Updates 2023-08-08

Welcome back, Folks!

Today is Patch Tuesday for August, 2023.

This month brings a whole bucket of ugly, and a reminder that fixing a bug is not the same thing as fixing the software. Every common browser released at least a security update each week for the last month, with Firefox maxing out sanity tests by releasing five (5) security updates in a mere ten (10) days. I warned about this years ago.

There were over 160 major hacks (some involving millions of users and thousands of organizations, one involving billions of users, Microsoft’s own security keys), and over 200 application updates this month. It’s a huge month, with about 4 GB of updates for most users.

This Month in Technology

Acupuncture and Integrative Solutions Incorporated, All-In-One Security, Allegheny County, AlphaPo, AMD Zen CPUs, AMD Zen2 CPUs, AMI MegaRAC Baseboard Management Controller (BMC), Argentina’s Comprehensive Medical Care Program, PathGroup Health Plan, Barracuda ESG, Batesville Tool & Die, Inc., Baylor College of Medicine, BAZAN Group, Beverly Hills Plastic Surgery, Bi-Bett Corporation, BookCrossing, Buckingham County Public Schools, Buffalo State, California Public Employee and Retirement System (CalPERS), Call of Duty, Canon printers, CardioComm Solutions Inc, Care N’ Care Insurance Company, Inc., Centers for Medicare and Medicaid (CMS), Charles George Department of Veterans Affairs Medical Center, Cisco SD-WAN vManage, Citrix Netscaler ADC and Gateway serversCloudzy, CoinsPaid, ColdFusion (several times),  Colorado Department of Higher Education (CDHE), Colorado State University (CSU), Comdirect, Commerzbank, Conic Finance, almost all CPUs, CraftRise, Curve Finance, Deutsche Bank AG, air-gapped systems in Eastern Europe, Egyptian Ministry of Health and Population, Era Lend, Estée Lauder (twice!), European diplomats, Evotec, Exchange Online, EY Law, Fairfax Oral and Maxillofacial Surgery, Family Vision of Anderson, P.A., Fortinet SSL VPNs, FortiOS and FortiProxy, Gary Motykie, M.D., Ghostscript, Google Accelerated Mobile Pages (AMP), Google Cloud Build, Harkins Pain & Sleep Management Group, Harris Health System, Hawai’i Community College, Helix, Henry Ford Health, Highland Health Systems, Hillsborough County, Hines Interests Limited Partnership, Hot Topic, Howard County General Hospital, Immigration Directorate General in Indonesia, ING, Italian government, Ivanti Endpoint Manager Mobile/Mobileiron — an unknown number of devices are effected, likely in the millions (and again, and again), IVF Michigan, P.C., Johns Hopkins Health System Corporation, JumpCloud, Kenya’s e-Citizen, LeetSwap, LetMeSpy, Life Management Center of Northwest Florida, Inc., Locally, MagicDuel, Majorel, Maximus Federal Services, Inc,  Microsoft, Microsoft Azure, Microsoft Exchange, MikroTik RouterOS routers, Military and Police “Secure” Radio systems, Minecraft servers, MobiMed ePR, Molina Healthcare, Mondee, at least 545 servers/organizations running MOVEit software, Multichain, National Student Clearinghouse (3,500 colleges and universities97% of postsecondary enrollment in the US), NATO (yes, that NATO), New England Life Care, Inc., 12 Norwegian Ministries, Norwegian Government Security and Service Organisation (DSS), NPO Mashinostroyeniya, OpenAI, Orrick, Herrington & Sutcliffe, Ortivus, Outlook.com, PaperCut NG/MF, Paramedic Billing Services, Park Royal Hospital, Pension Benefit Information, Performance Health Technology (PH Tech), Physicians Insurance, Poly Network, Postbank, Prospect Medical Holdings, Quinn Emanuel, Razer, Redis, Rite Aid Corporation, Roblox, Roblox Developer Conference, Rockstar Games Inc., Rockwell Automation ControlLogix, Rodeo Finance, Saint Francis Health System, Salesforce, Serco Inc., several hospitals, Shutterfly, 70,000 small office/home office (SOHO) routers, SonicWall, South Central Ambulance Service, South Western Ambulance Service, Southern Association of Independent Schools, Sutter Senior Care, Tampa General Hospital, Teachers Insurance and Annuity Association of America, Terrestrial Trunked Radio (TETRA), Tesla, The Chattanooga Heart Institute, The Health Plan of West Virginia, Inc., Tigo, TLScontact, Tomra, Uber Technologies Inc, Ubuntu OverlayFS, UEFI boot loader security, UK Electoral Commission, Ukrainian and Polish businesses, Unified Pain Management, US Ambassador to China, US Department of Commerce (and at least two dozen other US government agencies), UT Southwestern Medical Center, Vermillion, VirusTotal, VMware ESXi, VMware Tanzu Application Service, Wake Family Eye Care, WooCommerce Payments, WordPress Ninja Forms, Wuhan Earthquake Monitoring Center, Yamaha, Zimbra (twice), and Zyxel firewalls have reportedly been hacked or compromised this month.

In light of all that, Barracuda Networks asserts that fewer than 100 scammers are responsible for global email extortion campaigns, leading to record breaches. There is yet another means of exfiltrating user information and passwords – this time from the sound your keyboard makes as you type.

BAZAN Group, Microsoft Exchange Online, Microsoft Sharepoint, Reddit, Slack, Spotify, and WhatsApp have suffered from outages this month.

Last months updates broke display and audio hardware, Outlook for Desktop saving, Outlook hyperlinks, websites in Safari, Screen Time on iOS, video recording and playback, certain VPNs, and Windows Update. I am also seeing reports from dozens of my clients that the iOS and iPadOS updates released last week are triggering alerts about “new devices” connecting to users’ Apple accounts. In all cases it was triggered shortly after a restart of a device that had received the OTA update.

Google is *really* pushing Enhanced Safe Browsing, the feature that allows them to monitor all activity on your devices, including third-party apps and websites in other browsers, even when you tell them no. Google announced they will be making it easier to remove personal information and explicit images from Google Search. Google is pushing WEI, though, which will make it impossible to enforce security and privacy in your own browser. As an example, your local Taco Bell could refuse to show you their address on their own website – or even load at all – unless you enable their ability to access your precise location, microphone and camera. This isn’t just my paranoia, it’s a standard Google is pushing at this very moment.

IBM’s Red Hat has announced that they will change the way they “comply” with the GPLv2 open source requirements, limiting access to some of their source. Oracle (yes, that Oracle!) is actually pointing out the insanity of this move.

Amazon is raising prices on some IPv4 addresses.

Clop ransomware is now using bittorrent to bypass takedowns. Cloudflare, primarily known for their security and privacy features, is being abused to aid malware.

The SEC is now mandating that publicly traded companies disclose attacks in four business days after discovery. The Australian government isn’t sure if the Privacy Act applies to their own actions when they violate citizen’s trust or privacy.

Microsoft is going to be forcing users of the native Windows Mail and Calendar applications to the “new Outlook” starting this month. Don’t do it!

Now for the good news:

The FBI finally found out which evil organization purchased malicious spyware after the US banned it: the FBI itself!

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is huge this month. The typical computer should see roughly 4 GB in updates today. Let’s get started.

Microsoft released updates to address 88 vulnerabilities in .NET Core, .NET Framework, ASP.NET, Azure Arc, Azure DevOps, Azure HDInsights, Dynamics Business Central Control, Memory Integrity System Readiness Scan Tool, Microsoft Dynamics, Microsoft Edge (Chromium-based), Microsoft Exchange Server, Microsoft Office, Microsoft Office Excel, Microsoft Office Outlook, Microsoft Office SharePoint, Microsoft Office Visio, Microsoft Teams, Microsoft WDAC OLE DB provider for SQL, Microsoft Windows Codecs Library, Reliability Analysis Metrics Calculation Engine, SQL Server, Tablet Windows User Interface, Visual Studio, Windows Bluetooth A2DP driver, Windows Cloud Files Mini Filter Driver, Windows Common Log File System Driver, Windows Cryptographic Services, Windows Defender, Windows Fax and Scan Service, Windows Group Policy, Windows HTML Platform, Windows Hyper-V, Windows Kernel, Windows LDAP – Lightweight Directory Access Protocol, Windows Message Queuing, Windows Mobile Device Management, Windows Projected File System, Windows Reliability Analysis Metrics Calculation Engine, Windows Smart Card, Windows System Assessment Tool, Windows Wireless Wide Area Network Service, and MSRT (~ 2 GB). This includes security updates. A reboot is required.

Apple released updates for macOS Ventura 13.5, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, Safari 16.6, iOS 15.7.8, iOS 16.6, iPadOS 15.7.8, iPadOS 16.6, tvOS 16.6, watchOS 9.6, and Pro Video Formats 2.2.6. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

iOS 15.7.8 and 16.6 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 15.7.8 and 16.6 are security updates. Use Settings, General, Software Update to install the most current update.

watchOS 9.6 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 16.6 is a security update. Use System, Software Update to install the most current version.

Google Chrome OS 108.0.5359.239 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Ventura (13.x) means that macOS Catalina (10.15) and older are no longer supported. If you can not install at least macOS Big Sur (11) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v22H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it, but I recommend you continue to use Windows 10 until early 2025 before you consider switching to it.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 23.7.2 resolves several bugs. This is not a security update.
https://www.amd.com/en/support

BullZip PDF Printer 14.3.0.2961 resolves several bugs and improves compatibility. This is not a security update.
https://www.bullzip.com/products/pdf/info.php#download

Display Driver Uninstaller 18.0.6.5 improves removal. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

Drivers by Seagull 2023.3 adds support for 300 new models including several RFID tag printers. This is not a security update.
https://www.seagullscientific.com/support/downloads/drivers/

DS4Windows 3.2.13 several new features and improves hardware compatibility. This is not a security update.
https://github.com/Ryochan7/DS4Windows/releases/latest

Ghostscript 10.01.2 resolves several bugs. This is a security update.
https://www.bullzip.com/products/pdf/download.php

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.56.20 is a security update. Use Menu, Help, About to get the most current version.
https://brave.com/

Microsoft Edge 115.0.1901.200 is a security update. Use Menu, Help, About to get the most current version.
https://www.microsoft.com/en-us/edge/business/download

Firefox 116.0.2 is a security update…the fifth in the last ten days! Use Menu, Help, About to get the most current version.
https://www.mozilla.org/en-US/firefox/new/

Firefox ESR 115.1.0 is a security update. Use Menu, Help, About to get the most current version.
https://www.mozilla.org/en-US/firefox/organizations/all/

Google Chrome 115.0.5790.170 is a security update. Use Menu, Help, About to get the most current version.
https://www.google.com/chrome/

Microsoft Edge 115.0.1901.188 is a security update. Use Menu, Help, About to get the most current version.
https://www.microsoft.com/en-us/edge/business/download

Microsoft Edge WebView2 115.0.1901.200 is a security update. Use Menu, Help, About to get the most current version.
https://developer.microsoft.com/en-us/microsoft-edge/webview2/

SeaMonkey 2.53.17 is a security update. Use Menu, Help, About to get the most current version.
https://www.seamonkey-project.org/

Vivaldi 6.1.3035.257 is a security update. Use Menu, Help, About to get the most current version.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Mailspring 1.11.0 improves cosmetics and resolves several bugs. This is a security update.
https://getmailspring.com/

Spark (macOS) 3.6.8 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Spark 3.6.8 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 115.1.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk (macOS) 7.2.1 resolves several bugs. This is not a security update.
https://anydesk.com/en/downloads

curl 8.2.1 resolves dozens of bugs. This is a security update.
https://curl.haxx.se/windows/

Dropbox 179.4.4985 doesn’t provide a change log so should be treated as a security update.
https://www.dropbox.com/

Facebook Messenger 192.0.0.8.125 is a security update.
https://www.messenger.com/download

FreeFileSync 12.5 resolves several bugs and improves stability and reliability. This is not a security update.
https://www.freefilesync.org/download.php

Google Drive 79.0 is a security update.
https://drive.google.com/start

Grocy Desktop 2.5.0 updates Grocy to 4.0.1 and resolves several bugs and improves performance. This is not a security update.
https://github.com/grocy/grocy-desktop

Microsoft Teams 1.6.00.20074 updates the channels experience and improves security. This is a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 27.0.1 resolves dozens of bugs. This is a security update.
https://nextcloud.com/

Npcap 1.76 resolves a couple bugs, improves performance, and updates the code signing key. This is not a security update.
https://nmap.org/npcap/

Qbox 4.0.5.48 doesn’t provide a change log so should be treated as a security update.
https://www.coraltreetech.com/qbox

Rclone 1.63.1 resolves several bugs, improves compatibility and resilience. This is not a security update.
https://rclone.org/

Signal (Android) 6.27.10 doesn’t provide a change log so should be treated as a security update.
https://signal.org/android/apk/

Signal 6.27.1 improves voice and video calling. This is not a security update.
https://signal.org/download/macos/
https://signal.org/download/windows/

Skype 8.99.0.403 resolves several bugs, integrates motr Bing AI, and adds self-chat. This is not a security update.
https://www.skype.com/

Telegram 4.8.10 resolves a couple bugs. This is not a security update.
https://telegram.org/

Zoom 5.15.6.19959 resolves dozens of bugs. This is a security update. Note that Zoom has also recently updated their Terms of Service to assert ownership of any audio, video, or other communication through their platform IN ANY WAY THEY SEE FIT with no way to opt out.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 3.0.11 resolves a dozen bugs. This is not a security update.
https://en.3tene.com/

Bitwig Studio 5.0.4 resolves a couple minor bugs. This is not a security update.
https://www.bitwig.com/download/

darktable 4.4.2 resolves several bugs. This is not a security update.
https://www.darktable.org/

Picard 2.9 resolves dozens of bugs. This is not a security update.
https://picard.musicbrainz.org/

Plex Desktop 1.75.0.3920 resolves several bugs. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Home Theater 1.44.1.3926 resolves several bugs. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Media Server 1.32.5.7349 resolves several bugs and improves hardware compatibility. This is a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

GameMaker Studio 2023.6.0.92 improves macOS compatibility. This is not a security update.
https://www.yoyogames.com/en/gamemaker

GDevelop 5.2.169 resolves several bugs. This is not a security update.
https://gdevelop.io/download

Lego Studio 2.23.7.3 resolves a stability bug. This is not a security update.
https://www.lego.com/en-us/ldd

Minecraft Server (Bedrock) 1.20.14.01 is a security update.
https://www.minecraft.net/en-us/download/server/bedrock

PS5 23.01-07.60.00 improves performance. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Acrobat and Reader 23.003.20269, 20.005.30516.10516, and 20.005.30514.10514 are security updates.
https://helpx.adobe.com/security/products/acrobat/apsb23-30.html

Adobe Commerce and Magento Open Source 2.4.6-p2, 2.4.5-p4, 2.4.4-p5, 2.4.3-ext-4, 2.4.2-ext-4, 2.4.1-ext-4, 2.4.0-ext-4, and 2.3.7-p4-ext-4 are security updates.
https://helpx.adobe.com/security/products/magento/apsb23-42.html

Adobe Dimension 3.4.10 is a security update.
https://helpx.adobe.com/security/products/dimension/apsb23-44.html

Adobe XMP Toolkit SDK 2023.07 is a security update.
https://helpx.adobe.com/security/products/xmpcore/apsb23-45.html

Blender 3.6.1 improves performance and resolves several bugs. This is not a security update.
https://www.blender.org/download/

Calibre 6.24.0 adds the ability to operate full text search across a subset of books, fixes calibre:// links, and resolves several bugs. This is not a security update.
https://calibre-ebook.com/

GnuCash 5.3 resolves a couple bugs and improves performance. This is not a security update.
https://www.gnucash.org/

ImageMagick 7.1.1-15 resolves several bugs. This is a security update.
https://imagemagick.org/

Inkscape 1.3 resolves dozens of bugs and improves several tools. This is not a security update.
https://inkscape.org/release/

Kdenlive 23.04.3 resolves over a dozen bugs. This is not a security update.
https://kdenlive.org/

LibreOffice Fresh 7.5.5 resolves 70 bugs. This is not a security update. Remember that the “Fresh” line is beta software and you should use the “Still” line instead.
https://www.libreoffice.org/

Nextcloud Desktop 3.9.1 resolves a dozen bugs. This is not a security update.
https://nextcloud.com/

Paint.net 5.0.8 resolves several bugs. This is not a security update.
https://www.getpaint.net/

Security Software Updates

One or more of these is likely to be of interest to most people.

