Updates 2020-02-11

Welcome back, Folks!

Today is Patch Tuesday for February 2020.

Microsoft blinked and released three updates to Windows 7 this month, however two of the issues that were resolved were actually caused by their EOL updates released last month. It’s no longer trustworthy, so do not let Windows 7 touch the Internet!

Windows 7 is officially end-of-life (EOL). If you’re still running it, shame on you, and if you are running a licensed version of Windows 7 or 8 you can still upgrade to Windows 10 and have a supported version of Windows for the foreseeable future. Don’t want to do it yourself? Call me!
https://saferpc.info/contact/

The Windows Update engine relies upon a file called “wsusscn2.cab” which is currently choking on download. While there are several Windows updates available today, it looks like the time just to check for updates will be over 2 hours for most devices today. Have patience or wait to start patching until later when they resolve this issue. There’s plenty of other stuff to patch anyway.

This Month in Technology

macOS finally fixes the Sudo bug (after 9 years), but this pales in comparison to the ease at which Mac users are infected through social engineering tactics. If you still think Mac’s are more secure than Windows, you need to see the numbers from MalwareBytes which show the typical Mac is targeted by nearly double the malware that Windows devices are. One special note here is that the users trusted the names of the websites that were involved, mostly a result of allowing domains to expire (a common concept within the broad scheme of domain hijacking).

While we’re on the subject of renewing domains, don’t forget your certificates! TLS/SSL certificates are often an enterprise’s weakest point of failure, especially when they’re not renewed on time. This will become even more important as TLS 1.0 and 1.1 are deprecated over the next couple months, which will prevent most older devices from being able to safely use the Internet at all. How important is certificate trust? Last months certificate hijacking bug allowed a researcher to replicate NSA and Github certificates in less than 24 hours which could be used immediately in MitM and DNS cache poisoning attacks with no effort from the attacker and as little as 10 lines of browser-based code.

Microsoft has decided to end it’s own ad platform within UWP apps, which will seriously hurt the entire UWP ecosystem and likely their users, by encouraging less security- and privacy-concerned third-party platforms to take their place.

This month we’ve seen data dumps from Twitter user details (shortly before a Twitter outage), Trello, Google, half a million servers, routers, and IoT devices, a major cannabis dispensary POS vendor, THSuite, WhatsApp had a major vulnerability (since patched), a Zoom vulnerability allowed hackers to eavesdrop on your calls, Mitsubishi was hacked via their enterprise security software, Trend Micro OfficeScan, and the United Nations was hacked through an unpatched server.

Is your privacy important? Apple bowed to the FBI to prevent fully-encrypted backups, ICE is using cellphone location data to track immigrants, but Avast has decided to stop selling it’s user data and they’re “sorry”, so at least there’s some good news.

Of course, any account can be hacked, even Facebook’s Twitter and Instagram accounts, and the NFL, and this month the City of Oshkosh (WI) and Duplin County (NC) join the “yet another government network hijacked” club.

It’s one thing to be incompetent when it comes to security, but Blizzard doesn’t even understand their users. This month they’re asserting total copyright ownership of any mods their users create and they released Warcraft: Reforged, which is the first game to ever be reviewed this poorly by the userbase. You might give Blizzard some credit for this – after all, they did build the engine that allowed the third-party “Dota” to flourish. LastPass, however, built their own system but accidentally removed their own extension from the Chrome Web Store!

In IoT news, more than 2/3rds of corporate and government entities were compromised with endpoint attacks in 2019, the weakest link might be the building itself or any of tens of millions of devices on a typical corporate or government network, though, as expected, many Huawei IoT devices have a backdoor. A serious public key exposure in Fortinet SIEM allows evildoers to kill your security appliance, and a critial zero-day in SolarWinds RMM allows attackers to hijack your network. Supply chain attacks targeting EOL Windows 7 devices remind us why we should avoid EOL hardware and software, and Phillips Hue lightbulbs are still proving that they weren’t well though-out security-wise. Thousand of WordPress-based websites have been hijacked to redirect visitors to evil sites, and there is always more to security than patching.

Let’s end my soapbox on a happy note: The best news this month might just be that Netflix finally offers an option to disable those #@$& autoplay previews. It’s about time.

Let’s Get Busy

Now back to our regularly scheduled program. The typical computer should see roughly 2.2 GB in updates today. Let’s get started.

Microsoft released updates for Windows, Internet Explorer, .NET, Flash, Servicing Stack, and MSRT (~1.2 GB). This includes security updates. A reboot is required.

Apple released updates for macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra, iCloud for Windows 10.9.2, iCloud for Windows 7.17, iOS 13.3.1, iPadOS 13.3.1, iTunes for Windows 12.10.4, Safari 13.0.5, tvOS 13.3.1, and watchOS 6.1.2. These are security updates. Use Apple Software Update to install the most current versions.

iOS 13.3.1 and 12.4.5 are security updates. Use Settings, General, Software Update to install the most current update.

iPadOS 13.3.1 is a security update. Use Settings, General, Software Update to install the most current update.

watchOS 6.1.2 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 13.3.1 is a security update. Use System, Software Update to install the most current version.

Google Chrome OS 79.0.3945.123 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Adobe Flash Player 32.0.0.330 is a security update. Take comfort knowing that Flash will be EOL in only 10 months.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Catalina (10.15) means that macOS Sierra (10.12) and older are no longer supported. If you can not install at least macOS High Sierra (10.13) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (1909) is a pretty small update so will install quickly. Windows 10 pushes you to get the latest Windows 10 release every 6 months. If you don’t let it finish and you’re on a slow connection, this process kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Display Driver Uninstaller 18.0.2.2 resolves several issues and improves removal procedure. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

BullZip PDF Printer 11.12.0.2816 improves compatibility with Chrome 80+. This is not a security update.
https://www.bullzip.com/products/pdf/info.php#download

Intel Driver and Support Assistant 20.1.5 improves user interface, performance, uninstall, and resolves several bugs. This is not a security update.
https://www.intel.com/p/en_US/support/detect

nVidia 442.19 adds framerate capping, performance improvements for certain games, VRSS controls, and support for newer hardware. This is not a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Garmin Express 6.20 doesn’t provide a changelog so should be treated as a security update.
https://www.garmin.com/en-US/software/express/

Browser Updates

One or more of these are likely to be of interest to everyone.

Google Chrome 80.0.3987.100 is a security update. This version is also the predecessor to the new samesite cookie handling behavior that will cause problems for various industries, including ad-services. Use Menu, Help, About to install the most current version.

Firefox 73.0 is a security update. Use Menu, Help, About to install the most current version.

Firefox ESR 68.5.0 is a security update. Use Menu, Help, About to install the most current version.

Iridium 2019.11.78 is a security update. Use Menu, Help, About to install the most current version.

Vivaldi 2.10.1745.27 is a security update. Use Menu, Help, About to install the most current version.

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 68.5.0 is a security update. Use Menu, Help, About to install the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

MaxMind GeoLite: Due to their interpretation of the CCPA (California Consumer Privacy Act), MaxMind has opted to no longer provide direct downloads of their IP information databases. An account and agreement to perform updates immediately upon publishing new releases and removal of all existing copies is now required. Due to this we will no longer be listing MaxMind on SaferPC. I suggest you integrate their automatic update service into your existing platform to ensure that you can comply with their new usage agreement.

