Updates 2020-03-24

Hi, Folks!

It’s not Patch Tuesday, but security updates from Apple, Adobe, Google, and many others have triggered an out-of-cycle update.

This Month/Week in Technology

NPM is joining Github. Cool.

Apple was fined $1.2 billion by French antitrust authorities. And you thought the next iPhone was going to be expensive yesterday? They’ll be rolling the expense of the antitrust settlement into your next iDevice.

Security is all about trust. The thing to remember is that just because something claims to be a security application or service doesn’t mean it is. Antivirus and VPNs are no exception. By the way, if you’re still using Avast, you may as well just send your passwords out to random email addresses along with all your other personal data.

Content Delivery Networks (CDNs) are critical for scalable web distribution. Unfortunately, this makes them prime targets for malware distribution as well.

Salesforce customers will soon no longer be able to use Data Backup Recovery. Consider this a reminder that while the cloud might store everything, it’s not always easy to get it back when you’ve lost it.

The US Department of Defense is glacially slow (8+ years) at fixing security issues. Don’t say you weren’t warned. In their wisdom, the FBI says you shouldn’t save your passwords in your browser. Duh.

Even if you don’t, however, your data is stored by most other entities you interact with. For example, every 10 years the US performs the Census and collects a wide variety of information about every household in the country. When the US Census Bureau data is hacked you can find that data online, too. But that’s not even the worst of what’s wrong with the Census this year. Their website uses a script that performs a unique fingerprint of every single device that connects to their site and attempts to load various sensor features to further profile and access features of the device. Coupled with the “unique” login you use when filling out the Census your online activity can be permanently tied to your devices. And yes, this is the same organization that had a major data leak earlier in this paragraph.

The Internet of Things (IoT) is much less secure than you may have thought, no matter how bad you thought it was. 98% of their traffic is sent unencrypted, more than half of devices suffer from critical vulnerabilities that will likely never be patched, IoT devices are often used as a foothold to gain access to your internal networks, and hospitals are some of the worst offenders for employing insecure and unmaintained IoT devices.

Is it any wonder that the Russian FSB was developing an IoT botnet? Another FSB contractor was hacked and their tools were released in much the same way as the CIA Vault7 hack.

Now for the good news:

Comcast has made their public Wi-Fi hotspots available free to everyone and has removed data caps for the next 60 days as a result of the current pandemic. Just make sure you’re using a VPN. 🙂

Let’s Get Busy

Apple released updates for macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra, Xcode 11.4, Safari 13.1, watchOS 6.2, watchOS 5.3.6, tvOS 13.4, iOS 13.4, iPadOS 13.4, iOS 12.4.6, and iTunes 12.10.5 for Windows. These are security updates. Use the Apple App Store or Apple Software Update to install the most current versions.

iOS 13.4 and 12.4.6 are security updates. Use Settings, General, Software Update to install the most current version.

watchOS 6.2 and 5.3.6 are security updates. Use your updated iPhone to install the most current version through the Watch app.
https://support.apple.com/en-us/HT204641

tvOS 13.4 is a security update. Use Settings, General, Updates to install the most current version.

Adobe Flash Player 32.0.0.344 is a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

nVidia 442.75 resolves several compatibility issues and adds app/game profiles. This is not a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Browser Updates

One or more of these are likely to be of interest to everyone.

Brave 1.5.113 is a security update. Use Menu, Help, About to install the most current version.
https://brave.com/

Google Chrome 80.0.3987.149 is a security update. Use Menu, Help, About to install the most current version.

Vivaldi 2.11.1811.49 is a security update. Use Menu, Help, About to install the most current version.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 68.6.0 is a security update. Use Menu, Help, About to install the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

BrowsingHistoryView 2.40 adds a new date/time filter. This is not a security update.
https://www.nirsoft.net/utils/browsing_history_view.html

FileZilla Client 3.47.2.1 resolves several bugs. This is not a security update.
https://filezilla-project.org/

FreeFileSync 10.22 resolves several bugs. This is not a security update.
https://www.freefilesync.org/download.php

Npcap 0.9989 resolves several bugs. This should be treated as a security update.
https://nmap.org/npcap/

Prosody 0.11.5 adds foreground/background flags to replace daemon functionality. This is not a security update.
https://prosody.im/download/start

Media Updates

These are unlikely to be of interest to most people.

iTunes 12.10.5 is a security update. Use Apple Software Update to install the most current version.

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Reader DC 20.006.20042 is a security update. Use Help, Check for Updates to install the most current version.