Gpg4win 4.2.0 resolves a dozen bugs. This is a security update.
https://www.gpg4win.org/download.html

HTTP Toolkit 1.13.0 doesn’t provide a change log so should be treated as a security update.
https://httptoolkit.tech/

MalwareBytes Anti-Malware 4.5.34 resolves several bugs. This is not a security update.
https://www.malwarebytes.org/antimalware/

MalwareBytes Anti-Malware Mac 4.20.7 resolves several bugs. This is not a security update.
https://www.malwarebytes.com/mac/

OpenSSL 1.1.1v and 3.1.2 are security updates.
https://slproweb.com/products/Win32OpenSSL.html

ProtonVPN 2.4.3 improves stability. This is not a security update.
https://protonvpn.com/download

Radmin VPN 1.4.4642.1 doesn’t provide a change log so should be treated as a security update.
https://www.radmin-vpn.com/

Tails 5.16 is a security update.
https://tails.boum.org/install/dvd/index.en.html

uBlock Origin 1.51.0 resolves several bugs and adds support for several new filters and scriptlets. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

VT-CLI 0.14.0 adds silent operation support, winget and go support, and resolves a couple bugs. This is not a security update.
https://github.com/VirusTotal/vt-cli/releases/latest

Capture Updates

These are unlikely to be of interest to most people.

Camtasia 23.1.2 updates libraries and resolves several bugs. This is a security update.
https://www.techsmith.com/video-editor.html

SnagIt 23.2.0 updates libraries and resolves over a dozen bugs. This is a security update.
https://www.techsmith.com/screen-capture.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 12.1.1.2 adds support for new encodings. This is not a security update.
https://www.dvdfab.cn/download.htm

StreamFab 6.1.3.4 resolves several bugs. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 1.0.2.8 improves conversion speed and resolves a couple bugs. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Utility Updates

These are unlikely to be of interest to most people.

.NET Runtime 7.0.10 is a security update.
https://dotnet.microsoft.com/en-us/download/dotnet

1Password 8.10.9 resolves dozens of bugs. This is not a security update.
https://1password.com/downloads/windows/
https://1password.com/downloads/mac/

8GadgetPack 37.0 updates My Weather and removes unsupported widgets. This is not a security update.
https://8gadgetpack.net/

Bitcoin 25.0 improves network communication, RPCs, and resolves several bugs. This is not a security update.
https://bitcoin.org/en/download

Bitwarden 2023.7.1 adds commands to the CLI Secrets Manager. This is not a security update.
https://bitwarden.com/

CCleaner 6.14.10584 is a security update.
https://www.ccleaner.com/

Dell Command Update 5.0.0 doesn’t provide a change log so should be treated as a security update.
https://www.dell.com/support/article/us/en/04/sln311129/dell-command-update?lang=en

DesktopOK 11.01 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 4.0.45.0 updates libraries and resolves several bugs to improve compatibility. This is a security update.
https://dngrep.github.io/

Etcher 1.18.12 resolves a couple bugs. This is not a security update.
https://www.balena.io/etcher/

Everything Toolbar 1.2.0 improves compatibility. This is not a security update.
https://github.com/stnkl/EverythingToolbar/

Go 1.21.0 is a major update, adding several new tools and language constructs. This is a security update.
https://go.dev/

GoodSync 12.3.1 improves AutoUpdate sync, stability, and resolves several compatibility issues. This is not a security update.
https://www.goodsync.com/

HWiNFO 7.60 doesn’t provide a change log so should be treated as a security update.
https://www.hwinfo.com/download/

Java 8u381 is a security update.
https://www.java.com/en/download/manual.jsp

JShelter 0.13 improves stability. This is not a security update.
https://jshelter.org/install/

LiveTcpUdpWatch 1.51 adds dark background and full screen support. This is not a security update.
https://www.nirsoft.net/utils/live_tcp_udp_watch.html

NetworkOpenedFiles 1.61 adds dark background and full screen support. This is not a security update.
https://www.nirsoft.net/utils/network_opened_files.html

NTLite 2023.7.9371 resolves several bugs and improves features. This is not a security update.
https://www.ntlite.com/download/

OSForensics 10.0.1015 resolves several bugs. This is not a security update.
https://www.osforensics.com/download.html

osquery 5.9.1 adds ARM support and resolves several bugs. This is a security update.
https://osquery.io/downloads

PowerToys 0.72.0 resolves several bugs and improves compatibility. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

Process Explorer 17.05 improves stability. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/process-explorer

Rufus 4.2 improves compatibility and stability, adds conversion options, and resolves several bugs. This is not a security update.
https://rufus.ie/en_US/

ScreenConnect 23.5.8.8598 improves logging. This is not a security update.
https://www.connectwise.com/software/control/download

SmartMonTools 7.4 adds several new switches, improved hardware support, and resolves a couple bugs. This is not a security update.
https://smartmontools.org/

TcpLogView 1.38 updates IP database. This is not a security update.
https://www.nirsoft.net/utils/tcp_log_view.html

Ventoy 1.0.94 resolves compatibility issues. This is not a security update.
https://www.ventoy.net/en/index.html

VMMap 3.33 improves compatibility. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/vmmap

WinRAR 6.23 is a security update.
https://www.rarlab.com/

WinScan2PDF 8.61 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

ZoomIt 7.1 adds audio capture support. This is not a security update.
https://learn.microsoft.com/en-us/sysinternals/downloads/zoomit

ZoomText 2023 2023.2307.29.400 improves keyboard shortcuts and resolves several bugs.
https://support.freedomscientific.com/Downloads/ZoomText

Developer Updates

These are unlikely to be of interest to most people.

ADB 34.0.4 resolves several bugs. This is not a security update.
https://developer.android.com/studio/releases/platform-tools

Android Studio 2022.3.1.18 improves compatibility. This is not a security update.
https://developer.android.com/studio

AutoHotkey 2.0.4 resolves several bugs. This is not a security update.
https://www.autohotkey.com/download/

AutoHotkey 1.1.37.01 resolves several bugs. This is not a security update.
https://www.autohotkey.com/download/

GitHub Desktop 3.2.7 resolves several bugs. This is not a security update.
https://desktop.github.com/

Godot (macOS) 4.1.1 improves stability. This is not a security update.
https://godotengine.org/

MySQL ConnectorNet 8.1.0 resolves several bugs. This is not a security update.
https://dev.mysql.com/downloads/connector/net/

MySQL Server 8.0.34 resolves dozens of bugs. This is a security update.
https://dev.mysql.com/downloads/installer/

Node.js 18.17.0 updates libraries, improves performance, and resolves several bugs. This is not a security update.
https://nodejs.org/en/

Node.js 20.5.0 updates libraries, improves performance, and resolves several bugs. This is not a security update.
https://nodejs.org/en/

Visual Studio Code 1.81 resolves several bugs. This is not a security update.
https://code.visualstudio.com/

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 7.0.10 resolves dozens of bugs. This is not a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

HumHub 1.14.3 resolves several bugs. This is not a security update.
https://www.humhub.com/en

ISPConfig 3.2.11 adds support for Debian 12 and resolves several bugs. This is not a security update.
https://www.ispconfig.org/ispconfig/download/

Invision Community 4.7.12 updates libraries and resolves dozens of bugs. This should be treated as a security update.
https://invisioncommunity.com/

Grocy 4.0.1 is a major update adding new API features, compatibility, and performance improvements. This build also resolves several bugs.
https://github.com/grocy/grocy

MailEnable 10.47 resolves several bugs. This should be treated as a security update.
https://www.mailenable.com/

ownCloud Client 4.2.0.11670 resolves several bugs. This should be treated as a security update.
https://owncloud.com/desktop-app/

Contact Form 7 5.8 adds several hooks and resolves a couple bugs. This is not a security update.
https://wordpress.org/extend/plugins/contact-form-7/

Duplicator 1.5.5.1 improves messaging and subsite mapping structure. This is not a security update.
https://wordpress.org/plugins/duplicator/

Social Post Feed 4.1.9 adds promotional link, updates the block and improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/custom-facebook-feed/

Theme My Login 7.1.6 resolves a couple bugs and adds a new hook. This is not a security update.
https://wordpress.org/extend/plugins/theme-my-login/

W3 Total Cache 2.4.0 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/w3-total-cache/

WooCommerce 7.9.0 resolves over a hundred bugs, updates blocks and options. This is a security update.
https://wordpress.org/extend/plugins/woocommerce/

WP Mail SMTP 3.8.2 resolved several bugs. This is not a security update.
https://wordpress.org/extend/plugins/wp-mail-smtp/

WPBakery 7.0 adds a couple elements, improves notifications and compatibility. This is not a security update.
https://wpbakery.com/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2023-06-13

Welcome back, Folks!

Today is Patch Tuesday for June, 2023.

This month brings critical security updates for all supported Apple products, the end of all non-LTS versions of Windows 10 other than v22H2 (if you aren’t sure whether you are using LTS, you aren’t), and new security updates for every browser every single week since last month. That’s on top of the 180+ major hacks, and over 220 application updates this month.

Prepare yourself, there will be about 4.5 GB of updates for most devices this month.

This Month in Technology

Accellion FTA, Aer Lingus, airBaltic, Albany ENT & Allergy Services, Alvaria, Inc., Android, 60,000 malicious Android apps, millions of Android-based devices have been  pre-infected, Apria Healthcare, ASAS Health, Ascension Providence, Ascension Seton, Asian Health Services, Atomic Wallet, Augusta, Georgia, Bank Syariah Indonesia, Barracuda Email Security Gateway appliances (since 2022), BBC, Bluefield University, Boots, Brightline, Inc., Brightly Software SchoolDude, British Airways, Builders FirstSource Flex Plan, Bukkit and CurseForge Minecraft mods, Burton Snowboards, Capita, Casepoint (used by SEC, DOD and Pentagon), Celer, Children’s Health Insurance Program, Chilean army, Cisco Secure Client (formerly AnyConnect), Cisco Small Business Series Switches, City of Dallas, Texas, Clarke County Hospital, Credit Control Corp, Culbertson Memorial Hospital, D-Link D-View 8, Discord, Earlens Corporation, thousands of eCommerce sites, Eisai, Elgon Information Systems, Emby, Enzo Biochem, Essen Medical Associates, Extreme Networks, Farmalink, Fertility Specialists Medical Group, FortiOS, Franklin Templeton Canada, Franklin, Tennessee, GIGABYTE PCs, GitLab, Globalcaja, Goodwill Industries of Greater New York and Northern NJ, Inc., Google Chrome, over 30 Chrome extensions, Grant Regional Health Center, Great Expressions Dental Centers, Harvard Pilgrim Health Care, Hillsborough County Supervisors of Elections Office, Honda, HWL Ebsworth, Idaho Falls Community Hospital, Illinois Department of Healthcare and Family Services, Illinois Department of Human Services, IMA Financial Group, Inc., Infotel JSC, Intellihartx, iOS, Iowa Department of Health and Human Services (again!), iPhones, iSpace, Inc., Israeli organizations, ITx Companies, JD Group, Jimbos Protocol, Kaspersky, KeePass, Kiddowares Parental Control – Kids Place, L3Harris, Lacroix, Lancaster Orthopedic Group, Latitude Financial Services, Lehigh Valley Health Network, Luxottica, macOS, Madhya Pradesh Power Management Co, Managed Care of North America (MCNA) Dental, Marshall Information Services, LLC dba Primary Solutions, Martinique, MedInform, Inc., MEO, Mercy Home, Mercy Medical Center – Clinton, Inc., Microsoft Azure, Microsoft Exchange, Microsoft Visual Studio, Minnesota Department of Education, Mountain View Hospital, Mountain View RediCare, MOVEit Transfer (since 2021 – and more coming almost daily), MSI, NextGen Healthcare, North Shore Medical Labs, Norton Healthcare, Nova Scotia government, Onix Group LLC, Orbiter Finance, Oyate Health Center, Pacific Union College, thousands of PaperCut servers, PartsSource, Inc. Welfare Benefit Plan, Pearland ISD, Texas, PharMerica, Amazon PillPack, Pioneer Valley Ophthalmic Consultants, PC, 30 Portuguese financial institutions, R&B Corporation of Virginia, the defunct RaidForums, RenderDoc, RentoMojo, ReportLab, Rheinmetall AG, Ruckus Wireless Admin, Sacramento County, Salesforce ‘Ghost Sites’, Samsung mobile devices, Scandinavian Airlines, ScanSource, Seoul National University Hospital, Sesame, Inc., Shell Recharge, SimpleTire, Skolkovo Foundation, Solutran, South and Southeast Asia government, aviation, and telecommunication organizations, South East Regional Organised Crime Unit, Sparta Community Hospital District, State of Illinois, Strava, Swiss government, Synergy Hematology Oncology Medical Associates, T. Rowe Price Group, Inc., Tennessee Orthopaedic Clinics, The CSC Generation Holdings, Inc. Health and Welfare Plan, The Philadelphia Inquirer, Topcon Healthcare Solutions, Inc., Tornado Cash, Toyota Motor Corporation (over a decade), TP-Link routers, Trezor T Hardware Wallet, Tron, UI Community Home Care, Uintah Basin Healthcare, United Healthcare Services, Inc. Single Affiliated Covered Entity, University of Manchester, University of Rochester, Uranium Finance, “critical US infrastructure” since 2021, US communications infrastructure, US Department of Transportation, US government contractor ABB, Valley Orthopaedic Specialists, Vascular Center of Intervention, VMware Aria Operations for Networks, VMware ESXi servers, WhizComms, Windows 10 WordPad, Windows Internet Information Services, Windows XP activation, WordPress Advanced Custom Fields, WordPress Beautiful Cookie Consent Banner, WordPress Essential Addons for Elementor, WordPress Gravity Forms, WordPress Jetpack, Zacks Investment Research, Zellis, Zimbra, and Zyxel have reportedly been hacked or compromised this month.