Prosody 0.11.4 improves performance and resolves several bugs. This is not a security update.
https://prosody.im/download/start

BrowsingHistoryView 2.36 adds option to delete Chrome and Firefox history records. This is not a security update.
https://www.nirsoft.net/utils/browsing_history_view.html

FreeNAS 11.3 is a major update offering improved performance, security controls, community plugin integration, improved granularity of alerts and more. This is not a security update.
https://www.freenas.org/download-freenas-release/

Npcap 0.9987 is a security update.
https://nmap.org/npcap/

Media Updates

These are unlikely to be of interest to most people.

iTunes 12.10.4 is a security update. Use Apple Software Update to install the most current version.

Game Updates

These are unlikely to be of interest to most people.

Steam 2020.01.20 resolves several bugs and improves reliability of Remote Play. This is not a security update.

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Reader DC 20.006.20034 is a security update. Use Help, Check for Updates to get the most current version.

Adobe DNG 12.2 adds support for new hardware. This is not a security update.
Mac: https://supportdownloads.adobe.com/detail.jsp?ftpID=6879
Win: https://supportdownloads.adobe.com/detail.jsp?ftpID=6881

Adobe Experience Manager 6.5.0-31870 and 6.4.0-31868 are security updates.
https://helpx.adobe.com/security/products/experience-manager/apsb20-08.html

Adobe Digital Editions 4.5.11 is a security update.
https://helpx.adobe.com/security/products/Digital-Editions/apsb20-07.html

Adobe Framemaker 2019.0.5 is a security update.
https://helpx.adobe.com/security/products/framemaker/apsb20-04.html

Adobe Illustrator CC 24.0.2 is a security update.
https://helpx.adobe.com/security/products/illustrator/apsb20-03.html

Artweaver 7.0.4 resolves several bugs and improves performance with impasto and PSD text layers. This is not a security update.
https://www.artweaver.de/

Atom 1.44.0 resolves several bugs. This is not a security update.
https://atom.io/

LibreOffice Still 6.3.4 is a major update adding a wide variety of new features and performance improvements. This is not a security update.
https://www.libreoffice.org/

LibreOffice Fresh 6.4.0 resolves almost 500 bugs, including security issues. The typical user should run LibreOffice Still (stable), not Fresh (beta).
https://www.libreoffice.org/

Lightworks NLE 14.5 adds dozens of new features, export options, media codecs, and over a hundred bugs. This should be treated as a security update.
https://www.lwks.com/

Notepad++ 7.8.4 adds JSON and Workspace improvements, and resolves a crash bug. This is not a security update.
https://notepad-plus-plus.org/

Paint.net 4.2.9 resolves several bugs and improves performance. This is not a security update.
https://www.getpaint.net/

Security Software Updates

One or more of these is likely to be of interest to most people.

QubesOS 4.0.3 is a security update.
https://www.qubes-os.org/downloads/

elementaryOS 5.1.2 is a security update.
https://elementary.io/

RogueKiller 14.1.1 resolves several bugs. This is a security update.
https://www.adlice.com/download/roguekiller/

TinyWall 3.0 improves reliability, user interface, exception controls, and resolves several bugs. This is not a security update.
https://tinywall.pados.hu/

Capture Updates

These are unlikely to be of interest to most people.

ScreenToGif 2.20.2 resolves several bugs. This is not a security update.
https://www.fosshub.com/ScreenToGif.html

Converter Updates

These are unlikely to be of interest to most people.

MKVToolnix 43.0.0 resolves several bugs and improves user interface defaults options from command line. This is not a security update.
https://www.fosshub.com/MKVToolNix.html

DVDFab 11.0.7.1 resolves several bugs and adds support for newer encodings. This is not a security update.
https://www.dvdfab.cn/download.htm

Utility Updates

These are unlikely to be of interest to most people.

RoboForm 8.6.6 improves compatibility and resolves several bugs. This is not a security update.
https://www.roboform.com/

Easy2Boot 1.B8A improves compatibility and user-interface. This is not a security update.
https://www.fosshub.com/Easy2Boot.html

1Password for Mac 7.4.2 improves compatibility and resolves several bugs. This is not a security update.
https://1password.com/downloads/mac/

ControlMyMonitor 1.25 adds option to put icon in tray. This is not a security update.
https://www.nirsoft.net/utils/control_my_monitor.html

DesktopOK 6.84 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

DevManView 1.66 adds Class GUID column. This is not a security update.
https://www.nirsoft.net/utils/device_manager_view.html

Etcher 1.5.76 updates libraries and resolves several bugs. This is not a security update.
https://www.balena.io/etcher/

Everything CLI 1.1.0.18 doesn’t provide a changelog, so should be treated as a security update.
https://www.voidtools.com/

FileLocator Pro 8.5.2944 resolves several bugs. This is not a security update.
https://www.mythicsoft.com/filelocatorpro/download

Fing 8.8.2 improves user interaction and resolves several bugs. This is not a security update.
https://community.fing.com/

GoodSync 10.10.21 improves performance and reliability, resolves several bugs. This is not a security update.
https://www.goodsync.com/

MS ISO Downloader 8.31 adds support for new media. This is not a security update.
https://www.heidoc.net/joomla/technology-science/microsoft/67-microsoft-windows-and-office-iso-download-tool

OSFMount 3.0.1005 adds command-line options to load physical or logical emulation only, and resolves a permissions bug. This is not a security update.
https://www.osforensics.com/tools/mount-disk-images.html

SetDefaultBrowser 1.4 adds support for Chromium-based Edge. This is not a security update.
https://kolbi.cz/blog/2017/11/10/setdefaultbrowser-set-the-default-browser-per-user-on-windows-10-and-server-2016-build-1607/

TaskSchedulerView 1.54 adds options to select/deselect all to column chooser. This is not a security update.
https://www.nirsoft.net/utils/task_scheduler_view.html

USBDeview 2.86 adds mode option for Regedit call, to support opening with or without elevation.
https://www.nirsoft.net/utils/usb_devices_view.html

WinScan2PDF 5.21 improves WIA compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WizTree 3.32 resolves several bugs, adds options to export file types to CSV, filterexclude, and command-line supporter activation. This is not a security update. On the note of Supporters – this software is amazing. Use it. And donate.
https://antibody-software.com/web/software/software/wiztree-finds-the-files-and-folders-using-the-most-disk-space-on-your-hard-drive/

Developer Updates

These are unlikely to be of interest to most people.

Godot 3.2 improves reliability, performance, stability and resolves almost 2,000 bugs. This should be treated as a security update.
https://godotengine.org/

Node.js 13.8.0 is a security update.
https://nodejs.org/en/

SQLite 3.31.1 adds generated columns, hard heap limits, improved pragma, dbstat aggregated mode support, open nofollow, and resolves an internal schema compatibility issue. This compatibility fix is temporary, so fix your applications if you currently rely on parsing the data structure via internal schema. This is a security update.
https://www.sqlite.org/download.html

Visual Studio Code 1.42 resolves several bugs, improves user interface, additional preference controls, task management, and more. This is not a security update.
https://code.visualstudio.com/

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 6.1.2-135663 resolves several bugs and improves compatibility. This is not a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

Adminer 4.7.6 resolves several bugs. This is not a security update.
https://www.adminer.org/en/

Drupal 8.8.2 resolves dozens of bugs. This is not a security update.
https://drupal.org/download

HumHub 1.4.0 updates libraries and resolves dozens of bugs. This is not a security update.
https://www.humhub.com/en/download

Joomla 3.9.15 is a security update.
https://www.joomla.org/

Magento 2.3.4, 2.2.11, 1.14.4.4, 1.9.4.4 are security updates.
https://helpx.adobe.com/security/products/magento/apsb20-02.html

Nextcloud Hub 18.0.0 is a major update adding improved file, flow, photos, calendar, mail, and talk integration, and ONLYOFFICE support. This is not a security update.
https://nextcloud.com/

ScreenConnect 19.6.26659.7340 is a security update.
https://www.connectwise.com/software/control/download

SpamAssassin 3.4.4 is a security update.
http://spamassassin.apache.org/downloads.cgi

YOURLS 1.7.6 is a security update.
https://yourls.org/

bbPress 2.6.4 is a security update.