Adobe Creative Cloud Desktop?5.1 is a security update.
https://www.adobe.com/creativecloud/catalog/desktop.html

Adobe Bridge 10.0.3 is a security update.
https://www.adobe.com/products/bridge.html

Adobe ColdFusion 2016.14 and 2018.8 are security updates.
https://helpx.adobe.com/coldfusion/kb/coldfusion-2016-update-14.html
https://helpx.adobe.com/coldfusion/kb/coldfusion-2018-update-8.html

Adobe Experience Manager 6.3.3.8, 6.4.8.0, and 6.5.4.0 are security updates.
https://helpx.adobe.com/experience-manager/aem-releases-updates.html

Adobe Photoshop 20.0.9 and 21.1.1 are security updates. Use Adobe Creative Cloud Desktop to install the most current versions (after you patch it).

Adobe Acrobat 2020.006.20042, 2017.011.30166, and 2015.006.30518 are security updates. Use Adobe Creative Cloud Desktop to install the most current versions (after you patch it).

Adobe Genuine Integrity Service 6.6 is a security update. AdobeGCClient does not have a separate installer or updater, and will update as you patch other programs.

Atom 1.45.0 resolves several bugs and updates libraries. This should be treated as a security update.
https://atom.io/

LibreOffice Fresh 6.4.2 resolves over 90 bugs. This is a security update. LibreOffice Fresh is a beta version, and should be avoided for most users.
https://www.libreoffice.org/

Security Software Updates

One or more of these is likely to be of interest to most people.

RogueKiller 14.3.0 updates libraries, improves reliability and scanning behaviors. This is a security update.
https://www.adlice.com/download/roguekiller/

Capture Updates

These are unlikely to be of interest to most people.

ScreenToGif 2.22.1 resolves a couple bugs and updates translations. This is not a security update.
https://github.com/NickeManarin/ScreenToGif/releases/latest

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 11.0.8.1 adds support for new encodings, improves compatibility, and resolves a couple bugs. This is not a security update.
https://www.dvdfab.cn/download.htm

Utility Updates

These are unlikely to be of interest to most people.

1Password for Windows 7.4.759 resolves several bugs and improves compatibility. This is not a security update.
https://1password.com/downloads/windows/

CurrPorts 2.61 resolves a state-monitoring bug. This is not a security update.
https://www.nirsoft.net/utils/cports.html

Etcher 1.5.80 resolves several bugs and updates electron. This should be treated as a security update.
https://www.balena.io/etcher/

Everything 1.4.1.969 improves stability. This is not a security update.
https://www.voidtools.com/

Fing 9.0.0 adds several new feature shortcuts and an Account tab. This is not a security update.
https://community.fing.com/

GoodSync 10.11.2 resolves several bugs. This is not a security update.
https://12pd.com/click?goodsync

IsMyHdOK 2.11 updates language packs and resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

TeamViewer 15.4.4445 resolves several bugs and adds the tvopt file format for setting portability. This is not a security update.
https://www.teamviewer.com/en/download/windows/

WSUS Offline 12.0 removes support for Windows 7, Windows Server 2008 R2, Win10 v1703, splits Win10 updates to versioned folders for future updates, and updates supercedence values. This is not a security update.
https://download.wsusoffline.net/

Developer Updates

These are unlikely to be of interest to most people.

Inno Setup 6.0.4 improves compatibility, Restart Manager, and RTF, adds Dark Theme, several fixes and HTTPS on the website. This is not a security update.
https://www.jrsoftware.org/isdl.php

Node.js 13.11.0 updates libraries, improves compatibility, and resolves several bugs. This is not a security update.
https://nodejs.org/en/

StrawberryPerl 5.30.2.1 updates libraries, improves compatibility, and resolves several bugs. This is a security update. You probably shouldn’t be using StrawberryPerl though, since they still aren’t using HTTPS even though they can get it free through LetsEncrypt. Sad.
http://strawberryperl.com/

Web Package Updates

These are likely to be of interest only to web developers.

Drupal 8.8.4 is a security update.
https://drupal.org/download

HumHub 1.4.4 resolves several bugs. This is not a security update.
https://www.humhub.com/en/download

phpMyAdmin 4.9.5 is a security update.
https://www.phpmyadmin.net/

Nextcloud Server 18.0.3 is a security update.
https://nextcloud.com/

phpList 3.5.1 updates libraries and resolves several bugs. This is a security update.
https://www.phplist.org/

Connectwise Control 20.2.27450.7387 resolves several bugs. This is not a security update.
https://www.connectwise.com/software/control/download

Akismet 4.1.4 improves compatibility and activation process. This is not a security update.

