8.9.2 is a security update.
https://wordpress.org/extend/plugins/woocommerce/

WPBakery 7.7 resolves several bugs. This is a security update.
https://wpbakery.com/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/