Interactive World Map 3.1.4 is a major update that resolves several issues. This is not a security update.

myStickymenu 2.3.4 resolves several bugs. This is not a security update.

Postie 1.9.41 resolves regex bug and now attempts to process only 1 email at a time. This is not a security update.

Sucuri Security 1.8.23 updates key updater and improves user interface. This is not a security update.

W3 Total Cache 0.13.1 resolves several bugs. This is not a security update.

WooCommerce 3.9.1 resolves several bugs. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2019-06-11

Hi, Folks!

Today is Patch Tuesday for June 2019 and it’s a big one.

The typical computer should see roughly 1.1 GB in updates today. Let’s get started.

Microsoft released updates for Windows, .NET, Edge, Internet Explorer, Flash, Dynamic Update, POSReady and MSRT (~2 GB). This includes security updates. A reboot is required.

Apple released updates for iOS 12.3.2, iCloud for Windows 7.12, iTunes for Windows 12.9.5, AirPort Base Station Firmware 7.9.1, and macOS Mojave 10.14.5 Supplemental Update. This includes security updates. Use Apple Software Update to install the most current versions.

iOS 12.3.2 is a security update. Use Settings, General, Software Update to install the most current update.

Adobe Flash Player 32.0.0.207 is a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Google Chrome OS 74.0.3729.159 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The now-current release of Windows 10 (1903) will cause your computer to feel unusually slow until it is installed. This is a side-effect of the Windows 10 upgrade cycle, which pushes out 3-6 GB through Windows update to get you to the latest Windows 10 release every 6 months. If you don’t let it finish and you’re on a slow connection, it will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Display Driver Uninstaller 18.0.1.5 adds support for newer hardware, improves cleanup and stability. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

Intel Driver & Support Assistant 19.5.22 resolves several bugs and improves security. This is a security update.
https://www.intel.com/p/en_US/support/detect

nVidia 430.86 adds support for newer hardware and updates game profiles. This is a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Browser Updates

One or more of these are likely to be of interest to everyone.

Google Chrome 75.0.3770.80 is a security update. Use Menu, Help, About to install the most current version.

Firefox 67.0.2 is a security update. Use Menu, Help, About to install the most current version.

Firefox ESR 60.7.0 is a security update. Use Menu, Help, About to install the most current version.

Vivaldi 2.5.1525.48 is a security update. Use Menu, Help, About to install the most current version.

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 60.7.0 is a security update. Use Menu, Help, About to install the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

iCloud for Windows 7.12 is a security update. Use Apple Software Update to get the most current version.

Skype 8.45.0.41 adds quick sign out and improves preference persistence. This is not a security update.
https://12pd.com/click?skype

IPInfoOffline 1.50 adds GeoLite2 City, Country and ASN database support. This is not a security update.
https://www.nirsoft.net/utils/ip_country_info_offline.html

MaxMind GeoIP 201906 is a data refresh.
https://dev.maxmind.com/geoip/

Technitium DNS Server 3.3 resolves several bugs. This is not a security update.
https://technitium.com/dns/

WinSCP 5.15.2 is a security update.
https://winscp.net/eng/index.php

Media Updates

These are unlikely to be of interest to most people.

FastStone Viewer 7.1 adds HEIC and WEBP support, resolves bugs, and improves stability and security. This is a security update.
https://www.faststone.org/FSViewerDetail.htm

iTunes 12.9.5 is a security update. Use Apple Software Update to get the most current version.

VLC Media Player 3.0.7 improves Blu-ray and MP4 support, and resolves several bugs. This is a security update.
https://www.videolan.org/vlc/

Game Updates

These are unlikely to be of interest to most people.

PlayStation PS4 6.71 improves performance. This is not a security update.
https://www.playstation.com/en-us/support/system-updates/ps4/

Office Updates

One or more of these are likely to be of interest to most people.

Artweaver 6.0.12 improves stability and resolves a cloning bug. This is not a security update.
http://www.artweaver.de/

LibreOffice Fresh 6.2.4 resolves over a hundred bugs. This is not a security update.
https://www.libreoffice.org/

Notepad++ 7.7.0 updates Scintilla to 4.1.x and adds code signing. This should be treated as a security update. The first time it is opened after updating from a previous version will take longer. Be patient.
https://12pd.com/click?npp

Atom 1.38.0 resolves several bugs. This is not a security update.
https://atom.io/

Security Software Updates

One or more of these is likely to be of interest to most people.

Wireshark 3.0.2 is a security update.
https://www.wireshark.org/

Gpg4win 3.1.8 resolves several bugs. This is not a security update.
https://www.gpg4win.org/download.html

OpenSSL 1.0.2s is a security update.
https://openssl.org/

RogueKiller 13.2.2 resolves several bugs. This is not a security update.
https://www.adlice.com/softwares/roguekiller/

RouterPassView 1.81 resolves a bug decompressing some binaries. This is not a security update.
https://www.nirsoft.net/utils/router_password_recovery.html

Stinger 12.1.0.3196 adds support for new detections. This is not a security update.
https://12pd.com/click?stinger

DNSQuerySniffer 1.80 adds support for GeoLite2 City and Country databases. This is not a security update.
https://www.nirsoft.net/utils/dns_query_sniffer.html

Capture Updates

These are unlikely to be of interest to most people.

SnagIt 2019.1.2 adds support for varying High-DPI displays, resolves several bugs, updates integration. This is not a security update.
https://download.techsmith.com/snagit/enu/snagit.exe

Converter Updates

These are unlikely to be of interest to most people.

CDex 2.18 resolves several bugs. This is not a security update.
https://cdex.mu/?q=download

DVDFab 11.0.3.4 improves compatibility, adds support for new encodings, and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/download.htm

MakeMKV 1.14.4 adds support for new encodings and resolves several bugs. This is not a security update.
https://12pd.com/click?makemkv

Utility Updates

These are unlikely to be of interest to most people.

NTLite 1.8.0.6975 adds settings, adds support for Windows 10 v1903, and resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

1Password for Mac 7.3 improves mini, integration, and drag and drop support. This is not a security update.
https://1password.com/downloads/mac/

8GadgetPack 29.0 improves compatibility with Windows 10 v1903. This is not a security update.
https://8gadgetpack.net/

Beyond Compare 4.2.10.23938 adds support for case-sensitive folders, improves compatibility with OneDrive, and resolves several bugs. This is not a security update.
https://www.scootersoftware.com/download.php?zz=dl4

Carbonite 6.3.5 resolves OneDrive compatibility issues. This is not a security update.
https://account.carbonite.com/

CPU-Z Installer 1.89 adds support for newer hardware. This is not a security update.
https://www.cpuid.com/softwares/cpu-z.html

DesktopOK 6.31 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

GoodSync 10.9.33 improves compatibility, updates libraries, and resolves bugs. This is not a security update.
https://12pd.com/click?goodsync

IsMyHdOK 1.71 improves compatibility and performance. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

NetworkInterfacesView 1.15 adds several new fields and automatic elevation support. This is not a security update.
https://www.nirsoft.net/utils/network_interfaces.html

NetworkTrafficView 2.30 adds several new columns. This is not a security update.
https://www.nirsoft.net/utils/network_traffic_view.html

OSFMount 3.0.1004 resolves a couple bugs. This is not a security update.
https://www.osforensics.com/tools/mount-disk-images.html

PointerStick 3.55 removes buggy code signing certificate. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

QuickSetDNS 1.30 adds support for IPv6.
https://www.nirsoft.net/utils/quick_set_dns.html

RoboForm 8.5.9 adds encryption iteration option and resolves several bugs. This is not a security update.
https://12pd.com/click?rf

SearchMyFiles 2.92 resolves large file size search and adds Explorer context feature. This is not a security update.
https://www.nirsoft.net/utils/search_my_files.html

TraceRouteOK 1.41 adds Polish language support. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/TraceRouteOK

WinScan2PDF 4.81 removes buggy code signing certificate. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WizTree 3.29 resolves stability bugs. This is a security update.
https://antibody-software.com/web/software/software/wiztree-finds-the-files-and-folders-using-the-most-disk-space-on-your-hard-drive/

WSUS Offline 11.7.2 resolves several bugs. This should be treated as a security update.
http://download.wsusoffline.net/

Windows 10 Media Creation Tool 1903 allows creating your own Windows 10 installation media for the latest build of Windows.
https://www.microsoft.com/en-us/software-download/windows10

Developer Updates

These are unlikely to be of interest to most people.