Custom Facebook Feed 2.12.4 improves compatibility and resolves several bugs. This is not a security update.

myStickymenu 2.3.8 improves compatibility, reduces announcement nag frequency, and allows custom HTML within notification bar. This is not a security update.

Postie 1.9.44 refactors code for separation of purpose and adds an action for registering shortcodes.

Redirection 4.7.1 resolves several bugs. This is not a security update.

WooCommerce 4.0.1 improves Action Scheduler and resolves several bugs. This is not a security update.

WP Mail SMTP 1.9.0 adds several troubleshooting features, improves documentation, About, and warns when settings are not saved. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2020-03-10

Welcome back, Folks!

Today is Patch Tuesday for March 2020.

The next build of Windows 10 is just around the corner. If you don’t want to be the guinea pig I strongly suggest you update to v1909 within the next month. This will grant you a reprieve from the new version for a couple months. Let everyone else beta test and you can upgrade when they’ve worked out the bugs.

Windows 7 is still end-of-life (EOL). If you’re still running it, shame on you, and if you are running a licensed version of Windows 7 or 8 you can still upgrade to Windows 10 and have a supported version of Windows for the foreseeable future. Don’t want to do it yourself? Call me!
https://saferpc.info/contact/

This Month Week in Technology

In 2019, Android reportedly had the most vulnerabilities of any OS, but in its defense, there are literally dozens of manufacturers that build on Android and many of the issues stem from these third-parties. Also, if you’re running Android, you really should also be using SnoopSnitch which can identify whether security updates have been applied to your device or if it’s been abandoned by the vendor.

Movies like Eagle Eye demonstrated how easy it was for a malicious actor to observe your mobile remotely, but if you have a smart assistant enabled (such as Alexa, Siri, Google Assistant, Cortana) then it is possible to remotely control it using audio signals that are beyond the range of human hearing.

There’s more evidence than ever that selling your Intellectual Property to a third party puts your users at risk. It’s very common in browser extensions and website plugins. It doesn’t matter how secure the core engine is if the user installs a malicious or defective extension/plugin. There’s always a line, though, right? Facebook is actually suing an SDK maker for harvesting the data that…Facebook collected.

Netgear has issued security patches for almost 50 router models. If you use Wi-Fi then, by it’s very nature, you’re susceptible to being tracked. The protocol itself is your enemy since it requires that it transmit all your “known” networks on a regular basis during a heartbeat connection status report. Even if you disable Wi-Fi everywhere except trusted locations, those trusted locations can be still be compromised due to weak security in the on-device encryption key. Intel and AMD CPUs for nearly a decade have had significant flaws that allow data exfiltration by unprivileged users.

More than a million enterprise Microsoft accounts have been compromised, primarily through password reuse. Guys, NEVER reuse passwords! Defense contractors getting hacked isn’t really anything new, but you’d think they had better backups so they wouldn’t have to pay half-million dollar ransoms.

Malware authors evade detection in many ways. One of the most common diagnostic tests for malicious software is to run it within a virtual machine. As expected, developers can detect and disable their malware within these environments. The Malware Evasion Encyclopedia provides advice to educate researchers to keep one step ahead of the malware.

.NET Core 3.0 is dead. Long live .NET Core! Oh, and switching to 3.1 is easy.

I’ll end my soapbox on a happy note:

A new Wi-Fi chip design for IoT devices consumes only 1/5000th of the energy of current models. Wow!

Let’s Get Busy

Now back to our regularly scheduled program. Thanks to the monster of updates pushed during “weekly update February”, Patch Tuesday this month is pretty light. The typical computer should see roughly 1.1 GB in updates today. Let’s get started.

Microsoft released updates for Windows, Internet Explorer, Servicing Stack, and MSRT (~600 MB). This includes security updates. A reboot is required.

Google Chrome OS 80.0.3987.137 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Catalina (10.15) means that macOS Sierra (10.12) and older are no longer supported. If you can not install at least macOS High Sierra (10.13) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (1909) is a pretty small update so will install quickly. Windows 10 pushes you to get the latest Windows 10 release every 6 months. If you don’t let it finish and you’re on a slow connection, this process kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

BullZip PDF Printer 11.13.0.2823 resolves an SFTP bug. This is not a security update.
https://www.bullzip.com/products/pdf/info.php#download

Intel Driver and Support Assistant 20.2.9 resolves several bugs. This is not a security update.
https://www.intel.com/p/en_US/support/detect

nVidia 442.59 adds support for new hardware and resolves several bugs. This is not a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Logitech Options 8.10.154 adds support for newer hardware and resolves several bugs. This is not a security update.
https://www.logitech.com/en-us/product/options

Browser Updates

One or more of these are likely to be of interest to everyone.