ASUS routers, ChatGPT, GitHub, Microsoft 365, Microsoft Azure Portal, Microsoft OneDrive, Microsoft’s Outlook.com, Reddit, and ScanSource have suffered from outages this month.

Last months updates broke HP Office Jet printers, Surface laptop cameras, VPN performance, Windows Defender, Windows file copy, and Windows printing and audio playback.

30% of all internet traffic is malicious. Is anyone really surprised? Facebook has actually made progress against phishing by suing a registrar used primarily to create phishing domains.  The .zip TLD was released this month and it is already being used for malicious purposesMozilla was pushing full-screen ads for their VPN service. Google Ads remain one of the most common sources for malware.

Amazon has been fined $30 million over Ring and Alexa privacy violations. Microsoft will pay a mere $20 million for illegally collecting data on children in violation of COPPA. Meta (Facebook) has been fined $1.3 billion for moving data to US servers.

Call of Duty players can be identified on any platform violating their privacy. The American Hospital Association (AHA) doesn’t respect your privacy. People are sacrificing their tech, crypto and privacy in hopes of 15 minutes of fame.

Ford is so concerned about their spontaneous combustion issues, they’re advising owners of their vehicles to park outside.

While I’m not a big fan of Reddit, their new API rates and policies are going to be the death of many subreddits, since they’ll result in less automation by the good guys while not reducing the automation used by the bad guys.

Apple introduced Rapid Security Response (fast patching for security issues) last month, and have already caused panic among users.

The FDA has once-again expanded its own authority in what can only result in shrinking the food supply.

As expected, OAuth provides a fancy new “watering hole” target for attackers.

Now for the good news:

Microsoft will be killing Cortana later this year.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is huge this month. The typical computer should see roughly 4.5 GB in updates today. Let’s get started.

Windows 10 and Windows 11 versions 22H2 should now be installed on all supported hardware as all prior non-LTS versions are no longer supported.

Microsoft released updates to address 1,378 bugs including 73 vulnerabilities in .NET and Visual Studio, .NET Core, .NET Framework, ASP .NET, Azure DevOps, Microsoft Dynamics, Microsoft Edge (Chromium-based), Microsoft Exchange Server, Microsoft Office, Microsoft Office Excel, Microsoft Office OneNote, Microsoft Office Outlook, Microsoft Office SharePoint, Microsoft Power Apps, Microsoft Printer Drivers, Microsoft WDAC OLE DB provider for SQL, Microsoft Windows Codecs Library, NuGet Client, Remote Desktop Client, Role: DNS Server, SysInternals, Visual Studio, Visual Studio Code, Windows Authentication Methods, Windows Bus Filter Driver, Windows Cloud Files Mini Filter Driver, Windows Collaborative Translation Framework, Windows Container Manager Service, Windows CryptoAPI, Windows DHCP Server, Windows Filtering, Windows GDI, Windows Geolocation Service, Windows Group Policy, Windows Hello, Windows Hyper-V, Windows Installer, Windows iSCSI, Windows Kernel, Windows NTFS, Windows ODBC Driver, Windows OLE, Windows PGM, Windows Remote Procedure Call Runtime, Windows Resilient File System (ReFS), Windows Server Service, Windows SMB, Windows TPM Device Driver, Windows Win32K, and MSRT (~2 GB). This includes security updates. A reboot is required.

Apple released updates for macOS Ventura 13.4, macOS Monterey 12.6.6, macOS Big Sur 11.7.7, iOS 15.7.6, iOS 16.5, iPadOS 15.7.6, iPadOS 16.5, tvOS 16.5, watchOS 9.5.1, Safari 16.5, iTunes 12.12.9 for Windows, and Pro Video Formats 2.2.5. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

iOS 15.7.6 and 16.5 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 15.7.6 and 16.5 are security updates. Use Settings, General, Software Update to install the most current update.

watchOS 9.5.1 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 16.5 is a security update. Use System, Software Update to install the most current version.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Ventura (13.x) means that macOS Catalina (10.15) and older are no longer supported. If you can not install at least macOS Big Sur (11) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. All non-LTS versions of Windows 10 other than v22H2 are now out of support, upgrade to v22H2 now. If you aren’t sure whether you are using LTS, you aren’t. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v22H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it, but I recommend you continue to use Windows 10 until early 2025 before you consider switching to it.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 23.5.2 resolves several bugs and improves reliability. This is not a security update.
https://www.amd.com/en/support

Crucial Storage Executive 9.01 doesn’t provide a changelog so should be treated as a security update.
https://www.crucial.com/support/storage-executive

Display Driver Uninstaller 18.0.6.4 adds command-line arguments to optimize removal and improves cleanup for AMD. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

DS4Windows 3.2.11 resolves several bugs and updates libraries. This should be treated as a security update.
https://github.com/Ryochan7/DS4Windows/releases/latest

Garmin Express 7.17.2 doesn’t provide a changelog so should be treated as a security update.
https://www.garmin.com/en-US/software/express/

Wacom Driver 6.4.2-3 adds training, help bar tips, and resolves several bugs. This is not a security update.
https://www.wacom.com/en-us/support/product-support/drivers

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.52.122 is a security update.
https://brave.com/

Google Chrome 114.0.5735.133 is a security update.
https://www.google.com/chrome/

Google Chrome 109.0.5414.149 (for Windows Server 2012) is a security update.
https://www.google.com/chrome/

Microsoft Edge 113.0.1774.57 is a security update.
https://www.microsoft.com/en-us/edge/business/download

Microsoft Edge 109.0.1518.100 (for Windows Server 2012) is a security update.
https://www.microsoft.com/en-us/edge/business/download

Microsoft Edge WebView2 114.0.1823.43 is a security update.
https://developer.microsoft.com/en-us/microsoft-edge/webview2/

Firefox 114.0.1 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Vivaldi 6.1.3035.75 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

ProtonMail (Android) 3.0.15 is a security update.
https://proton.me/mail/download

Spark 3.6.0.50235 improves stability and resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.6.0.50236 improves stability and resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 102.12.0 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 7.1.12 resolves several bugs. This is not a security update.
https://anydesk.com/en/downloads

AnyDesk (macOS) 7.1.0 adds User Account support. This is not a security update.
https://anydesk.com/en/downloads

curl 8.1.2 resolves dozens of bugs. This is not a security update.
https://curl.haxx.se/windows/

DNSDataView 1.71 resolves a cosmetic bug. This is not a security update.
https://www.nirsoft.net/utils/dns_records_viewer.html

Dropbox 175.4.5569 resolves several bugs. This is not a security update.
https://www.dropbox.com/

Facebook Messenger 188.0.11.164 is a security update.
https://www.messenger.com/download

FileZilla Server 1.7.2 resolves several bugs and improves Let’s Encrypt compatibility. This is not a security update.
https://filezilla-project.org/

FreeFileSync 12.3 resolves several bugs. This is not a security update.
https://www.freefilesync.org/download.php

Google Drive 76.0 is a security update.
https://drive.google.com/start

IPInfoOffline 1.70 adds support for additional IP location databases. This is not a security update.
https://www.nirsoft.net/utils/ip_country_info_offline.html

MailEnable 10.46 is a security update.
https://www.mailenable.com/

MeshCentral 2.11.7849.20089 resolves several bugs and updates libraries. This is not a security update.
https://meshcentral.com/info/downloads.html

Microsoft Teams 1.6.00.12455 resolves several bugs and adds lobby bypass, virtual front desk, and QR code sign-in for hotdesks. This is not a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 27.0 is a major update, with updates to libraries and resolves several bugs. This is a security update.
https://nextcloud.com/

Nmap 7.94 resolves several bugs, updates libraries, and adds dozens of new signatures. This is a security update.
https://nmap.org/

Pocketnet-GUI 0.8.49 improves IPFS support, adds option to purge local storage, and resolves several bugs. This is not a security update.
https://pocketnet.app/

PushBullet 501 doesn’t provide a changelog so should be treated as a security update.
https://www.pushbullet.com/

Signal 6.20.2 improves stability and adds scroll-to for mentions. This is not a security update.
https://signal.org/download/windows/
https://signal.org/download/macos/

Signal (Android) 6.22.8 doesn’t provide a changelog so should be treated as a security update.
https://signal.org/android/apk/

Skype 8.97.0.204 resolves several bugs. This is not a security update.
https://www.skype.com/

Syncthing 1.23.5 resolves several bugs. This is not a security update.
https://syncthing.net/

Technitium DNS Server 11.2 adds support for SVCB and HTTPS and unknown record types, PTR App, Weighted Round Robin App and resolves several bugs. This is not a security update.
https://technitium.com/dns/

Telegram 4.8.3 resolves several bugs. This is not a security update.
https://telegram.org/

USB Drive Log 1.12 adds sort-by. This is not a security update.
https://www.nirsoft.net/utils/usb_drive_log.html

Wget 1.21.4 is a security update.
https://eternallybored.org/misc/wget/

WinSCP 6.1 is a major update. This adds many features and resolves several bugs. This is a security update.
https://winscp.net/eng/index.php

Zoom 5.14.11.17466 resolves several bugs. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 3.0.9 resolves several bugs and improves tracking and interaction controls. This is not a security update.
https://en.3tene.com/

iTunes 12.12.9.4 is a security update.
https://www.apple.com/itunes/download/

Plex Desktop 1.70.2.3845 resolves several bugs and adds discover together. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Home Theater 1.39.2.3822 adds sign-out and resolves several bugs. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Media Server 1.32.3.7192 adds support for new hardware and resolves several bugs. This is a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

GDevelop 5.1.164 resolves several bugs. This is not a security update.
https://gdevelop.io/download

Lego Studio 2.23.5.1 resolves several bugs. This is not a security update.
https://www.lego.com/en-us/ldd

PS5 23.01-07.40.00 resolves several bugs and improves stability. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Animate 22.0.10 and 23.0.2 are security updates.
https://helpx.adobe.com/security/products/animate/apsb23-36.html

Adobe Commerce and Magento Commerce 2.3.7-p4-ext-3, 2.4.0-ext-3, 2.4.1-ext-3, 2.4.2-ext-3, 2.4.3-ext-3, 2.4.4-p4, 2.4.5-p3, and 2.4.6-p1 are security updates.
https://helpx.adobe.com/security/products/magento/apsb23-35.html

Adobe Experience Manager 2023.4 and 6.5.17.0 are security updates.
https://helpx.adobe.com/security/products/experience-manager/apsb23-31.html

Adobe Substance 3D Designer 13.0.0 is a security update.
https://helpx.adobe.com/security/products/substance3d_designer/apsb23-39.html

Audacity 3.3.3 resolves several bugs. This is not a security update.
https://www.audacityteam.org/download/

ImageMagick 7.1.1-11 resolves dozens of bugs. This is a security update.
https://imagemagick.org/

Kdenlive 23.04.1 resolves several bugs. This is not a security update.
https://kdenlive.org/

LibreOffice Fresh 7.5.4 resolves 80 bugs. This is not a security update. Remember that the “Fresh” line is beta software so should be avoided by most users.
https://www.libreoffice.org/

LibreOffice 7.4.7 resolves over 50 bugs. While the 7.4 “Still” branch is now end of life, this should be used for the next 6 weeks before 7.5 is released as “Still.”
https://www.libreoffice.org/

Nextcloud Desktop 3.9.0 resolves dozens of bugs. This is not a security update.
https://nextcloud.com/

Notepad++ 8.5.3 resolves over a dozen bugs. This is not a security update.
https://notepad-plus-plus.org/

Paint.net 5.0.6 improves cosmetics and resolves several bugs. This is not a security update.
https://www.getpaint.net/

Calibre 6.21.0 resolves several bugs and adds output formats. This is not a security update.
https://calibre-ebook.com/

Adobe Reader DC 23.003.20201 resolves several bugs. This is not a security update.
https://get.adobe.com/reader

Adobe Reader DC Patch 23.001.20174 resolves a stability bug. This is not a security update.
https://get.adobe.com/reader

Adobe Reader DC Patch (Mac) 23.001.20177 resolves a stability bug. This is not a security update.
https://get.adobe.com/reader

Security Software Updates

One or more of these is likely to be of interest to most people.

Chainsaw 2.6.2 resolves a rule parsing bug. This is not a security update.
https://github.com/countercept/chainsaw

KeePass 2.54 adds triggers, global URL overrides, password generator profiles, improvements to exports and reporting, and resolves several bugs. This is not a security update.
https://keepass.info/

OpenSSL 3.1.1 is a security update.
https://slproweb.com/products/Win32OpenSSL.html

OpenSSL 1.1.1u is a security update.
https://www.openssl.org/source/

ProtonVPN (macOS) 3.1.4 resolves several bugs. This should be treated as a security update.
https://protonvpn.com/download

Radmin VPN 1.3.4570.5 doesn’t provide a changelog so should be treated as a security update.
https://www.radmin-vpn.com/

RogueKiller 15.10.0 resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

SuperAntiSpyware 10.0.1252 is a security update.
https://www.superantispyware.com/download.html

Stinger 12.2.0.614 should be treated as a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

Tails 5.14 is a security update.
https://tails.boum.org/install/dvd/index.en.html

uBlock Origin 1.50.0 resolves dozens of bugs. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

Velociraptor 0.6.9 should be treated as a security update.
https://github.com/Velocidex/velociraptor/releases/latest

YARA 4.3.2 is a security update.
https://github.com/VirusTotal/yara/

Capture Updates

These are unlikely to be of interest to most people.

Open Broadcaster Software 29.1.2 resolves dozens of bugs. This is not a security update.
https://obsproject.com/

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 12.1.0.8 adds support for new encodings. This is not a security update.
https://www.dvdfab.cn/download.htm

iMazing HEIC Converter 2.0.9 doesn’t provide a changelog so should be treated as a security update.
https://imazing.com/heic

MakeMKV 1.17.4 adds support for new encodings and resolves several bugs. This is not a security update.
https://www.makemkv.com/download/

PDF Creator 5.1.1 resolves a couple bugs. This is not a security update.
https://www.pdfforge.org/pdfcreator

StreamFab 6.1.2.6 adds support for new sources and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 1.0.2.0 resolves several bugs. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Utility Updates

These are unlikely to be of interest to most people.