Node.js 12.4.0 moves several experimental features to stable, and updates several heap capabilities. This is not a security update.
https://nodejs.org/en/

StrawberryPerl 5.30.0.1 updates Perl core, gcc compiler and libraries. This is a security update.
http://strawberryperl.com/

Visual Studio Code 1.35 improves native semantic behaviors, definition context, breadcrumbs, and better merge conflict display. This is not a security update.
https://code.visualstudio.com/

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 6.0.8-130520 resolves several bugs. This is not a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

Drupal 8.7.3 resolves several bugs. This is a security update.
https://drupal.org/download

Joomla 3.9.7 is a security update.
https://www.joomla.org/

ConnectWise Control 19.1.24050.7079 doesn’t provide a detailed changelog (their site changes have been a pain), so this should be treated as a security update.
https://www.connectwise.com/software/control/download

MailEnable Enterprise 10.24 is a security update.
https://www.mailenable.com/

Nextcloud Server 16.0.1 resolves several bugs. This is not a security update.
https://nextcloud.com/

phpMyAdmin 4.9.0.1 resolves dozens of bugs. This is a security update.
https://www.phpmyadmin.net/home_page/news.php

WordPress 5.2.1 resolves several bugs. This is not a security update.
https://wordpress.org/

Autoptimize 2.5.1 improves image handling, CSS deferral, and settings interface. This is not a security update.

Contact Form 7 5.1.3 resolves the Mail tab check bug. This is not a security update.

myStickymenu 2.1.6 is a security update.

Postie 1.9.35 resolves several bugs. This is not a security update.

Really Simple CAPTCHA 2.0.2 resolves a bug. This is not a security update.

Redirection 4.3.1 resolves several bugs. This is not a security update.

NextScripts Social Networks Auto-Poster 4.3.7 improves compatibility. This is not a security update.

W3 Total Cache 0.9.7.5 updates libraries, resolves several bugs, and improves default PHP behaviors. This is not a security update.

WooCommerce 3.6.4 resolves several bugs. This is not a security update.

WordPress Zero Spam 3.1.1 resolves several bugs. This is a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2019-05-14

Hi, Folks!

Today is Patch Tuesday for May 2019.

This month was eventful.

Mozilla resolved the catastrophic end-of-extensions bug in Firefox that disabled all extensions worldwide for all Firefox users. From the rage and fear, you’d have thought the entire Internet was broken. While this event was disastrous for everyone who relies upon browser extensions for their daily lives (such as AdBlock), it was likely the single-most effective cleanup of malware in history.

Antivirus isn’t enough. According to reputable sources, a Russian hacking collective (Fxmsp) claims to have secured access to three leading antivirus companies.

According to the hacking collective, they worked tirelessly for the first quarter of 2019 to breach these companies and finally succeeded and obtained access to the companies’ internal networks.

The collective extracted sensitive source code from antivirus software, AI, and security plugins belonging to the three companies. Fxmsp also commented on the capabilities of the different companies’ software and assessed their efficiency.

Dell SupportAssist is probably the lowest-hanging fruit on your computer. An independent researcher was able to unwrap the Dell SupportAssist service and force install arbitrary software on networked devices using no more than a single DNS hijack and publicly-available “codes” that Dell uses to authenticate actions. Their design is roughly akin to taping the keys to your house on the front door. While you should, of course, remove SupportAssist, you should also treat this as a stark reminder of why you should never use untrusted networks.

Microsoft Office changed the EULA to their software, which triggered several different issues, including previously purchased software no longer working, new data sharing prompts and an unceasing series of popups for some users. Logging out of your Microsoft Account and back in resolves the issue for many, but others required registry hacks. Smooth move, MS.

Now back to our regularly scheduled program.

The typical computer should see roughly 1.3 GB in updates today. Let’s get started.

Microsoft released updates for Windows, .NET, Edge, Internet Explorer, Flash, and MSRT (~850 MB). This includes security updates. A reboot is required.

Apple released updates for macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, Safari 12.1.1, and Apple TV Software 7.3. This includes security updates. Use Apple Software Update to install the most current versions.

iOS 12.3 is a security update. Use Settings, General, Software Update to install the most current update.

watchOS 5.2.1 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 12.3 is a security update. Use System, Software Update to install the most current version.

Adobe AIR 32.0.0.125 is a security update.
Win: https://12pd.com/click?air
Mac: https://12pd.com/click?airmac

Adobe Flash Player 32.0.0.192 is a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Fedora 30-1.2 is a major update improving compatibility, performance, and more. This build adds the optional Pantheon Desktop which will ease the transition of those coming from a macOS environment. Coupled with Darling it should now be much easier to leave Apple for Linux.
https://getfedora.org/en/workstation/download/

Google Chrome OS 74.0.3729.125 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The now-current release of Windows 10 (1903) will cause your computer to feel unusually slow until it is installed. This is a side-effect of the Windows 10 upgrade cycle, which pushes out 3-6gb through Windows update to get you to the latest Windows 10 release every 6 months. If you don’t let it finish and you’re on a slow connection, it will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Display Driver Uninstaller 18.0.1.3 improves reliability. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

Intel Driver & Support Assistant 19.4.18 improves detection of updates, adds support for Windows 10 LTSB, and adds notifications. This is a security update.
https://www.intel.com/p/en_US/support/detect

nVidia 430.64 adds support for newer hardware, removes support for Kepler hardware, and resolves several bugs. This is a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Logitech SetPoint 6.69.126 resolves several bugs. This is not a security update.
https://support.logitech.com/en_us/software/setpoint

Browser Updates

One or more of these are likely to be of interest to everyone.

Google Chrome 74.0.3729.157 is a security update (and adds dark mode). Use Menu, Help, About to install the most current version.

Firefox 66.0.5 resolves the catastrophic end-of-extensions bug. Use Menu, Help, About to install the most current version.

Firefox ESR 60.6.3 resolves the catastrophic end-of-extensions bug. Use Menu, Help, About to install the most current version.

Iridium 2019.04.73.0 is a security update. Use Menu, Help, About to install the most current version.

Vivaldi 2.5.1525.41 resolves several bugs, adds new features, improves reliability and performance. This is a security update. Use Menu, Help, About to install the most current version.

Email Updates

One or more of these are likely to be of interest to everyone.

OutlookAttachView 3.16 adds a combobox to select folders to scan or skip. This is not a security update.
https://www.nirsoft.net/utils/outlook_attachment.html

Internet Updates

One or more of these are likely to be of interest to everyone.