Google Chrome 80.0.3987.132 is a security update. Use Menu, Help, About to install the most current version.

Firefox 74.0 is a security update. Use Menu, Help, About to install the most current version.

Firefox ESR 68.6.0 is a security update. Use Menu, Help, About to install the most current version.

Vivaldi 2.11.1811.47 is a security update. Use Menu, Help, About to install the most current version.
https://vivaldi.com/

Internet Updates

One or more of these are likely to be of interest to everyone.

WinSCP 5.17.2 resolves several bugs and disables TLS 1.3 by default. This is not a security update.
https://winscp.net/eng/index.php

Npcap 0.9988 resolves several bugs. This is not a security update.
https://nmap.org/npcap/

Office Updates

One or more of these are likely to be of interest to most people.

Notepad++ 7.8.5 resolves several bugs. This is not a security update.
https://notepad-plus-plus.org/

Nextcloud Desktop 2.6.4 resolves several bugs. This is not a security update.
https://nextcloud.com/

Security Software Updates

One or more of these is likely to be of interest to most people.

NSudo 8.0 resolves several bugs, improves reliability, and reduces file size. This is not a security update.
https://github.com/M2Team/NSudo/releases/latest

TinyWall 2.1.15 now offers the upgrade to 3.0.0 on 64-bit systems. 3.0.0 is in beta and provides user interface, performance, stability and reliability improvements. It is, however, beta software, so should be avoided until it is stable.
https://tinywall.pados.hu/

uBlock Origin 1.25.2 resolves several bugs and improves GUI. This is not a security update.
https://github.com/gorhill/uBlock/releases/latest

Capture Updates

These are unlikely to be of interest to most people.

ScreenToGif 2.22 resolves several bugs and improves automatic update. This is not a security update.
https://github.com/NickeManarin/ScreenToGif/releases/latest

SnagIt 2020.1.1 adds SharePoint sharing, and resolves several bugs. This is a security update.
https://download.techsmith.com/snagit/enu/snagit.exe

Converter Updates

These are unlikely to be of interest to most people.

MakeMKV 1.15.0 updates the user interface, adds new preferences for LibMMBD integration, and improves reliability. This is not a security update.
https://www.makemkv.com/download/

MKVToolnix 44.0.0 adds attachment drag and drop, improves reliability, and resolves several bugs. This is not a security update.
https://www.fosshub.com/MKVToolNix.html

DVDFab 11.0.7.7 adds support for new encodings, new profiles, and adds BluPath feature. This is not a security update.
https://www.dvdfab.cn/download.htm

Utility Updates

These are unlikely to be of interest to most people.

1Password for Windows 7.4.750 adds several new features, including Windows Hello support, rewritten interface engine, improved display support, and over 80 fixes and improvements. This is not a security update.
https://1password.com/downloads/windows/

Beyond Compare 4.3.4.24657 updates libraries, resolves several bugs, and improves compatibility. This is not a security update.
https://www.scootersoftware.com/download.php?zz=dl4

Bitcoin 0.19.1 resolves several bugs. This is not a security update.
https://bitcoin.org/en/download

DesktopOK 6.88 updates the language file. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

DMDE 3.6.1.773 adds support for 64-bit macOS. This is not a security update.
https://dmde.com/

Everything 1.4.1.965 resolves several bugs. This is not a security update.
https://www.voidtools.com/

Fing 8.9.0 resolves several bugs and integrates a database of supported devices (Fingpedia), this is not a security update.
https://community.fing.com/

GoodSync 10.10.26 improves compatibility and status reporting. This is not a security update.
https://12pd.com/click?goodsync

Rufus 3.9 resolves several bugs and improves compatibility. This is not a security update.
https://rufus.ie/en_IE.html

TeamViewer 15.3.8497 resolves compatibility bug with hash authentication, but disables hash auth for settings. This is not a security update.
https://www.teamviewer.com/en/download/windows/

WSUS Offline 11.9 is the last version to support Windows 7, updates supersedence URLs, and resolves several bugs. This is not a security update.
https://download.wsusoffline.net/

Developer Updates

These are unlikely to be of interest to most people.