1Password for Mac 8.10.7 resolves dozens of bugs. This is not a security update.
https://1password.com/downloads/mac/

1Password for Windows 8.10.7 resolves dozens of bugs. This is not a security update.
https://1password.com/downloads/windows/

7-Zip 23.00 resolves several bugs and improves performance in some situations. This is not a security update.
https://www.7-zip.org/

AppResourcesUsageView 1.05 adds sort-by option. This is not a security update.
https://www.nirsoft.net/utils/app_resources_usage_view.html

BatteryHistoryView 1.05 adds sort-by option. This is not a security update.
https://www.nirsoft.net/utils/battery_history_view.html

Bitwarden 2023.5.0 resolves several bugs. This is not a security update.
https://bitwarden.com/

CCleaner 6.12.10490 resolves several bugs. This is not a security update.
https://www.ccleaner.com/

ControlMyMonitor 1.37 adds support for abbreviated IDs and improves compatibility. This is not a security update.
https://www.nirsoft.net/utils/control_my_monitor.html

CurrPorts 2.75 adds support for additional IP location databases. This is not a security update.
https://www.nirsoft.net/utils/cports.html

Dell Command Update 4.9.0 resolves several bugs and improves stability. This should be treated as a security update.
https://www.dell.com/support/article/us/en/04/sln311129/dell-command-update?lang=en

Dell OS Recovery Tool 2.3.7515 doesn’t provide a changelog so should be treated as a security update.
https://www.dell.com/support/home/uk/en/ukbsdt1/drivers/osiso/recoverytool

dnGrep 3.2.330.0 resolves several bugs. This is not a security update.
https://dngrep.github.io/

email-oauth2-proxy 2023-05-18 resolves several bugs. This is not a security update.
https://github.com/simonrob/email-oauth2-proxy

ESEDatabaseView 1.72 adds sort-by and open recent file support. This is not a security update.
https://www.nirsoft.net/utils/ese_database_view.html

Everything 1.4.1.1024 is a security update.
https://www.voidtools.com/

Everything Toolbar 1.1.1 resolves a couple bugs. This is not a security update.
https://github.com/stnkl/EverythingToolbar/

Fido 1.50 removes inactive downloads and adds UEFI Shell 2.2 23H1. This is not a security update.
https://github.com/pbatard/Fido/releases

FileTypesMan 1.97 resolves a support annoyance. This is not a security update.
https://www.nirsoft.net/utils/file_types_manager.html

Fing 3.3.1 resolves several bugs. This is not a security update.
https://www.fing.com/products/fing-desktop-download-windows

FullEventLogView 1.78 adds full screen mode. This is not a security update.
https://www.nirsoft.net/utils/full_event_log_view.html

Git SCM 2.41.0 resolves dozens of bugs. This is a security update.
https://git-scm.com/

Go 1.20.5 is a security update.
https://go.dev/

GoodSync 12.2.5 resolves several bugs. This is not a security update.
https://www.goodsync.com/

grepWin 2.0.15 resolves several bugs. This is not a security update.
https://github.com/stefankueng/grepWin/releases/latest

GUIPropView 1.25 adds sort-by and black background support. This is not a security update.
https://www.nirsoft.net/utils/gui_prop_view.html

Homedale 2.06 resolves a crash bug. This is not a security update.
https://www.the-sz.com/products/homedale/

HWiNFO 7.46 resolves several bugs. This is not a security update.
https://www.hwinfo.com/download/

InstalledAppView 1.07 adds sort-by support and resolves a high-DPI bug. This is not a security update.
https://www.nirsoft.net/utils/installed_app_view.html

LastActivityView 1.37 resolves a stability bug. This is not a security update.
https://www.nirsoft.net/utils/computer_activity_view.html

LiveTcpUdpWatch 1.50 adds ASN and Organization columns, and support for additional IP location databases. This is not a security update.
https://www.nirsoft.net/utils/live_tcp_udp_watch.html

ManageWirelessNetworks 1.11 adds sort by support. This is not a security update.
https://www.nirsoft.net/utils/manage_wireless_networks.html

MobileFileSearch 1.45 adds the ability to cancel search with Esc. This is not a security update.
https://www.nirsoft.net/utils/mobile_device_file_search.html

MultiMonitorTool 2.10 adds abbreviated ID support. This is not a security update.
https://www.nirsoft.net/utils/multi_monitor_tool.html

NetRouteView 1.40 adds several new columns and option to copy as route. This is not a security update.
https://www.nirsoft.net/utils/network_route_view.html

NetworkOpenedFiles 1.60 adds support for folder, user and computer filters. This is not a security update.
https://www.nirsoft.net/utils/network_opened_files.html

NTLite 2023.5.9257 resolves several bugs and improves compatibility. This is not a security update.
https://www.ntlite.com/download/

OpenToonz 1.7.1 resolves a stability bug. This is not a security update.
https://github.com/opentoonz/opentoonz/

OSForensics 10.0.1013 resolves several bugs. This is not a security update.
https://www.osforensics.com/download.html

AOMEI Partition Assistant 10.0 is a major update with cosmetic and functional changes. This is not a security update.
https://www.diskpart.com/

PingInfoView 2.30 adds high-resolution ping time support and the ability to hide disabled items. This is not a security update.
https://www.nirsoft.net/utils/multiple_ping_tool.html

PointerStick 6.26 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

PowerToys 0.70.1 improves stability. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

Process Monitor 3.94 resolves a stability bug and restores Copy All functionality. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/procmon

PropertySystemView 1.20 adds CopyProperty command-line support. This is not a security update.
https://www.nirsoft.net/utils/windows_property_system_view.html

Recuva 1.53.2096 resolves a detection bug. This is not a security update.
https://www.ccleaner.com/recuva

RoboForm 9.4.8 resolves several bugs. This is not a security update.
https://www.roboform.com/

Rufus 4.1 resolves several bugs. This is not a security update.
https://rufus.ie/en_US/

SimpleWMIView 1.54 adds full screen and sort-by support. This is not a security update.
https://www.nirsoft.net/utils/simple_wmi_view.html

TeamViewer 15.42.7 resolves several bugs. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/

Unity 2022.3.1 resolves dozens of bugs. This is a security update.
https://unity3d.com/get-unity/download/archive

WakeMeOnLan 1.91 updates the internal MAC addresses database. This is not a security update.
https://www.nirsoft.net/utils/wake_on_lan.html

WhyNotWin11 2.5.0.5 resolves several bugs and improves compatibility. This is not a security update.
https://github.com/rcmaehl/WhyNotWin11

WinGet 1.4.11071 resolves dozens of bugs and updates libraries. This is a security update.
https://github.com/microsoft/winget-cli/releases/latest

WinRAR 6.22 improves reliability and resolves stability bugs. This is not a security update.
https://www.rarlab.com/

WizTree 4.14.0.1 resolves several bugs. This is not a security update.
https://www.diskanalyzer.com/

ZoomIt 7.0 adds several new features including screen recording, annotation and editing. This is not a security update.
https://learn.microsoft.com/sysinternals/downloads/zoomit

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 2022.2.1.20 resolves several bugs. This is not a security update.
https://developer.android.com/studio

cx_Freeze 6.15 resolves several bugs and improves compatibility. This is not a security update.
https://cx-freeze.readthedocs.io/en/latest/index.html

Get-IMAPAccessToken 2023.5.22 resolves a bug. This is not a security update.
https://github.com/DanijelkMSFT/ThisandThat/blob/main/Get-IMAPAccessToken.ps1

GitHub Desktop 3.2.4 resolves several bugs. This is not a security update.
https://desktop.github.com/

Godot 4.0.3 provides resolution for hundreds of bugs and feature issues. This is not a security update.
https://godotengine.org/

Node.js 20.3.0 updates libraries and resolves several bugs. This is not a security update.
https://nodejs.org/en/

Python 3.11.4 is a security update.
https://www.python.org/downloads/windows/

SQLite 3.42.0 resolves several bugs. This is not a security update.
https://www.sqlite.org/download.html

Unreal Engine 5.2 adds dozens of new features and resolves several bugs. This is not a security update.
https://unrealengine.com/en-US/

Visual Studio Code 1.79.1 adds read-only, automatic copy, Git branch naming, and several other features. This is a security update.
https://code.visualstudio.com/

Virtual Machine Updates

These are unlikely to be of interest to most people.

PPSSPP 1.15.4 resolves several bugs. This is not a security update.
https://www.ppsspp.org/download/

Web Package Updates

These are likely to be of interest only to web developers.

Invision Community 4.7.10 adds Courses, improved email bounce handling, and resolves dozens of bugs. This is not a security update.
https://invisioncommunity.com/

HumHub 1.14.2 resolves several bugs. This is not a security update.
https://www.humhub.com/en

ISPConfig 3.2.10p1 resolves several bugs. This is not a security update.
https://www.ispconfig.org/ispconfig/download/

Joomla 4.3.2 is a security update.
https://www.joomla.org/

jQuery 3.7.0 resolves several bugs and integrates Sizzle directly into jQuery. This is not a security update.
https://code.jquery.com/

ownCloud Client 4.0.0.10896 resolves several bugs. This is not a security update.
https://owncloud.com/desktop-app/

phpList 3.6.13 improves updater process and resolves several bugs. This is not a security update.
https://www.phplist.org/

Piwigo 13.7.0 is a security update.
https://piwigo.org/

SMF 2.1.4 updates libraries and resolves several bugs. This is not a security update.
https://www.simplemachines.org/

WordPress 6.2.2 is a security update.
https://wordpress.org/

BuddyPress 11.2.0 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/buddypress/

Contact Form 7 5.7.7 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/contact-form-7/

myStickymenu 2.6.3 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/mystickymenu/

Really Simple CAPTCHA 2.2 updates minimum requirements and Apache directives. This is not a security update.
https://wordpress.org/extend/plugins/really-simple-captcha/

WooCommerce 7.7.2 resolves dozens of bugs. This is not a security update.
https://wordpress.org/extend/plugins/woocommerce/

WP Plugin Update Checker 5.1 improves GitHub and GitLab parsing and resolves a couple bugs. This is not a security update.
https://github.com/YahnisElsts/plugin-update-checker/releases/latest

WPBakery 6.13.0 is a security update.
https://wpbakery.com/

WPtouch 4.3.53 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/wptouch/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2023-05-09

Welcome back, Folks!

Today is Patch Tuesday for May, 2023.

This month brings news that the current stable release of Windows 10 will be the last version released until it is end of life (EOL) in October 2025. This means it is mature and won’t have annoying operating system changes on a regular basis, unlike Windows 11. There were over 150 major hacks, and over 215 application updates this month. All in all it’s a big month, with about 3.5 GB of updates for most users.

This Month in Technology

Alto Calore Servizi, American Bar Association, Americold, Amnesty International Australia, an African telecommunications organization, Apache Superset, APC’s Easy UPS Online Monitoring Software, Apro.cl, automotive Controller Area Network, AvidXchange, Banco de Venezuela, Berkeley, Bitmarck Germany, Bitrue, Blue Shield of California, Bluefield University, Brightline, Caltech, Capita, Cementos Bio-Bio S.A, Cementos Progreso, CH Media, Cisco IOS routers, Cisco PCD, Cisco Phone Adapters, City of Dallas, Texas, Conagua, Constellation Software, 9 cryptocurrency exchange websites, Cummins Behavioral Health Systems, 13 internet domains used for DDoS-for-hire services, Delphi Drug & Alcohol Council, Diocese of Las Vegas, Elastic, Ethan Health, LLC, Eurasia Group, Fairfax County Public Schools, Fincantieri Marine Group, Fortra, FTX, Fullerton India, GDAC, Genova Burns LLC, Google Chrome, Graceworks Lutheran Services, Group Euromotors, Guam Memorial Hospital, a Haarlem (NL) company, Hardenhuish School, HealthPlan Services, Inc., Henry County Hospital, Hillsborough County Supervisor of Elections Office, Hundred Finance, Hyundai, Illumina’s Universal Copy Service, Intel Boot Guard, Intel CPUs, Intel TDX, Iowa Department of Health and Human Services, John Muir Health – Walnut Creek Medical Center, Kabarak University, Kodi Foundation, KuCoin, La Clinica de La Raza, Inc., Lake Dallas Independent School District, Latitude Financial, Level Finance, Lürssen, Mars Area School District, Medtronic, MEO, Merlin, MetaMask, Methodist Family Health, Microsoft SQL servers, MiniMed Distribution Corp., MIT, Modern Cardiology Associates, Montgomery General Hospital, Monument Inc. and Tempest, MSI OEM Signing Keys, Murfreesboro Medical Clinic & SurgiCenter, Naivas Kenya, National Smallbore Rifle Association, NationsBenefits Holdings, LLC, NCR Aloha POS, NextGen Healthcare, Northeastern University, OGUsers, One Brooklyn Health, OrangeTee & Tie, Orqa, Packagist, Papercut, Pathway Healthcare, LLC, Philippines State Agencies, Point32Health, PrestaShop, RaidForums, RentoMojo, Retina & Vitreous of Texas, PLLC, Rheinmetall, Robeson Health Care Corporation, Roskomnadzor, Ruckus Wireless, SafeMoon, Saville Row, Seguros la Occidental, St. Vincent’s Ambulatory Care, Inc., Stanford, SushiSwap, T-Mobile (again), Tasmanian Government, TBK DVR, Tencent QQ, Terravision, TP-Link Archer A21, Trust Wallet, Twitter, two critical infrastructure organizations in the energy sector, two organizations involved in financial trading, Two Rivers Public Health Department, Ukraine, Ukrainian state networks, UMass Amherst, Unique Imaging, Inc, UniSat Wallet, United HealthCare, United Steelworkers Local 286, University of California, San Francisco, University Urology, Unlimited Care, Inc., Upper Peninsula Health Plan, US Consumer Financial Protection Bureau, US military “legacy weapons systems“, Valid Certifcadora, Veeam backup servers, VMware vRealize Log Insight, VMware, Western Digital, WP Advanced Custom Fields, WP Eval PHP, Yearn Finance, Yellow Pages Group, Yucatan government, and Z-Library (again) have reportedly been hacked or compromised this month.

1Password, Bank of Scotland, Google Search, Halifax, Lloyds Bank, Microsoft 365 and Exchange, Reddit, TSB Bank, and Twitter (twice) have suffered from outages this month.

Last months updates broke Microsoft Defender.

Google is finally adding end-to-end encryption to their security authenticator. However, they’re now weakening the security of your Google account by allowing anyone with any of your device PINs or patterns to access your account. If you’ve ever loaned your cell phone or tablet to a five year old to get them to be quiet during a conversation with family, Amazon is giving you another reason to avoid that.

Advertisements (especially via Google and Facebook) remain the #1 method of infecting victims. As if on queue, there will now be more ads in the Microsoft Windows Start Menu. Pirated software is still a very common method to hack a network. Microsoft is adding the ability to opt out of presence detection within Windows 11. 