Skype 8.44.0.41 adds message forwarding, provides additional view options, adds optional background blur, and adds event notifications. This is not a security update.
https://12pd.com/click?skype

DynDNS Updater 5.5.0 removes backend service reporting. This should be considered a security update.
https://www.dyndns.com/

Evernote 6.18.4.8489 adds several new shortcuts, resolves several bugs. This is not a security update.
https://www.evernote.com/

FileZilla Client 3.42.1 resolves several bugs, updates libraries, improves compatibility with macOS. This is a security update.
https://filezilla-project.org/

MaxMind GeoIP 201905 is a data refresh.
https://dev.maxmind.com/geoip/

Npcap 0.995 resolves several bugs. This is not a security update.
https://nmap.org/npcap/

WinSCP 5.15.1 resolves several bugs. This is not a security update.
https://winscp.net/eng/index.php

Game Updates

These are unlikely to be of interest to most people.

EA Origin 10.5.38.25027 resolves several bugs. This is not a security update.
https://www.origin.com/en-us/download

Steam 2019.05.01 resolves several bugs. This is not a security update.
https://www.steampowered.com/platform/update_history/index.php?skin=0&id=0

SteamOS 2.190 is a security update.
https://store.steampowered.com/steamos/download/?ver=custom

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Acrobat 19.012.20034 is a security update. Use Help, Check for Updates to get the most current version.

LibreOffice Still 6.1.6 is a security update.
https://www.libreoffice.org/

LibreOffice Fresh 6.2.3 resolves dozens of bugs. This is not a security update.
https://www.libreoffice.org/

Adobe DNG Converter 11.3 adds support for newer hardware. This is a security update.
https://helpx.adobe.com/photoshop/digital-negative.html

Atom 1.37.0 improves security and resolves several bugs. This should be treated as a security update.
https://atom.io/

Security Software Updates

One or more of these is likely to be of interest to most people.

Java 8u211 is a security update. If you are not sure you need Java (or don’t know the difference between Java and JavaScript), you’re better off removing Java than installing an update.
https://www.java.com/en/download/manual.jsp

RogueKiller 13.2.0 updates engine, resolves several bugs, adds signature automatic update to free version. This should be treated as a security update.
https://www.adlice.com/softwares/roguekiller/

Stinger 12.1.0.3168 adds support for new detections. This is a security update.
https://12pd.com/click?stinger

TDSSKiller 3.1.0.28 adds support for new detections. This is a security update.
https://support.kaspersky.com/viruses/utility#TDSSKiller

Converter Updates

These are unlikely to be of interest to most people.

CDex 2.17 resolves several bugs. This is not a security update.
http://cdex.mu/?q=download

DVDFab 11.0.2.9 adds support for new encodings and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/download.htm

FFmpeg 4.1.3 resolves several bugs. This is not a security update.
https://ffmpeg.org/ffmpeg.html

Utility Updates

These are unlikely to be of interest to most people.

1Password for Windows 7.3.684 resolves several bugs, adds cleanup, improves performance. This is not a security update.
https://1password.com/downloads/windows/

Bitcoin Core 0.18.0 resolves dozens of bugs, improves performance, reliability, and privacy, updates many features, and reduces dependency on OpenSSL. This should be treated as a security update.
https://bitcoin.org/en/download

BulkFileChanger 1.61 adds new command-line option. This is not a security update.
https://www.nirsoft.net/utils/bulk_file_changer.html

ControlMyMonitor 1.15 adds an option to prevent changing a value if it is current. This is not a security update.
https://www.nirsoft.net/utils/control_my_monitor.html

CurrPorts 2.55 adds ability to capture for an extended duration instead of capturing only a snapshot. This is not a security update.
https://www.nirsoft.net/utils/cports.html

Cygwin 3.0.7 adds support for a new locale and resolves a winsock bug. This is not a security update.
https://cygwin.com/

DesktopOK 6.16 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

FolderChangesView 2.27 adds option to include header in output. This is not a security update.
https://www.nirsoft.net/utils/folder_changes_view.html

GoodSync 10.9.32 resolves several bugs, updates libraries, and adds support for RealDisk. This is not a security update.
https://12pd.com/click?goodsync

ImageUSB 1.4.1003 resolves several bugs. This is not a security update.
https://www.osforensics.com/tools/write-usb-images.html

IsMyHdOK 1.66 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

NetworkTrafficView 2.25 improves reliability and adds support for UDP. This is not a security update.
https://www.nirsoft.net/utils/network_traffic_view.html

NirCmd 2.83 adds runinteractive options. This is not a security update.
https://www.nirsoft.net/utils/nircmd.html

NTLite 1.7.6.6912 adds support for Windows 10 v1903, resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

OSFMount 3.0.1003 improves performance, resolves several bugs. This is not a security update.
https://www.osforensics.com/tools/mount-disk-images.html

PointerStick 3.52 resolves a startup bug. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

RegFileExport 1.11 resolves a large-value bug. This is not a security update.
https://www.nirsoft.net/utils/registry_file_offline_export.html

SimpleWMIView 1.36 adds an option to attempt elevation. This is not a security update.
https://www.nirsoft.net/utils/simple_wmi_view.html

Synergy 1.10.2 resolves several bugs. This should be treated as a security update.
https://symless.com/blog/synergy-1-10-2-finally-released

DebugView 4.90 doesn’t provide a changelog, so should be treated as a security update.
https://live.sysinternals.com/

RAMMap 1.52 doesn’t provide a changelog, so should be treated as a security update.
https://live.sysinternals.com/

TaskSchedulerView 1.50 adds options to control tasks from the command line. This is not a security update.
https://www.nirsoft.net/utils/task_scheduler_view.html

WifiChannelMonitor 1.59 resolves a displaymode bug. This is not a security update.
https://www.nirsoft.net/utils/wifi_channel_monitor.html

WifiInfoView 2.46 adds always on top and scanning options, and updates the MAC database. This is not a security update.
https://www.nirsoft.net/utils/wifi_information_view.html

WinScan2PDF 4.78 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WSUS Offline 11.7 disables autorecall, updates libraries, improves detection. This is not a security update.
http://download.wsusoffline.net/

Developer Updates

These are unlikely to be of interest to most people.

Godot 3.1.1 is a security update.
https://godotengine.org/

MySQL 8.0.16 updates libraries, grant/revoke behavior, and resolves many bugs. This is a security update.
https://www.mysql.com/downloads/installer/

Node.js 12.2.0 resolves dozens of bugs, updates libraries, and adds and improves features. This is a security update.
https://nodejs.org/en/

SQLite 3.28.0 resolves several bugs, improves compatibility, and offers new language constructs. This is a security update.
https://www.sqlite.org/download.html

StrawberryPerl 5.28.2.1 updates core, modules, and libraries. This is a security update.
http://strawberryperl.com/

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 6.0.6-130049 resolves dozens of bugs. This should be treated as a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

Joomla 3.9.6 is a security update.
https://www.joomla.org/

Drupal 8.7.1 is a security update.
https://drupal.org/download

Nextcloud Server 16.0.0 adds ACL support, Talk commands, and machine learning for security and productivity. This is a security update.
https://nextcloud.com/

ScreenConnect 19.0.23665.7058 adds several new features, cosmetics, dark mode, network information, improves auditing and more. This is not a security update.
https://www.screenconnect.com/Download

phpList 3.4.2 resolves several bugs. This is not a security update.
https://www.phplist.com/download

WordPress 5.2 improves self-diagnostics, accessibility, and more. This is not a security update.
https://wordpress.org/

Akismet 4.1.2 resolves bugs and improves compatibility. This is not a security update.

Autoptimize 2.5.0 adds lazyloading, and redesigns image optimization. This is not a security update.

BuddyPress 4.3.0 is a security update.