Android Studio 3.6.1.0 resolves several bugs. This is not a security update.
https://developer.android.com/studio/index.html

Godot 3.2.1 resolves several bugs. This is not a security update.
https://godotengine.org/

Node.js 13.10.1 resolves several bugs. This is not a security update.
https://nodejs.org/en/

TortoiseGit 2.10.0 updates libraries and resolves several bugs. This is not a security update.
https://tortoisegit.org/

Visual Studio Code 1.43 adds a search editor, shangle controls, minimap improvements, column selection, and more. This is not a security update.
https://code.visualstudio.com/

Web Package Updates

These are likely to be of interest only to web developers.

Joomla 3.9.16 is a security update.
https://www.joomla.org/

Drupal 8.8.3 resolves over 50 bugs and updates libraries. This is not a security update.
https://drupal.org/download

HumHub 1.4.3 resolves several bugs. This is not a security update.
https://www.humhub.com/en/download

ScreenConnect 20.1.27036.7360 resolves several bugs. This is not a security update.
https://www.connectwise.com/software/control/download

Contact Form 7 5.1.7 adds LTR support and adds a cosmetic change to warning. This is not a security update.

Email Log 2.3.2 improves compatibility, user interface, and resolves a couple bugs. This is not a security update.

Simple Lightbox 2.8.1 improves compatibility. This is not a security update.

NextScripts Social Networks Auto-Poster 4.3.13 resolves several bugs and improves compatibility. This is not a security update.

WooCommerce 4.0.0 is a major update adding over 70 changes and fixes, updated libraries, and feature improvements. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2019-12-10

Merry Christmas, Folks!

Today is Patch Tuesday for December 2019.

Note: shortly after publishing, Google released Chrome 79.0.3945.79.

Windows 10, version 1909, is available. This version is minor compared to previous Windows 10 upgrades. Nevertheless, don’t do it yet. There is nothing so critically important in 1909 that the update can’t wait a month. Wait for it.
https://www.microsoft.com/en-us/software-download/windows10

Windows 7 will fall completely out of support in only 35 days. Don’t run out the clock. If you are running a licensed version of Windows 7 or 8 you can still upgrade to Windows 10 and have a supported version of Windows for the foreseeable future. Get it done before it’s too late. Don’t want to do it yourself? Call me!

There is a lot of talk right now about enabling POSready mode to gain additional time for Windows 7. This *does* work, but I recommend against it. POSready mode is designed to allow existing third-party software to continue to operate in the Windows 7 ecosystem, but Microsoft and most third-party developers will stop support when Windows 7 is end-of-life (EOL). This means that while your OS itself will continue to receive security updates, most other apps will not. If your device is used as a typical PC this means your risk will still significantly increase by relying on POSready with unmaintainable third-party applications.

Christmas is only a couple weeks away which means it’s that time of year when the best and worst of humanity is exposed. This time of year brings stress and urgency to everything, and that means people are more likely to be targeted for common phishing schemes, malicious attachments (invoices and holiday letters), end-of-year insurance scams, and advance fee fraud. You’ll be targeted by phone and email and the deluge won’t subside until mid-to-late January. Don’t be afraid to hang up and delete. It really is better to be safe than sorry.

If you’ve read more than a couple of my newsletters you’ve seen me hate on Avast regularly. Last week I was actually considering easing off and giving them another chance. Then I received diet spam FROM AVAST BUSINESS! I’ve reconsidered. If you’re using any of this software you should remove it immediately. Avast can’t be trusted. Having any of their software installed significantly increases the risk to your devices, and should be treated as a malware infection as far as I’m concerned.

Now back to our regularly scheduled program. The typical computer should see roughly 2 GB in updates today. Let’s get started.

Microsoft released updates for Windows, Internet Explorer, .NET, Servicing Stack, hardware drivers, and MSRT (~1 GB). This includes security updates. A reboot is required.

Apple released updates for macOS Catalina 10.15.2, Mojave Security Update 2019-002, and High Sierra Security Update 2019-007, iOS 13.3, iOS 12.4.4, iPadOS 13.3, Safari 13.0.4, Xcode 11.3, watchOS 5.3.4, watchOS 6.1.1, and tvOS 13.3. These are security updates. Use Apple Software Update to install the most current versions.

watchOS 6.1.1 and watchOS 5.3.4 are security updates. Use the Watch app on your iPhone to install the most current version.

tvOS 13.3 is a security update. Use System, Software Update to install the most current version.

macOS Catalina (10.15) is available. If you don’t have to, don’t install it. Mojave (10.14) will be supported for almost 2 more years.

iOS 13.3, iOS 12.4.4, and iPadOS 13.3 are security updates. Use Settings, General, Software Update to install the most current update.