Apple’s new “rapid security response” patching platform is failing. macOS Silicon isn’t safe from ransomware. 

QR codes are much more dangerous than you can imagine. Know the risks of reselling your used hardware.

Still no punishment when government violates their own rules. The EU is planning to scan all private files on personal devices in violation of privacy rights. The goal of securely classifying and validating organizational ownership of online resources is a lofty one, but this transparency – as proposed via QWACs – would put privacy at increased risk.

Now for the good news:

Apple and Google are finally taking an interest in how their platforms are abused for stalking via Bluetooth.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is large this month. The typical computer should see roughly 3.5 GB in updates today. Let’s get started.

Windows 10 and Windows 11 versions 22H2 should now be installed. Sadly, the new “Moments” features on Windows 11 will insert advertisements in the Start menu and Control Panel. Just another sign of the continuing decline of Windows.

Microsoft released updates to address 49 vulnerabilities in Microsoft Bluetooth Driver, Microsoft Edge (Chromium-based), Microsoft Graphics Component, Microsoft Office, Microsoft Office Access, Microsoft Office Excel, Microsoft Office SharePoint, Microsoft Office Word, Microsoft Teams, Microsoft Windows Codecs Library, Reliable Multicast Transport Driver (RMCAST), Remote Desktop Client, SysInternals, Visual Studio Code, Windows Backup Engine, Windows Installer, Windows iSCSI Target Service, Windows Kernel, Windows LDAP – Lightweight Directory Access Protocol, Windows MSHTML Platform, Windows Network File System, Windows NFS Portmapper, Windows NTLM, Windows OLE, Windows RDP Client, Windows Remote Procedure Call Runtime, Windows Secure Boot, Windows Secure Socket Tunneling Protocol (SSTP), Windows SMB, Windows Win32K, and MSRT (~2 GB). This includes security updates. A reboot is required.

Apple released updates for AirPods and Beats. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

Fedora 38-1.6 is a security update. This major version adds improved hardware support, modern security benefits, and updates libraries and resources.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Ventura (13.x) means that macOS Catalina (10.15) and older are no longer supported. If you can not install at least macOS Big Sur (11) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current — and final — release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v22H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is now stable and can be upgraded to if your hardware supports it, but I recommend you continue to use Windows 10 until early 2025 before you consider switching to it.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 23.4.3 improves performance and compatibility. This is not a security update.
https://www.amd.com/en/support

Daemon Tools Lite 11.2.0 adds VeraCrypt support, improves ARM compatibility and resolves several bugs. This is not a security update.
https://www.daemon-tools.cc/products/dtLite

Display Driver Uninstaller 18.0.6.3 improves cleanup. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

Drivers by Seagull 2023.2 adds another 300+ printer and device drivers, encrypted hardware and RFID support. This is a security update.
https://www.seagullscientific.com/support/downloads/drivers/

DS4Windows 3.2.10 resolves several bugs. This is not a security update.
https://github.com/Ryochan7/DS4Windows/releases/latest

Netgear Genie R6400 1.0.1.78 is a security update.
https://www.netgear.com/support/product/R6400.aspx#download

TP-Link Archer AX21 v1.20.230426 is a security update.
https://www.tp-link.com/us/support/download/archer-ax21/v1.20/#Firmware

Wacom Driver 6.4.2-1 resolves several bugs. This is not a security update.
https://www.wacom.com/en-us/support/product-support/drivers

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.51.110 is a security update.
https://brave.com/

Firefox 113.0 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Google Chrome 113.0.5672.92 is a security update.
https://www.google.com/chrome/

Google Chrome 109.0.5414.141 is a security update. The 109 version is now only supported on Windows Server 2012 and 2012r2.
https://www.google.com/chrome/

Microsoft Edge 112.0.1722.71 is a security update.
https://www.microsoft.com/en-us/edge/business/download

Microsoft Edge 109.0.1518.78 is a security update. The 109 version is now only supported on Windows Server 2012 and 2012r2.
https://www.microsoft.com/en-us/edge/business/download

Microsoft Edge WebView2 113.0.1774.35 is a security update.
https://developer.microsoft.com/en-us/microsoft-edge/webview2/

Vivaldi 6.0.2979.18 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

OutlookAttachView 3.50 adds From and To scan filtering. This is not a security update.
https://www.nirsoft.net/utils/outlook_attachment.html

ProtonMail (Android) 3.0.14 improves stability and performance. This is not a security update.
https://proton.me/mail/download

Spark 3.4.2.48202 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.4.2.48201 resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 102.10.1 improves compatibility and resolves several bugs. This is not a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 7.1.11 improves stability. This is not a security update.
https://anydesk.com/en/downloads

AnyDesk (macOS) 7.0.2 resolves several bugs and improves integration. This is not a security update.
https://anydesk.com/en/downloads

Dropbox 173.4.6706 resolves several bugs. This is not a security update.
https://www.dropbox.com/

Facebook Messenger 186.0.0.10.221 is a security update.
https://www.messenger.com/download

FileZilla Client 3.64.0 updates libraries. This should be treated as a security update.
https://filezilla-project.org/

Google Drive 74.0 is a security update.
https://drive.google.com/start

Microsoft Teams 1.6.00.11166 is a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 26.0.1 is a security update.
https://nextcloud.com/

Npcap 1.75 is a security update.
https://nmap.org/npcap/

Signal 6.16.0 resolves several bugs. This is not a security update.
https://signal.org/download/windows/

Signal (Android) 6.19.8 doesn’t provide a changelog so should be treated as a security update.
https://signal.org/android/apk/

Skype 8.96.0.403 adds several new features and improves stability. This is not a security update.
https://www.skype.com/

Technitium DNS Server 11.1.1 is a security update.
https://technitium.com/dns/

Telegram 4.8.1 resolves several bugs. This is not a security update.
https://telegram.org/

Telegram (Android) 9.6.0 resolves several bugs. This is not a security update.
https://telegram.org/apps

WinSCP 5.21.8 is a security update.
https://winscp.net/eng/index.php

Zoom 5.14.7.15877 is a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

3tene 3.0.7 is a security update.
https://en.3tene.com/

Plex Desktop 1.67.2.3705 is a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Home Theater 1.38.2.3738 resolves several bugs. This is a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Media Server 1.32.1.6999 resolves several bugs. This is a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Winamp 5.9.1 is a security update.
https://www.winamp.com/

Game Updates

These are unlikely to be of interest to most people.

GameMaker Studio 2023.4.0.84 resolves dozens of bugs.
https://www.yoyogames.com/en/gamemaker

Lego Studio 2.23.4.1 resolves several bugs. This is not a security update.
https://www.lego.com/en-us/ldd

Nintendo Switch 16.0.3 improves stability. This is not a security update.
https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/system%20updates/p/989

PS5 23.01-07.20.00 improves stability and performance. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2023.04.26 resolves several bugs. This is not a security update.
https://www.steampowered.com/platform/update_history/index.php?skin=0&id=0

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Reader DC 23.001.20143 is a security update.
https://get.adobe.com/reader

Adobe Substance 3D Painter 8.3.1 is a security update.
https://helpx.adobe.com/security/products/substance3d_painter/apsb23-29.html

Audacity 3.3.2 doesn’t provide a changelog so should be treated as a security update.
https://www.audacityteam.org/download/

Calibre 6.17.0 resolves several bugs and improves compression. This is not a security update.
https://calibre-ebook.com/

ImageMagick 7.1.1-8 resolves several bugs. This is not a security update.
https://imagemagick.org/

LibreOffice Fresh 7.5.3 resolves over a hundred bugs. This is a security update. The “Fresh” line is beta software. Please use the Still version which is stable software.
https://www.libreoffice.org/

Nextcloud Desktop 3.8.1 is a security update.
https://nextcloud.com/

PDF Candy Desktop 2.94 doesn’t provide a changelog so should be treated as a security update.
https://pdfcandy.com/

Security Software Updates

One or more of these is likely to be of interest to most people.

Cloudflare WARP 2023.04.27 doesn’t provide a changelog so should be treated as a security update.
https://1.1.1.1/

Cloudflare WARP (macOS) 2023.04.17 doesn’t provide a changelog so should be treated as a security update.
https://1.1.1.1/

HTTP Toolkit 1.12.6 doesn’t provide a changelog so should be treated as a security update.
https://httptoolkit.tech/

MalwareBytes Anti-Malware 4.5.27 resolves several bugs. This is not a security update.
https://www.malwarebytes.org/antimalware/

ProtonVPN 2.4.2 provide cosmetic improvements. This is not a security update.
https://protonvpn.com/download

ProtonVPN (macOS) 3.1.3 improves proof of effect cosmetics and compatibility. This is not a security update.
https://protonvpn.com/download

RogueKiller 15.9.0 resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

Stinger 12.2.0.603 adds detections. This is not a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

Tails 5.12 is a security update.
https://tails.boum.org/install/dvd/index.en.html

uBlock Origin 1.49.2 resolves several bugs. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

YARA 3.1 fixes several bugs. This should be treated as a security update.
https://github.com/VirusTotal/yara/

Capture Updates

These are unlikely to be of interest to most people.

Camtasia 23.0.2 resolves several bugs. This is not a security update.
https://www.techsmith.com/video-editor.html

Open Broadcaster Software 29.1.0 resolves dozens of bugs. This should be treated as a security update.
https://obsproject.com/

ScreenToGif 2.38 improves high-DPI compatibility. This is not a security update.
https://github.com/NickeManarin/ScreenToGif/releases/latest

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 12.1.0.5 adds support for new encodings. This is not a security update.
https://www.dvdfab.cn/download.htm

iMazing HEIC Converter 2.0.7 doesn’t have a changelog so should be treated as a security update.
https://imazing.com/heic

PDF Creator 5.1 adds ARM64 support, improves automation, and resolves several bugs. This is not a security update.
https://www.pdfforge.org/pdfcreator

StreamFab 6.1.2.1 resolves several bugs. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 1.0.1.8 improves performance. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Education updates

One or more of these are likely to be of interest to most people.

Zotero 6.0.26 resolves several bugs. This is not a security update.
https://www.zotero.org/

Utility Updates

These are unlikely to be of interest to most people.

1Password for Mac 8.10.6 resolves dozens of bugs and improves compatibility. This is a security update.
https://1password.com/downloads/mac/

1Password for Windows 8.10.6 resolves dozens of bugs and improves compatibility. This is not a security update.
https://1password.com/downloads/windows/

Agent Ransack 2022.3389 resolves several bugs. This is not a security update.
https://www.mythicsoft.com/agentransack/download/

Bitwarden 2023.4.0 is a security update.
https://bitwarden.com/

CCleaner 6.11.10455 resolves several bugs and improves compatibility. This is not a security update.
https://www.ccleaner.com/

DesktopOK 10.81 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

DMDE 4.0.6.806 resolves several bugs. This is not a security update.
https://dmde.com/

dnGrep 3.2.306.0 updates libraries and implements several new features. This is not a security update.
https://dngrep.github.io/

Everything Toolbar 1.0.5 resolves several bugs. This is not a security update.
https://github.com/stnkl/EverythingToolbar/

Fido 1.45 removes Windows 7 ISO download option since it’s no longer available for download. This is not a security update.
https://github.com/pbatard/Fido/releases

FileLocator Pro 2022.3389 resolves several bugs. This is not a security update.
https://www.mythicsoft.com/filelocatorpro/download

Fing 3.2 no longer provides a changelog so should be treated as a security update.
https://www.fing.com/products/fing-desktop-download-windows

Git SCM 2.40.1 is a security update.
https://git-scm.com/

Go 1.20.4 is a security update.
https://go.dev/

GoodSync 12.2.2 resolves several bugs and introduces a new encrypted file system option. This is not a security update.
https://www.goodsync.com/

grepWin Portable 2.0.13 resolves several bugs. This is not a security update.
https://github.com/stefankueng/grepWin/releases/latest

IsMyHdOK 3.88 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

Kingston SSD Manager 1.5.2.6 doesn’t provide a changelog so should be treated as a security update.
https://www.kingston.com/us/support/technical/ssdmanager

Memtest86+ 6.20 adds support for newer hardware and resolves a couple bugs. This is not a security update.
https://www.memtest.org/

NetworkInterfacesView 1.30 adds secondary sorting and sorting by menu. This is not a security update.
https://www.nirsoft.net/utils/network_interfaces.html

NetworkTrafficView 2.44 adds dark background option and sort by to the toolbar. This is not a security update.
https://www.nirsoft.net/utils/network_traffic_view.html

NTLite 2023.4.9228 resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

OSForensics 10.0.1010 resolves several bugs. This is not a security update.
https://www.osforensics.com/download.html

PowerToys 0.69.1 improves stability adn resolves several bugs. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

PSAppDeploy 3.9.3 resolves several bugs. This is not a security update.
https://psappdeploytoolkit.com/

PsExec 2.43 fixes a regression with -c. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/psexec

RoboForm 9.4.7 is a security update.
https://www.roboform.com/

Rufus 4.0 resolves several bugs and improves stability. This version now requires Windows 8 and newer. This is not a security update.
https://rufus.ie/en_US/

ScreenConnect 23.3.13.8507 resolves several bugs and breaks application compatibility with older instances. This is not a security update.
https://www.connectwise.com/software/control/download

Synergy 1.14.7 adds ability to bind client to specific network and resolves several bugs. This is not a security update.
https://symless.com/synergy/

Sysmon 14.16 adds new ArchiveDirectory system integrity controls and improves compatibility. This is a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon

TCPView 4.19 fixes a bug with the 32-bit version. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/tcpview

TeamViewer 15.41.9 resolves several bugs. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/

Unity 2022.2.18 resolves dozens of bugs. This is not a security update.
https://unity3d.com/get-unity/download/archive

WifiInfoView 2.80 adds full screen mode. This is not a security update.
https://www.nirsoft.net/utils/wifi_information_view.html

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 2022.2.1.19 adds several new features. This is not a security update.
https://developer.android.com/studio

GitHub Desktop 3.2.3 resolves a dozen bugs. This is not a security update.
https://desktop.github.com/

Java 8u371 is a security update.
https://www.java.com/en/download/manual.jsp

MySQL ConnectorNet 8.0.33 is a security update.
https://dev.mysql.com/downloads/connector/net/

MySQL Server 8.0.33 is a security update.
https://dev.mysql.com/downloads/installer/

Node.js 18.16.0 adds single-file executable support, improved URL parsing, and resolves a dozen bugs. This is not a security update.
https://nodejs.org/en/

Node.js 19.9.0 improves URL parsing and resolves several bugs. This is not a security update.
https://nodejs.org/en/

Node.js 20.1.0 adds several new features and updates dependencies. This is not a security update.
https://nodejs.org/en/

Rustup 1.26.0 resolves a dozen bugs and adds several new features. This is not a security update.
https://www.rust-lang.org/

VC Runtime 14.34.31938.0 is a security update.
https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist

Visual Studio Code 1.78.1 improves accessibility, color schemes, profile templates, and other features. This is a security update.
https://code.visualstudio.com/

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 7.0.8 is a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

Coppermine Gallery 1.6.25 resolves several bugs. This is not a security update.
https://coppermine-gallery.net/

Drupal 9.4.15 is a security update.
https://drupal.org/download

Joomla 4.3.1 resolves several bugs. This is not a security update.
https://www.joomla.org/

OpenCart 4.0.2.1 doesn’t provide a detailed changelog so should be treated as a security update.
https://www.opencart.com/

Antispam Bee 2.11.3 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/antispam-bee/

Autoptimize 3.1.7 is a security update.
https://wordpress.org/extend/plugins/autoptimize/

Contact Form 7 5.7.6 resolves a couple bugs. This is not a security update.
https://wordpress.org/extend/plugins/contact-form-7/

Duplicator 1.5.4 doesn’t provide a changelog so should be treated as a security update.
https://wordpress.org/plugins/duplicator/#developers

Sucuri Security 1.8.39 resolves an API error. This is not a security update.
https://wordpress.org/extend/plugins/sucuri-scanner/

Widgets on Pages 1.7.0 is a security update.
https://wordpress.org/extend/plugins/widgets-on-pages/

WooCommerce 7.6.1 resolves dozens of bugs. This is not a security update.
https://wordpress.org/extend/plugins/woocommerce/

WordPress Importer 0.8.1 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/wordpress-importer/

WP Cerber Security 9.5.4 improves compatibility. This is not a security update.
https://wpcerber.com/

WP Mail SMTP 3.8.0 resolves several bugs and improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/wp-mail-smtp/

W3 Total Cache 2.3.2 resolves several bugs. This should be treated as a security update.
https://wordpress.org/extend/plugins/w3-total-cache/

WPBakery 6.11.0 resolves several bugs. This is not a security update.
https://wpbakery.com/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2023-04-11

Welcome back, Folks!