Custom Facebook Feed 2.9.1 resolves several bugs. This is not a security update.

Email Log 2.3.1 resolves a bug. This is not a security update.

myStickymenu 2.1.4 resolves several bugs. This is not a security update.

Postie 1.9.33 now assigns an author to all media items. This is not a security update.

Raw HTML 1.6 improves handling of raw objects. This is not a security update.

Redirection 4.2.3 resolves a bug. This is not a security update.

Register IPs 1.8.1 is a security update.

NextScripts Social Networks Auto-Poster 4.3.6 resolves several bugs, adds location and twitter handle support. This is not a security update.

Sucuri Security 1.8.21 adds several new diagnostic features and resolves several bugs. This is not a security update.

Theme My Login 7.0.14 improves compatibility. This is not a security update.

W3 Total Cache 0.9.7.4 resolves several bugs. This is a security update.

WooCommerce 3.6.2 resolves many bugs. This is a security update.

WPtouch 4.3.37 adds SMS sharing option. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2019-04-09

Hi, Folks!

Today is Patch Tuesday for April 2019. Windows 10 v1903 is just around the corner. Edge users will start getting it over the next few days, with the majority of Home users getting it near the end of the month. You can delay it by installing v1809 if you haven’t done so yet, which will grant you a 3 month reprieve. Today is also the last day of updates released for any Windows 10 version prior to v1803. If you’re running v1507-v1709 (and not running a long-term servicing build) then you should upgrade to v1809 ASAP.

The typical computer should see roughly 1.2 GB in updates today. Let’s get started.

Microsoft released updates for Windows, .NET, Edge, Internet Explorer, Flash, POSReady, and MSRT (~850 MB). This includes security updates. A reboot is required.

Apple released updates for macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4, iCloud for Windows 7.11, Xcode 10.2, and watchOS 5.2. This includes security updates. Use Apple Software Update to install the most current versions.

iOS 12.2 is a security update. Use Settings, General, Software Update to install the most current update.

watchOS 5.2 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 12.2 is a security update. Use System, Software Update to install the most current version.

Adobe AIR 32.0.0.116 is a security update.
Win: https://12pd.com/click?air
Mac: https://12pd.com/click?airmac

Adobe Flash Player 32.0.0.171 is a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Google Chrome OS 73.0.3683.88 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The now-current release of Windows 10 (1903) will cause your computer to feel unusually slow until it is installed. This is a side-effect of the Windows 10 upgrade cycle, which pushes out 3-6gb through Windows update to get you to the latest Windows 10 release every 6 months. If you don’t let it finish and you’re on a slow connection, it will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Seagull Scientific Driver 2019.1 adds support for over 115 new printer models, but installs a Seagull Scientific Certificate which might later be used for exploitation. This is not a security update.
https://www.seagullscientific.com/drivers/

Display Driver Uninstaller 18.0.1.1 resolves several bugs. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

Intel Driver & Support Assistant 19.3.12 adds support for newer hardware and resolves several bugs. This is not a security update.
https://www.intel.com/p/en_US/support/detect

Browser Updates

One or more of these are likely to be of interest to everyone.

Google Chrome 73.0.3683.103 resolves several bugs. This is not a security update. Use Menu, Help, About to install the most current version.

Firefox 66.0.2 resolves several stability and compatibility bugs. This version follows closely on the 66.0.1 security update. Use Menu, Help, About to install the most current version.

Firefox ESR 60.6.1 is a security update. Use Menu, Help, About to install the most current version.

Vivaldi 2.4.1488.36 resolves several bugs, adds many new features including GUI customization and stack management. This is a security update. Use Menu, Help, About to install the most current version.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Mailspring 1.6.1 resolves several bugs. This is not a security update.
https://getmailspring.com/

Thunderbird 60.6.1 is a security update. Use Menu, Help, About to install the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

Skype 8.42.0.60
https://12pd.com/click?skype

FileZilla Client 3.41.2 is a security update.
https://filezilla-project.org/

MaxMind GeoIP 201904 is a data refresh.
https://dev.maxmind.com/geoip/

Npcap 0.992 resolves several bugs. This is not a security update.
https://nmap.org/npcap/

PuTTY 0.71 is a security update.
https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html

WGet 1.20.3 is a security update. However, this version breaks HTTPS so should be avoided for now.
https://eternallybored.org/misc/wget/

WinSCP 5.15 resolves several bugs and adds a dark mode. This is a security update.
https://winscp.net/eng/index.php

Line 9.4.0 adds chat capture. This is not a security update.
https://line.me/update

ZeroNet 0.6.5 resolves several bugs. This is not a security update.
https://zeronet.io/

Media Updates

These are unlikely to be of interest to most people.

iTunes 12.9.4 for Windows is a security update. Use Apple Software Update to install the most current version.

iCloud for Windows 7.11 is a security update. Use Apple Software Update to install the most current version.

CDBurnerXP 4.5.8.7042 resolves a burn speed bug on multiple copies. This is not a security update.
https://cdburnerxp.se/

FastStone Viewer 7.0 adds support for monitor color profiles, improves compatibility, and dual instance display option differences. This is a security update.
https://www.faststone.org/FSViewerDetail.htm

iTunes 12.9.4 is a security update.
https://www.apple.com/itunes/download/

Game Updates

These are unlikely to be of interest to most people.

EA Origin 10.5.36.23506 resolves several bugs. This is not a security update.
https://www.origin.com/en-us/download

PlayStation PS4 6.51 improves performance. This is not a security update.
https://www.playstation.com/en-us/support/system-updates/ps4/

SteamOS 2019-02-28 is a security update.
https://store.steampowered.com/steamos/download/?ver=custom

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Reader DC 19.010.20099 is a security update. Use Help, Check for Updates to install the most current version.

Atom 1.35.1 resolves a bug. This is not a security update.
https://atom.io/

Paint.net 4.1.6 resolves several bugs and improves performance. This is not a security update.
https://www.getpaint.net/

LibreOffice Fresh 6.2.2 resolves dozens of bugs. Remember that the Fresh branch is the LibreOffice Beta, so the Still (Stable) line should be used by most users.
https://www.libreoffice.org/

Artweaver 6.0.11 resolves several bugs. This is not a security update.
http://www.artweaver.de/

Notepad++ 7.6.6 resolves the file-change-detection nag on frequently updated files and adds GPG release signing.
https://12pd.com/click?npp

FrameMaker 2019.0.3 is a security update.
64-bit: https://supportdownloads.adobe.com/detail.jsp?ftpID=6645
32-bit: https://supportdownloads.adobe.com/detail.jsp?ftpID=6643

Adobe Bridge CC 9.0.3 is a security update.
https://helpx.adobe.com/security/products/bridge/apsb19-25.html

Adobe Experience Manager Forms 6.2.sp1-cfp15, 6.3.3.1, 6.4.2.0 are security updates.
https://helpx.adobe.com/security/products/aem-forms/apsb19-24.html

Adobe InDesign 14.0.2 is a security update.
https://helpx.adobe.com/security/products/indesign/apsb19-23.html

Adobe XD CC 17.0.12 is a security update.
https://helpx.adobe.com/security/products/xd/apsb19-22.html

Adobe Dreamweaver 19.1 is a security update.
https://helpx.adobe.com/security/products/dreamweaver/apsb19-21.html

Adobe Shockwave player 12.3.5.205 is a security update, however, it is officially end-of-life (EOL) as of today so your best option is to remove Shockwave from any and all devices.

Security Software Updates

One or more of these is likely to be of interest to most people.