Google Chrome OS 78.0.3904.106 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Adobe Flash Player 32.0.0.303 is a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Catalina (10.15) means that macOS Sierra (10.12) and older are no longer supported. If you can not install at least macOS High Sierra (10.13) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (1909) is a pretty small update so will install quickly. Windows 10 pushes you to get the latest Windows 10 release every 6 months. If you don’t let it finish and you’re on a slow connection, this process kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

BullZip PDF Printer 11.11.0.2804 adds High-DPI support, printing page range, and copy+paste support for UTF16 characters. This is not a security update.
https://www.bullzip.com/products/pdf/info.php#download

Display Driver Uninstaller 18.0.2.0 improves Nvidia cleanup.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

Dymo Label 8.7.3 doesn’t provide a changelog, so should be treated as a security update.
https://www.dymo.com/en-US/online-support/dymo-user-guides

MS Mouse and Keyboard Center 20191127 adds support for newer hardware. This is not a security update.
https://www.microsoft.com/accessories/en-us/downloads/mouse-keyboard-center

Nvidia 441.66 adds image sharpening for Vulkan and OpenGL, support for newer hardware, and multiple security fixes. This is a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Browser Updates

One or more of these are likely to be of interest to everyone.

Google Chrome 79.0.3945.79 is a security update. Use Menu, Help, About to get the most current version.

Firefox 71.0 is a security update. Use Menu, Help, About to get the most current version.

Firefox ESR 68.3.0 is a security update. Use Menu, Help, About to get the most current version.

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 68.3.0 is a security update. Use Menu, Help, About to get the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

BrowsingHistoryView 2.30 adds History File and Record ID columns. This is not a security update.
https://www.nirsoft.net/utils/browsing_history_view.html

FileZilla Client 3.46.0 resolves a crash, and updates dependencies. This is a security update.
https://filezilla-project.org/

FreeFileSync 10.18 adds parallel processing, grid sort, filter counts, improved responsiveness and bug fixes. This is not a security update.
https://www.freefilesync.org/download.php

MaxMind GeoIP2 201912 is a data refresh.
https://dev.maxmind.com/geoip/

WinSCP 5.15.9 is a security update.
https://winscp.net/eng/index.php

Media Updates

These are unlikely to be of interest to most people.

CDBurnerXP 4.5.8.7128 improves error handling. This should be treated as a security update.
https://cdburnerxp.se/

Game Updates

These are unlikely to be of interest to most people.

Steam 2019.12.05 resolves several bugs, returns Small Mode, updates libraries, and adds GUI improvements. This should be treated as a security update.

Office Updates

One or more of these are likely to be of interest to most people.

Adobe Acrobat DC 19.021.20058 is a security update. Use Menu, Help, Check for updates to get the most current version.

Adobe Reader DC 19.021.20058 is a security update. Use Menu, Help, Check for updates to get the most current version.

Adobe Photoshop CC 20.0.8 and 21.0.2 are security updates. Use Adobe Creative Cloud to install the most current version.

Artweaver 7.0.3 resolves several bugs. This is not a security update.
https://www.artweaver.de/

Krita 4.2.8 improves disk write reliability, and resolves several bugs. This is not a security update.
https://krita.org/en/download/krita-desktop/

Notepad++ 7.8.2 resolves several bugs and returns the hotkeys to the save prompt. This is not a security update.
https://12pd.com/click?npp

Paint.net 4.2.8 updates libraries, improves performance, resolves several bugs, and adds self-repair with /repair. This should be treated as a security update.
https://www.getpaint.net/

Security Software Updates

One or more of these is likely to be of interest to most people.

Caine 11.0 adds several new features and apps, updates libraries, and updates core. This is a security update.
https://www.caine-live.net/

HTTP Toolkit 0.1.17 doesn’t provide a changelog so should be treated as a security update.
https://httptoolkit.tech/

RogueKiller 14.0.0.16 updates core engine, resolves several bugs, adds real time protection and documents protection. This should be treated as a security update.
https://www.adlice.com/softwares/roguekiller/

Capture Updates

These are unlikely to be of interest to most people.

SnagIt 2020.0.3 resolves an Editor launch bug. This is not a security update.
https://download.techsmith.com/snagit/enu/snagit.exe

Converter Updates

These are unlikely to be of interest to most people.