Today is Patch Tuesday for April, 2023.

This month brings over 160 significant hacks, and over 170 application updates. This is pretty normal these days, and the updates will weigh in at a little over 2.5 GB of updates for most users.

This Month in Technology

3CX, 51,000 websites, Ace Nursing, Activision, Adobe ColdFusion, Alivia Health, AllCare Plus Pharmacy, Inc, Allied Benefit, American Pain and Wellness, PLLC, an “East Asian company that develops data-loss prevention software for government and military,” Apple Safari, Aspire Public Schools, Associates in Dermatology, Atlantic Dialysis Management Services, Atlantic General Hospital, Autoridad de Acueductos y Alcantarillados, Bing.com search (via Azure AD), BitGo, BitKeep, Bitzlato, Black & McDonald, Blue Shield of California, Breached, Brooks Rehabilitation, Capita, ChatGPT, Chippewa County, CHU University hospitals, City of Oakland, City of Toronto, CloudPanel, Community Health Systems, Crown Resorts, Dole Food Company, a Dutch maritime logistics company, eFile-com, El Camino Health, El Consejo Nacional de Supervisión del Sistema Financiero, Elementor Pro WordPress plugin, Elmbrook School District, Essendant, Eye4Fraud, Fabrega Molino, Federal Law Enforcement Database, Ferrari, Florida-based community healthcare system, Frideres Dental LLC, Gala Games, General Bytes, 130+ organizations using GoAnywhere MFT, Guam Memorial Hospital, Hatch Bank, Hawaiian death registry, HDB Financial Services, Health Plan of San Mateo, Hitachi Energy, Homewood Health, HP LaserJet printers, Independent Living Systems, India’s Defense Research and Development Organization, Indian health system, Instituto De Educación Secundaria Ies Emilio Canalejo Olmeda, Integrated Supports for Living, Inc, Killer Instinct, Latitude Financial Services, Leaked Reality, LinusTechTips, Lionsgate, Long Son Petrochemicals, Lumen, Majestic Care Middletown Assisted Living LLC, McDonald’s, Medellin government, MedEx, Medminder, Merritt Healthcare Advisors, Microsoft SharePoint, Microsoft Teams, Mozilla Firefox, MSI, National Basketball Association, NCB Management Services, Nebu, Netgear Orbi, New Medical Healthcare, New York City public school special education students, New York-Presbyterian Hospital, NewBridge Services, NewYork-Presbyterian Hospital, Nexx smart devices, NHS Highland, Nonstop Administration and Insurance Services, Inc, NorthStar Emergency Medical Services, NS, Open University of Cyprus, Oracle VirtualBox, ParaSpace, Pension Protection Fund, PetroVietnam, Poolz Finance, POSCO Engineering & Construction, Postal Prescription Services – Kroger, Procter & Gamble, Proskauer Rose, QNAP, Rio Tinto, Rochester Public Schools, Rubrik, SafeMoon, Saks Fifth Avenue, Samsung, SD Worx, Shopper+, South Texas Health System, Sundry Files, Tallahassee Memorial Healthcare, Inc, Tasmanian Education Department, Telegram, Tesla Model 3, the WiFi protocol (this is big), TheGradCafe, Throne, TMX Finance (TitleMax, TitleBucks, InstaLoan), Top of the World Ranch Treatment Center, Toyota Italy, Tusla, Twitter, Uber, Ubuntu Desktop, UC San Diego Health, UHS of Delaware, Inc, UK’s Criminal Records Office, UK’s Virgin Red, Ukrainian utility company, US Congress, US Department of DefenseUS Federal Bureau of Investigation, US Marshals Service, US Special Operations Command, US Wellness Inc, US Wellness, Vazquez Nava Consultores y Abogados, Veeam’s Backup & Replication, Veritas Backup Exec, VM2, VMware Workstation, WellBe, Wells Fargo, West Virginia hospital, Western Digital, Wilkes-Barre Career and Technical Center, WinRAR SFX, WooCommerce, Yardley Dermatology Associates, PC, Yucatan government, Yum! Brands (Taco Bell, KFC, Pizza Hut), Z2U, ZenGo, Zimbra Collaboration Suite, and Zoll have reportedly been hacked or compromised this month.

Amazon has pulled the plug on their most successful charitable endeavor, AmazonSmile.

According to the FBI, 860 “critical” infrastructure organizations were hit with ransomware in 2022. Shouldn’t they just stop if they’re so concerned, since they’re usually the ones behind most terrorists?

It should come as no surprise that the recent spate of train derailments comes not long after a manager at one of the largest rail companies told inspectors to stop marking rail cars that needed repairs.

Apple Weather, Microsoft Defender, Reddit, and WD My Cloud suffered from outages this month.

Last months updates broke Red Dead Redemption 2, and caused problems for many printers by replacing the vendor print drivers with Microsoft’s incompatible drivers. But at least Microsoft is now inserting ads in the Start menu, right? Grrr.

Here’s yet another demonstration of how your “smart device” can be exploited without your knowledge. GM’s Cruise robotaxis have been recalled after they caused an accident in San Francisco. 

Now for the good news:

 

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is huge this month. The typical computer should see roughly
GB in updates today. Let’s get started.

Windows 10 and Windows 11 22H2 should now be installed. Sadly, the new “Moments” features on Windows 11 will insert advertisements in the Start menu and Control Panel. Just another sign of the continuing decline of Windows.

Microsoft released updates to address 93 vulnerabilities in .NET Core, Azure Machine Learning, Azure Service Connector, Microsoft Bluetooth Driver, Microsoft Defender for Endpoint, Microsoft Dynamics, Microsoft Dynamics 365 Customer Voice, Microsoft Edge (Chromium-based), Microsoft Graphics Component, Microsoft Message Queuing, Microsoft Office, Microsoft Office Publisher, Microsoft Office SharePoint, Microsoft Office Word, Microsoft PostScript Printer Driver, Microsoft Printer Drivers, Microsoft WDAC OLE DB provider for SQL, Microsoft Windows DNS, Visual Studio, Visual Studio Code, Windows Active Directory, Windows ALPC, Windows Ancillary Function Driver for WinSock, Windows Boot Manager, Windows Clip Service, Windows CNG Key Isolation Service, Windows Common Log File System Driver, Windows DHCP Server, Windows Enroll Engine, Windows Error Reporting, Windows Group Policy, Windows Internet Key Exchange (IKE) Protocol, Windows Kerberos, Windows Kernel, Windows Layer 2 Tunneling Protocol, Windows Lock Screen, Windows Netlogon, Windows Network Address Translation (NAT), Windows Network File System, Windows Network Load Balancing, Windows NTLM, Windows PGM, Windows Point-to-Point Protocol over Ethernet (PPPoE), Windows Point-to-Point Tunneling Protocol, Windows Raw Image Extension, Windows RDP Client, Windows Registry, Windows RPC API, Windows Secure Boot, Windows Secure Channel, Windows Secure Socket Tunneling Protocol (SSTP), Windows Transport Security Layer (TLS), Windows Win32K and MSRT (~
GB). This includes security updates. A reboot is required.

Apple released updates for iOS 15.7.5 and 16.4.1, iPadOS 15.7.5 and 16.4.1, macOS Big Sur 11.7.6, macOS Monterey 12.6.5, macOS Ventura 13.3.1, Safari 16.4.1, Studio Display Firmware Update 16.4, tvOS 16.4, and watchOS 9.4. This includes security updates. Use Apple Software Update to install these updates. A reboot is required.

iOS 16.4.1 and 15.7.5 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 16.4.1 and 15.7.5 are security updates. Use Settings, General, Software Update to install the most current update.

watchOS 9.4 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 16.4 is a security update. Use System, Software Update to install the most current version.

Google Chrome OS 112.0.5615.62 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Ventura (13.x) means that macOS Catalina (10.15) and older are no longer supported. If you can not install at least macOS Big Sur (11) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. Windows 10 pushes you to get the latest Windows 10 release every 12 months and only supports any consumer builds for 18 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v22H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is still very young so I encourage you to wait a few more months before you consider switching to it.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

AMD Adrenalin 23.4.1 resolves several bugs. This is not a security update.
https://www.amd.com/en/support

Display Driver Uninstaller 18.0.6.2 resolves a stability bug. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

Nvidia Driver 474.30 is a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.50.114 is a security update.
https://brave.com/

Google Chrome 112.0.5615.49 is a security update.
https://www.google.com/chrome/

Microsoft Edge 112.0.1722.34 is a security update.
https://www.microsoft.com/en-us/edge/business/download

Microsoft Edge 109.0.1518.78 is a security update. This version should be used only on devices where the current stable release is not available.
https://www.microsoft.com/en-us/edge/business/download

Firefox 112.0 is a security update.
https://www.mozilla.org/en-US/firefox/new/

SeaMonkey 2.53.16 is a security update.
https://www.seamonkey-project.org/

Vivaldi 5.7.2921.65 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

OutlookAttachView 3.48 adds sort-by to the toolbar. This is not a security update.
https://www.nirsoft.net/utils/outlook_attachment.html

Spark 3.3.6.46134 improves stability. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.3.6.46132 improves stability. This is not a security update.
https://sparkmailapp.com/

Thunderbird 102.9.1 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 7.1.11 is a bug fix for a security update.
https://anydesk.com/en/downloads

BrowsingHistoryView 2.55 adds sort-by to the toolbar. This is not a security update.
https://www.nirsoft.net/utils/browsing_history_view.html

curl 8.0.1 resolves dozens of bugs. This should be treated as a security update.
https://curl.haxx.se/windows/

Dropbox 171.4.6182 improves stability. This is not a security update.
https://www.dropbox.com/

FreeFileSync 12.2 resolves several bugs. This is not a security update.
https://www.freefilesync.org/download.php

Google Drive 73.0 resolves several bugs. This is not a security update.
https://drive.google.com/start

Microsoft Teams 1.6.00.6754 is a security update.
https://teams.microsoft.com/downloads

Nextcloud Server 26.0.0 is a major update with improvements across a dozens features and many bug fixes. This is not a security update.
https://nextcloud.com/

Npcap 1.73 is a security update.
https://nmap.org/npcap/

Omada Software Controller 5.9.31 resolves several bugs. This is not a security update.
https://www.tp-link.com/us/support/download/omada-software-controller/

Rclone 1.62.2 resolves several bugs. This is not a security update.
https://rclone.org/

Signal (Android) 6.16.2 doesn’t provide a detailed changelog so should be treated as a security update.
https://signal.org/android/apk/

Signal 6.13.0 improves dark mode and cosmetics. This is not a security update.
https://signal.org/download/windows/

Syncthing 1.23.4 resolves several bugs. This should be treated as a security update.
https://syncthing.net/

Telegram 4.7.1 resolves a couple bugs. This is not a security update.
https://telegram.org/

Trillian 6.5.0.28 resolves several bugs. This is not a security update.
https://www.trillian.im/

WinSCP 5.21.8 is a security update.
https://winscp.net/eng/index.php

Zoom 5.14.2.14578 resolves several bugs. This is not a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

Bitwig Studio 4.4.10 improves stability. This is not a security update.
https://www.bitwig.com/download/

iTunes 12.12.8.1 is a security update.
https://www.apple.com/itunes/download/

Plex Desktop 1.67.1.3665 fixes the subtitle render/crash issue. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Home Theater 1.37.2.3674 resolves several bugs. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Media Server 1.32.0.6918 resolves a font bug and a certificate installation bug. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-media-server

Game Updates

These are unlikely to be of interest to most people.

GameMaker Studio 2023.2.1.75 adds a new particle editor to the IDE and reworks some of the interface. This is not a security update.
https://www.yoyogames.com/en/gamemaker

GDevelop 5.1.160 resolves several bugs and adds more than a dozen new assets and feature improvements. This is not a security update.
https://gdevelop.io/download

Lego Studio 2.23.3.1 resolves several bugs. This is not a security update.
https://www.lego.com/en-us/ldd

Nintendo Switch 16.0.1 improves stability. This is not a security update.
https://en-americas-support.nintendo.com/app/answers/detail/a_id/22525/kw/system%20updates/p/989

PS5 23.01-07.01.01 resolves a cosmetic bug. This is not a security update.
https://www.playstation.com/en-us/support/hardware/ps5/system-software/

Steam 2023.03.15 resolves dozens of bugs. This should be treated as a security update.
https://www.steampowered.com/platform/update_history/index.php?skin=0&id=0

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Reader DC 23.001.20143 is a security update.
https://get.adobe.com/reader

Adobe Digital Editions 4.5.11.187658 is a security update.
https://www.adobe.com/solutions/ebook/digital-editions/download.html

Adobe InCopy 18.2 and 17.4.1 are security updates. Use Creative Cloud to install the update.