DNSQuerySniffer 1.76 adds Quick Filter feature. This is not a security update.
https://www.nirsoft.net/utils/dns_query_sniffer.html

Gpg4win 3.1.7 is a security update.
https://www.gpg4win.org/download.html

RogueKiller 13.1.9 updates scanning engine and adds support for several new file types. This should be treated as a security update.
https://www.adlice.com/softwares/roguekiller/

Wireshark 3.0.1 resolves several security issues.
http://www.wireshark.org/

Stinger 12.1.0.3107 adds support for new detections. This is a security update.
https://12pd.com/click?stinger

Capture Updates

These are unlikely to be of interest to most people.

VideoCacheView 3.05 adds manual merge option. This is not a security update.
https://www.nirsoft.net/utils/video_cache_view.html

Converter Updates

These are unlikely to be of interest to most people.

CDex 2.16 resolves several bugs. This is not a security update.
http://cdex.mu/?q=download

DVDFab 11.0.2.3 resolves several bugs and adds support for new encodings. This is not a security update.
https://www.dvdfab.cn/download.htm

Utility Updates

These are unlikely to be of interest to most people.

NTLite 1.7.5.6842 resolves several bugs and adds new options. This is not a security update.
https://www.ntlite.com/download/

CPU-Z Installer 1.88 adds support for new hardware. This is not a security update.
https://www.cpuid.com/softwares/cpu-z.html

Cygwin 3.0.6 resolves several bugs. This is not a security update.
https://cygwin.com/

GoodSync 10.9.30 resolves several bugs. This is not a security update.
https://12pd.com/click?goodsync

HWMonitor 1.40 adds support for new hardware. This is not a security update.
https://www.cpuid.com/softwares/hwmonitor.html

NirCmd 2.82 improves High-DPI compatibility. This is not a security update.
https://www.nirsoft.net/utils/nircmd.html

OSFMount 3.0.1000 adds several new features. This is not a security update.
https://www.osforensics.com/tools/mount-disk-images.html

RoboForm 8.5.8 resolves several bugs. This is not a security update.
https://12pd.com/click?rf

Rufus 3.5 adds Windows ISO download, adds Windows To Go support, and resolves several bugs. This is not a security update.
https://rufus.ie/en_IE.html

USBDeview 2.80 resolves serial number CLI options. This is not a security update.
https://www.nirsoft.net/utils/usb_devices_view.html

WakeMeOnLan 1.84 updates the MAC database. This is not a security update.
https://www.nirsoft.net/utils/wake_on_lan.html

WinScan2PDF 4.77 improves stability. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WSUS Offline 11.6.1 resolves several bugs. This is not a security update.
http://download.wsusoffline.net/

Developer Updates

These are unlikely to be of interest to most people.

AutoHotkey 1.1.30.03 resolves several bugs. This is not a security update.
https://www.autohotkey.com/download/

Godot 3.1 adds several new features and improves stability. This is not a security update.
https://godotengine.org/

Node.js 11.13.0 resolves several bugs. This is not a security update.
https://nodejs.org/en/

Redemption 5.20.0.5298 resolves several bugs. This is not a security update.
http://www.dimastr.com/redemption/

DB Browser for SQLite 3.11.2 resolves several bugs. This is not a security update.
https://sqlitebrowser.org/

Visual Studio Code 1.33 adds several new features. This is not a security update.
https://code.visualstudio.com/

WinMerge 2.16.2 resolves several bugs. This is not a security update.
http://winmerge.org/

Virtual Machine Updates

These are unlikely to be of interest to most people.

PPSSPP 1.8.0 doesn’t provide a changelog so should be treated as a security update.
https://ppsspp.org/downloads.html

VMware Player 15.0.4 is a security update.
https://www.vmware.com/products/player/

Web Package Updates

These are likely to be of interest only to web developers.

Joomla 3.9.5 is a security update.
https://www.joomla.org/

Drupal 8.6.14 resolves several bugs. This is not a security update.
https://drupal.org/download

phpList 3.4.0 is a security update.
https://www.phplist.com/download

TinyMCE 5.0.3 resolves several bugs. This is not a security update.
https://www.tiny.cloud/get-tiny/

MailEnable 10.23 resolves several bugs. This is not a security update.
https://www.mailenable.com/

ScreenConnect 19.0.23234.7027 reorganizes the control interface, uses a new default theme, reformats the General tab and more. This is not a security update.
https://www.screenconnect.com/Download

Nextcloud Server 15.0.7 is a security update.
https://nextcloud.com/

WordPress 5.1.1 is a security update.
https://wordpress.org/

Redirection 4.2.1 resolves several bugs. This is not a security update.

NextScripts Social Networks Auto-Poster 4.3.4 removes Google+ and 500px, adds Google My Business and fixes VK. This is not a security update.

W3 Total Cache 0.9.7.3 resolves several bugs and improves compatibility. This is not a security update.

WooCommerce 3.5.7 is a security update.

WP Mail SMTP 1.4.2 removes TGMPA. This is not a security update.

WPtouch 4.3.36 adds kinsta check. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2019-03-12

Happy St. Patrick’s Day, Folks!

Today is Patch Tuesday for March 2019, which means that the next build of Windows (v1903) is just around the corner. You can delay it by installing v1809 if you haven’t done so yet, which will grant you a 3 month reprieve. Among other features and fixes, v1903 will add automatic boot repair after failed updates. This should resolve the #1 issue plaguing the Windows Update platform: not knowing whether your computer will boot after installing updates. Even so, don’t be the guinea pig. Postpone v1903 for a couple months to let people that don’t know any better be the victims of whatever flaws v1903 inevitably brings.

The typical computer should see roughly 1 GB in updates today. Let’s get started.

Microsoft released updates for Windows, .NET, Edge, Internet Explorer, Flash, POSReady, and MSRT (~600 MB). This includes security updates. A reboot is required.

Adobe Flash Player 32.0.0.156 is a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Google Chrome OS 72.0.3626.122 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The now-current release of Windows 10 (1809) will cause your computer to feel unusually slow until it is installed and v1903 will be coming soon. This is a side-effect of the Windows 10 upgrade cycle, which pushes out 3-6gb through Windows update to get you to the latest Windows 10 release every 6 months. If you don’t let it finish and you’re on a slow connection, it will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

BullZip PDF Printer 11.9.0.2735 is a security update.
https://www.bullzip.com/products/pdf/info.php#download

Display Driver Uninstaller 18.0.0.9 resolves several bugs. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

Intel Driver & Support Assistant 19.2.8 adds self-update, installer improvements, and resolves several bugs. This is not a security update.
https://www.intel.com/p/en_US/support/detect

nVidia 419.35 adds several new game profiles, G-SYNC improvements, CUDA 10.1, and resolves several bugs. This is not a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Browser Updates

One or more of these are likely to be of interest to everyone.

Google Chrome 73.0.3683.75 is a critical security update, resolving an bug that is being actively exploited in the wild. Use Menu, Help, About to install the most current version.

Firefox 65.0.2 resolves a geolocation bug. This is not a security update. Use Menu, Help, About to install the most current version.

Firefox ESR 60.5.2 resolves a crash bug. This is not a security update. Use Menu, Help, About to install the most current version.

Vivaldi 2.3.1440.60 is a security update. Use Menu, Help, About to install the most current version.

Email Updates

One or more of these are likely to be of interest to everyone.