MKVToolnix 41.0.0 adds many new features, improves meta storage, resolves several bugs. This is not a security update.
https://www.fosshub.com/MKVToolNix.html

DVDFab 11.0.6.4 adds support for new encodings, new hardware, adds Enlarger AI and resolves several bugs. This is not a security update.
https://www.dvdfab.cn/download.htm

MakeMKV 1.14.7 adds support for new encodings, resolves a file name variable expansion bug. This is not a security update.
https://12pd.com/click?makemkv

Utility Updates

These are unlikely to be of interest to most people.

Beyond Compare 4.3.3.24545 resolves several bugs. This is not a security update.
https://www.scootersoftware.com/download.php?zz=dl4

Bitcoin 0.19.0.1 integrates a tool to analyze and reduce memory consumption, adds and updates many RPC functions. This is not a security update.
https://bitcoin.org/en/download

CPU-Z Installer 1.91 adds support for newer hardware. This is not a security update.
https://www.cpuid.com/softwares/cpu-z.html

Dell Command Update 3.1 adds CLI support, automatic suspension of BitLocker for BIOS updates, enhances return codes for CLI, update scheduling, and resolves several bugs. This is not a security update.
https://www.dell.com/support/article/us/en/04/sln311129/dell-command-update?lang=en

DesktopOK 6.79 resolves a false AV alert. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

DevManView 1.65 adds shortcut creation, and adds option to start remote registry service for automation. This is not a security update.
https://www.nirsoft.net/utils/device_manager_view.html

Drive Snapshot 1.48 adds support for newer OSes, resolves encryption bugs. This is a security update.
http://www.drivesnapshot.de/en/

Etcher 1.5.69 updates libraries, resolves several bugs, and improves compatibility. This is not a security update.
https://www.balena.io/etcher/

GoodSync 10.10.15 resolves several bugs, improves and weakens security options (yes, really). This version should be avoided until they get their stuff together.
https://www.goodsync.com/

Homedale 1.86 improves the dot-chart. This is not a security update.
https://www.the-sz.com/products/homedale/

MS ISO Downloader 8.24 adds support for new media. This is not a security update.
https://www.heidoc.net/joomla/technology-science/microsoft/67-microsoft-windows-and-office-iso-download-tool

NTLite 1.8.0.7240 adds several options for new features, resolves bugs. This is not a security update.
https://www.ntlite.com/download/

OSForensics 7.1.1002 resolves several bugs and improves reliability. This should be treated as a security update.
http://www.osforensics.com/download.html

Password Security Scanner 1.50 adds support for Windows Credentials passwords, and resolves a couple bugs. This is not a security update.
https://www.nirsoft.net/utils/password_security_scanner.html

RoboForm 8.6.5 resolves an upgrade data conversion bug, improves experience when changing Master password, improves login from RF behavior, and resolves several other bugs. This is not a security update.
https://12pd.com/click?rf

SearchMyFiles 3.07 resolves a bug. This is not a security update.
https://www.nirsoft.net/utils/search_my_files.html

TraceRouteOK 1.61 adds window position saving, resolves several bugs. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/TraceRouteOK

USBDeview 2.85 adds option to create shortcuts. This is not a security update.
https://www.nirsoft.net/utils/usb_devices_view.html

WinScan2PDF 5.11 improves WIA reliability, performance. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WirelessKeyView 2.11 improves output formatting and adds explore from here option. This is not a security update. Note that downloads are not password protected. This is not a security update.
https://www.nirsoft.net/utils/wireless_key.html

WSUS Offline 11.8.3 updates supercedence list, resolves several bugs. This is not a security update.
http://download.wsusoffline.net/

Developer Updates

These are unlikely to be of interest to most people.

AutoHotkey 1.1.32.00 resolves several bugs, adds InputHook OnKeyUp callback, adds support for PixelSearch in fast mode. This is not a security update.
https://www.autohotkey.com/download/

Android Studio 3.5.3.0 improves stability and performance, resolves several bugs. This is not a security update.
https://developer.android.com/studio/index.html

Godot 3.1.2 resolves over 400 bugs. This is a security update.
https://godotengine.org/

Node.js 13.3.0 resolves several bugs, and updates libraries. This should be treated as a security update.
https://nodejs.org/en/

StrawberryPerl 5.30.1.1 updates core to 5.30.1 and updates libraries. This is not a security update.
http://strawberryperl.com/

Web Package Updates

These are likely to be of interest only to web developers.