Adobe Acrobat and Reader 23.001.20143 and 20.005.30467 are security updates.
https://helpx.adobe.com/security/products/acrobat/apsb23-24.html

Adobe Substance 3D Stager 2.0.2 is a security update.
https://www.adobe.com/products/substance3d-stager.html

Adobe Dimension 3.4.9 is a security update.
https://www.adobe.com/products/dimension.html

Adobe Substance 3D Designer 12.4.1 is a security update.
https://www.adobe.com/products/substance3d-designer.html

Artweaver 7.0.15 resolves several bugs. This is not a security update.
https://www.artweaver.de/

Calibre 6.15.1 resolves several bugs and improves document compatibility. This is not a security update.
https://calibre-ebook.com/

ImageMagick 7.1.1-6 resolves several bugs. This is not a security update.
https://imagemagick.org/

LibreOffice Fresh 7.5.2 resolves over 90 bugs. This is a security update. The “Fresh” line is beta software and should be avoided by most users.
https://www.libreoffice.org/

Nextcloud Desktop 3.8.0 resolves several bugs. This is not a security update.
https://nextcloud.com/

Notepad++ 8.5.2 resolves several context menu and cosmetic bugs. This is not a security update.
https://notepad-plus-plus.org/

Paint.net 5.0.3 adds center-point shape drawing and resolves several bugs. This is not a security update.
https://www.getpaint.net/

PDF-XChange Editor 9.5.368.0 is a security update.
https://www.tracker-software.com/product/pdf-xchange-editor

Security Software Updates

One or more of these is likely to be of interest to most people.

Caine 13.0 is a security update.
https://www.caine-live.net/

Chainsaw 2.6.0 resolves several bugs. This is not a security update.
https://github.com/countercept/chainsaw

FSS 2023.3.19 updates service list. This is not a security update.
https://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/

MalwareBytes Anti-Malware 4.5.26 improves reporting and resolves several bugs. This should be treated as a security update.
https://www.malwarebytes.org/antimalware/

ProtonVPN 2.4.1 improves stability. This is not a security update.
https://protonvpn.com/download

ProtonVPN (macOS) 3.0.15 resolves several bugs. This is not a security update.
https://protonvpn.com/download

QubesOS 4.1.2 is a security update.
https://www.qubes-os.org/downloads/

RogueKiller 15.8.2 resolves several bugs. This is not a security update.
https://www.adlice.com/download/roguekiller/

Stinger 12.2.0.570 improves detections. This should be treated as a security update.
https://www.mcafee.com/us/downloads/free-tools/stinger.aspx

SuperAntiSpyware 10.0.1250 resolves several bugs. This is not a security update.
https://www.superantispyware.com/download.html

Tails 5.11 is a security update.
https://tails.boum.org/install/dvd/index.en.html

uBlock Origin 1.48.4 resolves several bugs. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

Velociraptor 0.6.8 integrates several net
https://github.com/Velocidex/velociraptor/releases/latest

Wireless Network Watcher 2.31 adds a dark mode option and updates internal MAC address database. This is not a security update.
https://www.nirsoft.net/utils/wireless_network_watcher.html

YARA 4.3.0 resolves several bugs and adds new functions and behaviors. This should be treated as a security update.
https://github.com/VirusTotal/yara/

Capture Updates

These are unlikely to be of interest to most people.

Camtasia 22.5.3 resolves several crash bugs, installation issues and improves the UI. This is not a security update.
https://www.techsmith.com/video-editor.html

SnagIt 23.1.1 resolves several bugs. This is not a security update.
https://www.techsmith.com/screen-capture.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 12.1.0.3 improves compatibility. This is not a security update.
https://www.dvdfab.cn/download.htm

StreamFab 6.1.1.6 improves compatibility and provides new output options. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

UniFab 1.0.1.7 improves compatibility. This is not a security update.
https://www.dvdfab.cn/unifab.htm

Utility Updates

These are unlikely to be of interest to most people.

1Password for Mac 8.10.4 fixes of a dozen bugs. This is a security update.
https://1password.com/downloads/mac/

1Password for Windows 8.10.4 fixes over a dozen bugs. This is a security update.
https://1password.com/downloads/windows/

AstroGrep 4.4.9 updates libraries, adds dark theme, improves filters and resolves several bugs. This is a security update.
http://astrogrep.sourceforge.net/

Bitwarden 2023.3.3 adds domain verification, improved browser security, and resolves several bugs. This is a security update.
https://bitwarden.com/

CalyxOS Device Flasher 1.0.7 doesn’t provide a changelog so should be treated as a security update.
https://calyxos.org/install/

Carbonite 6.4.6 is a security update.
https://account.carbonite.com/

CCleaner 6.10.10347 improves cleaning and adds to the their driver update solution. This is not a security update.
https://www.ccleaner.com/

CrucialScan 20230308 doesn’t provide a changelog so should be treated as a security update.
https://www.crucial.com/store/systemscanner

CurrPorts 2.71 adds full screen display option. This is not a security update.
https://www.nirsoft.net/utils/cports.html

DesktopOK 10.77 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

DMDE 4.0.6.806 fixes several bugs. This is a security update.
https://dmde.com/

Everything Toolbar 1.0.5 improves stability and compatibility. This is not a security update.
https://github.com/stnkl/EverythingToolbar/

FolderChangesView 2.35 adds dark mode support and sort-by to the toolbar. This is not a security update.
https://www.nirsoft.net/utils/folder_changes_view.html

Go 1.20.3 is a security update.
https://go.dev/

GoodSync 12.2.0 resolves several bugs. This is not a security update.
https://www.goodsync.com/

IsMyHdOK 3.88 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

NTLite 2023.4.9191 adds components, new settings and resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

osquery 5.8.2 is a security update.
https://osquery.io/downloads

PowerToys 0.69.0 resolves several bugs. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

Process Explorer 17.04 is a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/process-explorer

PsExec 2.42 adds support for long paths. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/psexec

Regedix 2.0.0.0 adds registry scan and resolves paste bug. This is not a security update.
https://regedix.webrox.fr/

RoboForm 9.4.6 is a security update.
https://www.roboform.com/

Rufus 3.22 resolves several bugs. This is not a security update.
https://rufus.ie/en_US/

ScreenConnect 23.2.9.8466 improves compatibility. This is not a security update.
https://www.connectwise.com/software/control/download

TCPView 4.18 resolves a crash bug and improves dark mode. This is not a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/tcpview

TeamViewer 15.40.8 resolves a LAN bug. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/

Unity 2022.2.14 resolves dozens of bugs. This is not a security update.
https://unity3d.com/get-unity/download/archive

Ventoy 1.0.91 resolves several bugs. This is not a security update.
https://www.ventoy.net/en/index.html

WifiInfoView 2.79 resolves a display bug. This is not a security update.
https://www.nirsoft.net/utils/wifi_information_view.html

WinScan2PDF 8.55 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WizTree 4.13 adds regexp search, search history, command line options, virtual drives, sorting options, and resolves a couple bugs. This is not a security update.
https://www.diskanalyzer.com/

XnConvert 1.98 doesn’t provide a changelog so should be treated as a security update.
https://www.xnview.com/en/xnconvert/

ZoomText 2023 2023.2303.77.400 adds tethered view. This is not a security update.
https://support.freedomscientific.com/Downloads/ZoomText

Developer Updates

These are unlikely to be of interest to most people.

ADB 34.0.1 resolves several bugs. This is not a security update.
https://developer.android.com/studio/releases/platform-tools

GitHub Desktop 3.2.1 resolves a dozen bugs and provides several improvements. This is not a security update.
https://desktop.github.com/

Node.js 16.20.0 updates libraries and resolves several bugs. This is not a security update.
https://nodejs.org/en/

Node.js 19.9.0 adds a new tracing feature, URL parser improvements, and resolves several bugs. This is not a security update.
https://nodejs.org/en/

SQLite 3.41.2 resolves several bugs and improves several features. This is not a security update.
https://www.sqlite.org/download.html

Visual Studio Code 1.77.1 improves stability. This is not a security update.
https://code.visualstudio.com/

Web Package Updates

These are likely to be of interest only to web developers.

Coppermine Gallery 1.6.24 resolves several bugs. This is not a security update.
https://coppermine-gallery.net/

Drupal 9.4.12 is a security update.
https://drupal.org/download

Drupal 9.5.7 resolves a bug in the editor. This is not a security update.
https://drupal.org/download

WordPress 6.2 adds several new native features – custom CSS, sticky positions, new site editor, block management, Openverse media access, and more. This is not a security update.
https://wordpress.org/

Akismet 5.1 resolves several bugs. This should be treated as a security update.
https://wordpress.org/extend/plugins/akismet/

Autoptimize 3.1.6 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/autoptimize/

Contact Form 7 5.7.5.1 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/contact-form-7/

Duplicator 1.5.3.1 doesn’t provide a change log so should be treated as a security update.
https://wordpress.org/plugins/duplicator/

Limit Login Attempts 1.7.2 is a security update.
https://wordpress.org/extend/plugins/limit-login-attempts/

Redirection 5.3.10 resolves a save bug. This is not a security update.
https://wordpress.org/extend/plugins/redirection/

W3 Total Cache 2.3.1 improves compatibility and resolves several bugs. This is a security update.
https://wordpress.org/extend/plugins/w3-total-cache/

WooCommerce 7.5.1 improves stability. This is not a security update.
https://wordpress.org/extend/plugins/woocommerce/

WP Cerber Security 9.5.3 improves compatibility. This is not a security update.
https://wpcerber.com/

WPtouch 4.3.52 resolves a cosmetic bug. This is not a security update.
https://wordpress.org/extend/plugins/wptouch/

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

 

Updates 2023-01-10

Happy New Year, Folks!

Today is Patch Tuesday for January, 2023.

This month brings over 200 application updates and over 100 major hacks. It’s the lightest month we’ve seen in a while, with only about 3 GB of updates for most users.

This Month in Technology

3Commas, Aetna ACE, Antwerp, Belgium, Argonne (ANL), Astro, Avem Health Partners, Azienda Ospedaliera di Alessandria hospital, Bay City Health & Rehabilitation Center, Benchmark, BetMGM, BitKeep crypto wallet users, BMW, Bosselman Energy, Inc. Employee Health Benefits Plan, Brookhaven (BNL), BTC.com, CA Department of Finance, Captify Health, Careportal, Chick-fil-A, CircleCI, Citrix ADC and Gateway, CoinTracker, Comcast Xfinity, Consulate Health Care, Copper Mountain Mining Corporation, Cott Systems, Deezer, Degroof Petercam, Digipolis, DoorDash, Empresas Públicas de Medellín, FBI’s InfraGard, Fitzgibbon Hospital, Five Guys, Flying Blue, Foundcare, Inc., FuboTV, Gemini crypto exchange, Ghost CMS, GitHub auth, Google Home smart speaker, Grupo Estrategas EMM, H-Hotels, Hawaiian Eye Center, Hospital for Sick Children (SickKids), Indian Railway Catering and Tourism Corp, Intrado, John F. Kennedy International Airport taxi dispatch system, JsonWebToken, Kubernetes clusters, L. Knife & Son, Inc. Employee Benefits Plan, Lake Charles Memorial Health System, LastPass (“most” data was encrypted), Lawrence Livermore National Laboratories (LLNL), Legacy Hospice, LEGO BrickLink, Live Oak Surgery Center, Louis A. Johnson Veterans’ Administration Medical Center, Mango Markets, Maternal & Family Health Services, Maybank, Medicare, MedStar Mobile Healthcare, Mercedes, 60,000+ Microsoft Exchange servers, Midwest Orthopaedic Consultants, S.C., Monarch, Netgear WiFi routers, New Vision Dental, Okta, Port of Lisbon Administration, Prairie Lakes Healthcare System, PyTorch, Quality Behavioral Health, Queensland University of Technology, Rackspace, SAIF Corp, Sargent & Lundy, SevenRooms, Shibuya Ward office in Tokyo, Slack, SlideTeam, Social Blade, Synology, Telas Palo Grande, The Elizabeth Hospice, The Guardian, The Malaysian Election Commission, Three Rivers Provider Network, Toyota, TPG Telecom Ltd, Twitter, Uber, UK Schools, UK’s Department for Environment, Food & Rural Affairs, Ukrainian Government (because they pirated Windows), Ukrainian Ministry of Defense, Universidad De La Salle, University of Havana, University of Miami, Verisma Systems, Inc., VSCode Marketplace, Wabtec Corporation, Windows Problem Reporting, YITH WooCommerce Gift Cards Premium, and Zoho ManageEngine have reportedly been hacked or compromised this month.

ChatGPT, the latest AI designed to make humanity obsolete, is already being used to develop malwareAdobe is using your content to train their AI. 

Microsoft still hasn’t gone all-in on Windows 11. Google Chrome (and all other Chromium-based browsers – Edge, Brave, Vivaldi and so on) will no longer support Windows 7, 8, 8.1, or Server 2012/2012 R2 in only a month. The latest build of iTunes is not compatible with the end-to-end encryption feature on iOS/iPadOS.

The only government caught bombing people not party to the Russo-Ukrainian war says cyberattacks should be considered war crimes. The FTC is planning to kill the US economy, while the FCC has decided to regulate space.

Now for the good news:

Almost every ‘conspiracy theory‘ that people had about twitter turned out to be true. The FBI has seized domains involved in DDoS attacks.

John Deere will finally allow farmers to repair their own equipment. This is a major movement in conjunction with the Right to Repair, and could save farmers millions on production expenses.

Let’s Get Busy

Now back to our regularly scheduled program.

Patch Tuesday is huge this month. The typical computer should see roughly 3
GB in updates today. Let’s get started.

Windows 11 22H2 still isn’t ready for prime time, so hold off for at least another month.

Microsoft released updates to address 90 vulnerabilities in .NET Core, 3D Builder, Azure Service Fabric Container, Microsoft Bluetooth Driver, Microsoft Exchange Server, Microsoft Graphics Component, Microsoft Local Security Authority Server (lsasrv), Microsoft Message Queuing, Microsoft Office, Microsoft Office SharePoint, Microsoft Office Visio, Microsoft WDAC OLE DB provider for SQL, Visual Studio Code, Windows ALPC, Windows Ancillary Function Driver for WinSock, Windows Authentication Methods, Windows Backup Engine, Windows Bind Filter Driver, Windows BitLocker, Windows Boot Manager, Windows Credential Manager, Windows Cryptographic Services, Windows DWM Core Library, Windows Error Reporting, Windows Event Tracing, Windows IKE Extension, Windows Installer, Windows Internet Key Exchange (IKE) Protocol, Windows iSCSI, Windows Kernel, Windows Layer 2 Tunneling Protocol, Windows LDAP – Lightweight Directory Access Protocol, Windows Local Security Authority (LSA), Windows Local Session Manager (LSM), Windows Malicious Software Removal Tool, Windows Management Instrumentation, Windows MSCryptDImportKey, Windows NTLM, Windows ODBC Driver, Windows Overlay Filter, Windows Point-to-Point Tunneling Protocol, Windows Print Spooler Components, Windows Remote Access Service L2TP Driver, Windows RPC API, Windows Secure Socket Tunneling Protocol (SSTP), Windows Smart Card, Windows Task Scheduler, Windows Virtual Registry Provider, Windows Workstation Service and MSRT (~1.5 GB). This includes security updates. A reboot is required.