Mailspring 1.5.7 resolves several bugs and improves performance. This is not a security update.
https://getmailspring.com/

Thunderbird 60.5.1 is a security update. Use Menu, Help, About to install the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

Skype 8.41.0.54 adds call merge and caller-id, improved diagnostics, live captions, draft reviews, and notifications. This is not a security update.
https://12pd.com/click?skype

uTorrent 3.5.5.45146 resolves several bugs. This is not a security update.
http://www.utorrent.com/downloads

FreeFileSync 10.10 adds several new features and resolves bugs. This is a security update.
https://www.freefilesync.org/download.php

IPNetInfo 1.85 adds CSV export and export header control. This is not a security update.
https://www.nirsoft.net/utils/ipnetinfo.html

MaxMind GeoIP 201903 is a data refresh.
https://dev.maxmind.com/geoip/

Technitium DNS Server 3.0 adds TLS configuration and DNS-over-HTTPS, DNS-over-HTTP, DNS-over-TLS, additional settings and log improvements. This is not a security update.
https://technitium.com/dns/

WinSCP 5.13.8 updates libraries and resolves bugs. This is a security update.
https://winscp.net/eng/index.php

Media Updates

These are unlikely to be of interest to most people.

MusicBrainz Picard 2.1.3 resolves several bugs. This is not a security update.
https://picard.musicbrainz.org/

Game Updates

These are unlikely to be of interest to most people.

EA Origin 10.5.32.22222 improves the GUI and resolves several bugs. This is not a security update.
https://www.origin.com/en-us/download

Steam 2018.02.19 resolves several bugs. This is not a security update.

PlayStation PS3 4.84 improves performance. This is not a security update.
https://www.playstation.com/en-us/support/system-updates/ps3/

PlayStation PS4 6.50 adds Remote Play support for iOS. This is not a security update.
https://www.playstation.com/en-us/support/system-updates/ps4/

Office Updates

One or more of these are likely to be of interest to most people.

Scribus 1.4.8 resolves several bugs. This is not a security update.
https://www.scribus.net/

LibreOffice Fresh 6.2.1 resolves over 170 bugs. This is not a security update.
https://www.libreoffice.org/

Notepad++ 7.6.4 resolves several bugs. This build also adds horizontal scrolling (yay!). This is not a security update.
https://12pd.com/click?npp

Adobe Reader DC 19.010.20098 is a security update. Use Help, Check for Updates to get the most current version.

Photoshop CC 19.1.8 and Photoshop CC 20.0.4 are security updates.
https://helpx.adobe.com/security/products/photoshop/apsb19-15.html

Adobe Digital Editions 4.5.10.186048 is a security update.
https://helpx.adobe.com/security/products/Digital-Editions/apsb19-16.html

Security Software Updates

One or more of these is likely to be of interest to most people.

OpenSSL 1.0.2r is a security update.
https://indy.fulgan.com/SSL/

DNSQuerySniffer 1.75 adds wildcard support in the host name filter. This is not a security update.
https://www.nirsoft.net/utils/dns_query_sniffer.html

Avast! Home Edition 19.3.2369 adds UEFI scanning, separates VPN product, and resolves several bugs. This is not a security update.
https://www.avast.com/free-antivirus-download

Wireshark 3.0.0 is a major update adding several new features, switching to npcap, and resolves several bugs. This is not a security update.
https://www.wireshark.org/

RogueKiller 13.1.8 resolves several bugs. This is not a security update.
https://www.adlice.com/softwares/roguekiller/

Capture Updates

These are unlikely to be of interest to most people.

SnagIt 2019.1.1 resolves over a dozen bugs. This is a security update.
https://12pd.com/click?snagit

Converter Updates

These are unlikely to be of interest to most people.

CDex 2.15 resolves several bugs. This is not a security update.
https://cdex.mu/?q=download

DVDFab 11.0.1.8 adds support for new encodings, resolves several bugs. This is not a security update.
https://www.dvdfab.cn/download.htm

MakeMKV 1.14.3 adds support for new encodings and resolves several bugs. This is not a security update.
https://12pd.com/click?makemkv

Utility Updates

These are unlikely to be of interest to most people.

NTLite 1.7.3.6761 adds support for newer builds, new components, and resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

1Password for Mac 7.2.5 resolves several bugs. This is a security update.
https://1password.com/downloads/mac/

7-Zip 19.00 resolves several bugs and improves encryption strength. This is not a security update.
https://www.7-zip.org/

Autoruns 13.94 resolves a bug. This should be treated as a security update.
https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns

Sysmon 9.0 introduces rule groups that enable the specification of AND or OR matching logic across a set of rules. This is a security update.
https://live.sysinternals.com/

BulkFileChanger 1.60 adds EXIF timestamp changing support. This is not a security update.
https://www.nirsoft.net/utils/bulk_file_changer.html

Carbonite 6.3.4 excludes OneDrive Files On-Demand and improves GUI messaging. This is not a security update.
https://account.carbonite.com/

CintaNotes 3.13 adds new actions to rules, resolves several bugs. This is not a security update.
https://cintanotes.com/download

ControlMyMonitor 1.12 adds option to disable header line in exports. This is not a security update.
https://www.nirsoft.net/utils/control_my_monitor.html

Cygwin 3.0.3 resolves several bugs. This is not a security update.
https://cygwin.com/

DesktopOK 6.11 resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

Everything 1.4.1.935 fixes bugs with long file names and exclusions. This is not a security update.
https://www.voidtools.com/

GoodSync 10.9.26 resolves several bugs. This is not a security update.
https://12pd.com/click?goodsync

ImageUSB 1.4.1002 resolves bitlocker detection bug. This is not a security update.
https://www.osforensics.com/tools/write-usb-images.html

NetworkTrafficView 2.20 adds port filtering, Always On Top, and option to disable header line in exports. This is not a security update.
https://www.nirsoft.net/utils/network_traffic_view.html

PointerStick 3.44 improves cosmetics. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

RoboForm 8.5.7 resolves several bugs. This is a security update.
https://12pd.com/click?rf

Seagate DiscWizard 23.0.17160 doesn’t provide a changelog so should be treated as a security update.
https://www.seagate.com/support/downloads/item/discwizard-master-dl/

WSUS Offline 11.6 resolves several bugs, corrects superseded updates, and adds new hooks. This is not a security update.
http://download.wsusoffline.net/

Developer Updates

These are unlikely to be of interest to most people.

Node.js 11.11.0 resolves dozens of bugs. This is a security update.
https://nodejs.org/en/

SQLite 3.27.2 resolves several bugs. This is not a security update.
https://www.sqlite.org/download.html

DB Browser for SQLite 3.11.1 resolves several bugs. This should be treated as a security update.
https://sqlitebrowser.org/

Web Package Updates

These are likely to be of interest only to web developers.

TinyMCE 5.0.2 resolves several bugs. This is not a security update.
https://www.tiny.cloud/get-tiny/

Drupal 8.6.10 is a security update.
https://drupal.org/download

Joomla 3.9.4 is a security update.
https://www.joomla.org/

Nextcloud Server 15.0.5 is a security update.
https://nextcloud.com/

ColdFusion 2018 Update 3, ColdFusion 2016 Update 10, and ColdFusion 11 Update 18 are security updates.
https://helpx.adobe.com/security/products/coldfusion/apsb19-14.html

WordPress 5.1 resolves several bugs, improves the block editor, and adds Site Health. This is not a security update.
https://wordpress.org/

BuddyPress 4.2.0 is a security update.

Multisite Enhancements 1.5.1 resolves several bugs. This is not a security update.

Postie 1.9.32 resolves several bugs. This is not a security update.

Simple Lightbox 2.7.1 improves block editor compatibility. This is not a security update.

Sucuri Security 1.8.20 resolves several bugs. This is not a security update.

Theme My Login 7.0.13 adds several filters and action hooks, improves reliability and form-field controls. This is not a security update.

WooCommerce 3.5.6 resolves dozens of bugs. This is not a security update.

WPtouch 4.3.35 resolves the sms link stripping bug. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/