Google Chrome OS 108.0.5359.172 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Ventura (13.x) means that macOS Catalina (10.15) and older are no longer supported. If you can not install at least macOS Big Sur (11) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (v22H2) is very large so will take a long time to download on slower connections. Windows 10 pushes you to get the latest Windows 10 release every 12 months and only supports any consumer builds for 18 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

The now-current release of the Windows 11 (v22H2) is very large so will take a long time to download on slower connections. Windows 11 pushes you to get the latest Windows 11 release every 12 months and only supports any consumer builds for 24 months. If you don’t let it finish and you’re on a slow connection, this process will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Windows 11 is still very young so I encourage you to wait a few more months before you consider switching to it.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface. This includes “free” applications like Avast, OpenOffice, and games you do not actually play.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

DS4Windows 3.2.3 resolves a bug with the Shift Modifier trigger. This is not a security update.
https://github.com/Ryochan7/DS4Windows/releases/latest

Nvidia Driver 474.11 is a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Xerox Smart Start 1.7.71.0 doesn’t provide a changelog so should be treated as a security update.
https://www.support.xerox.com/en-us/content/143617

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.46.153 is a security update.
https://brave.com/

Google Chrome 108.0.5359.124 is a security update.
https://www.google.com/chrome/

Microsoft Edge 108.0.1462.76 is a security update.
https://www.microsoft.com/en-us/edge/business/download

Firefox 108.0.2 is a security update.
https://www.mozilla.org/en-US/firefox/new/

Vivaldi 5.6.2867.50 is a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Mailspring 1.10.8 resolves a couple bugs. This is not a security update.
https://getmailspring.com/

Spark 3.2.2.40861 improves stability and resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Spark (macOS) 3.2.2.40859 improves stability and resolves several bugs. This is not a security update.
https://sparkmailapp.com/

Thunderbird 102.6.1 is a security update.
https://www.thunderbird.net/en-US/

Internet Updates

One or more of these are likely to be of interest to everyone.

AnyDesk 7.1.7 improves command-line controls and resolves dozens of bugs. This is not a security update.
https://anydesk.com/en/downloads

curl 7.87.0 resolves dozens of bugs. This is not a security update.
https://curl.haxx.se/windows/

Dropbox 164.4.7914 resolves several bugs. This is not a security update.
https://www.dropbox.com/

Facebook Messenger 172.0.0.28.215 is a security update.
https://www.messenger.com/download

FreeFileSync 11.29 resolves several bugs. This is not a security update.
https://www.freefilesync.org/download.php

Google Drive 69.0 is a security update.
https://drive.google.com/start

Npcap 1.72 resolves a couple bugs. This is not a security update.
https://nmap.org/npcap/

Prosody 0.12.2 is a security update.
https://prosody.im/download/start

Rclone 1.61.1 adds several new features and resolves many bugs. This is not a security update.
https://rclone.org/

Signal (Android) 6.6.3 doesn’t provide a public changelog so should be treated as a security update.
https://signal.org/android/apk/

Signal 6.1.0 resolves several bugs. This is not a security update.
https://signal.org/download/windows/

Skype 8.91.0.404 adds automatic audio translation. Really. This is not a security update.
https://www.skype.com/

Syncthing 1.23.0 resolves several bugs. This is not a security update.
https://syncthing.net/

Telegram 4.5.3 resolves a bug. This is not a security update.
https://telegram.org/

Zoom 5.13.4.11835 is a security update.
https://zoom.us/

Media Updates

These are unlikely to be of interest to most people.

Bitwig Studio 4.4.6 resolves a couple bugs. This is not a security update.
https://www.bitwig.com/download/

darktable 4.2.0 resolves dozens of bugs. This is not a security update.
https://www.darktable.org/

iTunes 12.12.7.1 resolves several bugs and improves compatibility. This is not a security update.
https://www.apple.com/itunes/download/

Kodi 19.5 doesn’t provide a changelog so should be treated as a security update.
https://kodi.tv/

Plex Desktop 1.60.1.3413 improves album art and Discover behavior, and resolves several bugs. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Plex Home Theater 1.31.1.3412 improves album art and adds an option to dismiss Discover What to Watch. This is not a security update.
https://www.plex.tv/media-server-downloads/#plex-app

Unreal Media Server 15.0 improves streaming capabilities. This is a security update.
http://www.umediaserver.net/umediaserver/download.html

Winamp 5.9.1.10029 updates libraries and resolves several bugs. This is a security update.
https://www.winamp.com/player/

Game Updates

These are unlikely to be of interest to most people.

GameMaker Studio 2022.11.1.56 resolves several bugs. This is not a security update.
https://www.yoyogames.com/en/gamemaker

GDevelop 5.1.155 integrates direct access to the Asset Store and resolves several bugs. This is not a security update.
https://gdevelop.io/download

Steam 2023.12.01 resolves several bugs. This is not a security update.
https://www.steampowered.com/platform/update_history/index.php?skin=0&id=0

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Reader DC 22.003.20310 is a security update.
https://get.adobe.com/reader

Adobe Acrobat 22.003.20310 and 20.005.30436 are security updates.
https://helpx.adobe.com/security/products/acrobat/apsb23-01.html

Adobe InDesign 18.1 and 17.4.1 are security updates.
https://helpx.adobe.com/security/products/indesign/apsb23-07.html

Adobe InCopy 18.0 and 17.4 are security updates.
https://helpx.adobe.com/security/products/incopy/apsb23-08.html

Adobe Dimension 3.4.7 is a security update.
https://helpx.adobe.com/security/products/dimension/apsb23-10.html

Audacity 3.2.3 adds support for audio.com and resolves several bugs. This is not a security update.
https://www.audacityteam.org/download/

Calibre 6.11.0 adds automatic editing of CSS and resolves several bugs. This is not a security update.
https://calibre-ebook.com/

Krita 5.1.5 resolves several bugs. This is not a security update.
https://krita.org/en/download/krita-desktop/

Notepad++ 8.4.8 updates libraries and resolves over a dozen bugs. This is not a security update.
https://notepad-plus-plus.org/

Security Software Updates

One or more of these is likely to be of interest to most people.

DNSQuerySniffer 1.90 adds Show High Resolution Duration option. This is not a security update.
https://www.nirsoft.net/utils/dns_query_sniffer.html

Gpg4win 4.1.0 improves certificate handling and resolve several bugs. This is not a security update.
https://www.gpg4win.org/download.html

HTTP Toolkit 1.12.2 doesn’t provide a changelog so should be treated as a security update.
https://httptoolkit.tech/

KeePass 2.53 adds keyboard controls and history and filter improvements. This is not a security update.
https://keepass.info/

MalwareBytes Anti-Malware 4.5.19 resolves several bugs. This is not a security update.
https://www.malwarebytes.org/antimalware/

ProtonVPN 2.3.2 adds new languages. This is not a security update.
https://protonvpn.com/download

ProtonVPN (macOS) 3.0.11 adds new languages. This is not a security update.
https://protonvpn.com/download

RogueKiller 15.6.5 resolves several bugs and improves reliability. This is not a security update.
https://www.adlice.com/download/roguekiller/

Tails 5.8 is a security update.
https://tails.boum.org/install/dvd/index.en.html

uBlock Origin 1.46.0 resolves several bugs. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

Capture Updates

These are unlikely to be of interest to most people.

Open Broadcaster Software 29.0.0 adds several new encoders and decoders, and resolves several bugs. This is not a security update.
https://obsproject.com/

SnagIt 23.0.2 improves Grab Text feature and resolves several bugs. This is not a security update.
https://www.techsmith.com/screen-capture.html

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 12.0.9.6 adds support for new encodings. This is not a security update.
https://www.dvdfab.cn/download.htm

HandBrake 1.6.0 adds several transcoding options, updates libraries, and resolves several bugs. This is not a security update.
https://handbrake.fr/

StreamFab 6.1.0.2 improves compatibility and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/downloader-new.htm

Education updates

One or more of these are likely to be of interest to most people.

Zotero 6.0.19 adds automatic relinking of Mendeley citations, and resolves several bugs. This is not a security update.
https://www.zotero.org/

Utility Updates

These are unlikely to be of interest to most people.

1Password for Mac 8.9.12 improves reliability and resolves several bugs. This is not a security update.
https://1password.com/downloads/mac/

1Password for Windows 8.9.12 improves reliability and resolves several bugs. This is not a security update.
https://1password.com/downloads/windows/

AOMEI Partition Assistant 9.13.1 resolves several bugs. This is not a security update.
https://www.diskpart.com/

Bitwarden 2022.12.0 resolves several bugs. This is not a security update.
https://bitwarden.com/

CCleaner 6.07.10191 improves startup speed and resolves several bugs. This is not a security update.
https://www.ccleaner.com/

Cygwin 3.4.3 resolves a couple bugs. This is not a security update.
https://cygwin.com/

Dell Command Update 4.7.1 doesn’t provide release notes for this build, so it should be treated as a security update.
https://www.dell.com/support/article/us/en/04/sln311129/dell-command-update?lang=en

DesktopOK 10.61 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

dnGrep 3.2.242.0 adds a portable version, improves extension support, syntax highlighting, selection keys, and updates libraries. This is not a security update.
https://dngrep.github.io/

DMDE 4.0.2.804 resolves several bugs. This is not a security update.
https://dmde.com/

Etcher 1.13.2 resolves several bugs and updates dependencies. This is not a security update.
https://www.balena.io/etcher/

Fido 1.40 improves error handling. This is not a security update.
https://github.com/pbatard/Fido/releases

Go 1.19.5 resolves several bugs. This is not a security update.
https://go.dev/

GoodSync 12.1.4 resolves several bugs. This is not a security update.
https://www.goodsync.com/

grepWin 2.0.12 resolves several bugs. This is not a security update.
https://github.com/stefankueng/grepWin/releases/latest

Homedale 2.05 improves logging and SSID reporting. This is not a security update.
https://www.the-sz.com/products/homedale/

Memtest86+ 6.01 resolves a couple bugs. This is not a security update.
https://www.memtest.org/

NetworkInterfacesView 1.26 add Interface Index column. This is not a security update.
https://www.nirsoft.net/utils/network_interfaces.html

NTLite 2.3.9.9020 updates languages and components. This is not a security update.
https://www.ntlite.com/download/

osquery 5.7.0 provides several table updates, introduces security_profile_info, and resolves several bugs. This is not a security update.
https://osquery.io/downloads

PowerToys 0.66.0 improves installer and resolves dozens of bugs. This is not a security update.
https://github.com/microsoft/PowerToys/releases/latest

RoboForm 9.4.1 imposes new licensing restrictions for free accounts. This is not a security update.
https://www.roboform.com/

ScreenConnect 22.10.10924.8404 adds several new security features and controls, and resolves several bugs. This is not a security update.
https://www.connectwise.com/software/control/download

Superpaper 2.2.1 resolves several bugs. This is not a security update.
https://github.com/hhannine/superpaper/

TeamViewer 15.37.3 resolves a couple bugs. This is not a security update.
https://www.teamviewer.com/en-us/download/windows/

Unity 2022.2.1 resolves several bugs. This is not a security update.
https://unity3d.com/get-unity/download/archive

Ventoy 1.0.87 resolves several bugs. This is not a security update.
https://www.ventoy.net/en/index.html

WinScan2PDF 8.41 updates language files. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

ZoomText 2023 2023.2212.21.400 adds Freeze View and Early Adopter support. This is not a security update.
https://support.freedomscientific.com/Downloads/ZoomText

Developer Updates

These are unlikely to be of interest to most people.

GitHub Desktop 3.1.3 resolves several bugs. This is not a security update.
https://desktop.github.com/

NASM 2.16.01 resolves several bugs. This is not a security update.
https://www.nasm.us/index.php

Node.js 19.4.0 resolves dozens of bugs. This is not a security update.
https://nodejs.org/en/

Node.js 18.13.0 resolves several bugs. This is not a security update.
https://nodejs.org/en/

SQLite 3.40.1 resolves a couple bugs. This is not a security update.
https://www.sqlite.org/download.html

Visual Studio Code 1.74.2 resolves several bugs. This is not a security update.
https://code.visualstudio.com/

Virtual Machine Updates

These are unlikely to be of interest to most people.

PPSSPP 1.14.4 resolves dozens of bugs. This is not a security update.
https://ppsspp.org/downloads.html

VMware Workstation Player 17.0.0 improves TPM, adds support for newer operating systems, adds encryption, and updates OpenGL 4.3 and WDDM 1.2. This is a security update.
https://customerconnect.vmware.com/downloads/#all_products

Web Package Updates

These are likely to be of interest only to web developers.

Coppermine Gallery 1.6.21 corrects a couple bugs. This is not a security update.
https://coppermine-gallery.net/

Drupal 9.5.1 resolves several bugs. This is not a security update.
https://drupal.org/download

HumHub 1.13.0 improves module integration, Spaces, adds Open Graph, diagnostics and several other features. This is not a security update.
https://www.humhub.com/en/download

ISPConfig 3.2.9 adds 2FA and support for latest Ubuntu, and resolves several bugs. This is not a security update.
https://www.ispconfig.org/ispconfig/download/

jQuery 3.6.3 resolves the CSS.supports selector bug. This is not a security update.
https://code.jquery.com/

Piwigo 13.4.0 resolves several bugs. This is not a security update.
https://piwigo.org/

SpamAssassin 4.0.0 is a major update adding full Unicode support, parsing for many more URL forms and TLDs, and resolves several bugs. This is not a security update.
https://spamassassin.apache.org/downloads.cgi

BuddyPress 11.0.0 improves performance, adds webp support, and resolves dozens of bugs. This is a security update.
https://wordpress.org/extend/plugins/buddypress/

Contact Form 7 5.7.2 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/contact-form-7/

Social Post Feed 4.1.6 resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/custom-facebook-feed/

Postie 1.9.63 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/postie/

Raw HTML 1.6.4 improves compatibility. This is not a security update.
https://wordpress.org/extend/plugins/raw-html/

Register IP – Multisite 1.9.1 resolves a couple bugs. This is not a security update.
https://wordpress.org/extend/plugins/register-ip-multisite/

WooCommerce 7.2.2 resolves dozens of bugs. This is not a security update.
https://wordpress.org/extend/plugins/woocommerce/

WP Mail SMTP 3.7.0 improves cleanup and resolves several bugs. This is not a security update.
https://wordpress.org/extend/plugins/wp-mail-smtp/

WP Update Server 2.0.1 improves compatibility. This is not a security update.
https://github.com/YahnisElsts/wp-update-server

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/