Drupal 8.8.0 makes several feature-level and requirements changes (recommended PHP is now 7.2+), removes several features and modules, updates libraries, and improves code consistency. This should be treated as a security update.
https://drupal.org/download

Brackets 1.14.1 is a security update.
http://brackets.io/

MailEnable 10.28 resolves several bugs, and adds recurring tasks and custom special folders. This is not a security update.
https://www.mailenable.com/

phpMyAdmin 4.9.2 resolves several bugs and improves compatibility. This is a security update.
https://www.phpmyadmin.net/

ScreenConnect 19.5.26030.7282 improves server compatibility. This is not a security update.
https://www.connectwise.com/software/control/download

ColdFusion 2018 Update 7 is a security update.
https://helpx.adobe.com/coldfusion/kb/coldfusion-2018-update-7.html

bbPress 2.6.2 resolves several bugs. This is not a security update.

BuddyPress 5.1.0 resolves several bugs. This is not a security update.

Contact Form 7 5.1.6 resolves an incompatible CSS bug. This is not a security update.

Custom Facebook Feed 2.12.2 resolves a bug. This is not a security update.

FV Top Level Categories 1.9.1 improves compatibility. This is not a security update.

Multisite Enhancements 1.5.2 resolves several bugs. This is not a security update.

Redirection 4.5.1 resolves broken canonical redirects. This is not a security update.

NextScripts Social Networks Auto-Poster 4.3.11 adds WordPress 5.3 support, resolves several bugs. This is not a security update.

Sucuri Security 1.8.22 adds several new checks. This is not a security update.

W3 Total Cache 0.11.0 resolves several bugs, improves compatibility and performance, and adds lazy loading. This is not a security update.

WooCommerce 3.8.1 resolves several bugs. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

 

Updates 2019-11-12

Hi, Folks!

Today is Patch Tuesday for November 2019 and this month is huge.

The next build of Windows 10, version 1909, is being released this week. This version is minor compared to other Windows 10 upgrades and should be nearly indistinguishable from 1903. If you’re running 1903 now installing 1909 should have no negative impact. If you’re running an older version I recommend upgrading to 1903 before switching to 1909. In either case, don’t do it yet. There is nothing so critically important in 1909 that the update can’t wait a month. Wait for it.

Windows 7 will fall completely out of support in only 60 days. Don’t run out the clock. If you are running a licensed version of Windows 7 or 8 you can still upgrade to Windows 10 and have a supported version of Windows for the foreseeable future. Get it done before it’s too late. Don’t want to do it yourself? Call me!

Catalina has been out for a month now and the backlash is huge. Installation lockups, forced password resets, permission resets, iCloud sync problems, dropped support for 32-bit apps, and incompatibility issues requiring reinstallation or upgrade of many others are just a few of the issues experienced by the unlucky lemmings that Thought Things Would Be Different™. Apple is gradually resolving problems, but I recommend you hold off until at least 10.15.3 before upgrading (and then only if you don’t need any 32-bit apps). x.3 seems to be the sweet spot for macOS stability. That should be out sometime next month. With that said, don’t postpone installing the patches for your current build of macOS. These are always security updates.

In the news this month Google is buying Fitbit (so find another tracker), we’re reminded to always disable NFC, compromising fingerprint readers is still extremely easy, light is as effective as voice, punctuation is still important, iOS 13+’s aggressive memory cleanup is more “abusive” than “aggressive,” and still brokenanything you share with any business or entity will no doubt inevitably be exposed, especially if it’s Adobe, or even your antivirus company, that “user interface design” and “security” are far removed, and that IoT is putting us all further at risk every single day.

The co-founder and CEO of Mine, an online privacy advocacy organization, observes that cybersecurity is becoming less accessible to smaller companies, but that’s why I’m here. Check out our subscription to learn more. Our goal is to provide enterprise-level support to everyone at a cost that is reasonable even for home users.

Now back to our regularly scheduled program. The typical computer should see roughly 2 GB in updates today. Let’s get started.

Microsoft released updates for Windows, Internet Explorer, Servicing Stack, and MSRT (~800 MB). This includes security updates. A reboot is required.

Apple released updates for iOS 13.2.2, iPadOS 13.2.2, macOS Catalina 10.15.1, Security Update 2019-001 Mojave, Security Update 2019-006 High Sierra, tvOS 13.2, watchOS 6.1, Safari 13.0.3, and Xcode 11.2. These are security updates. Use Apple Software Update to install the most current versions.

macOS Catalina (10.15) is available. This is a large download and will take between 2 and 4 hours to install on most hardware. The release of macOS Catalina (10.15) means that macOS Sierra (10.12) is now no longer supported. If you can not install at least macOS High Sierra (10.13) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

iOS 13.2.2 is a security update. Use Settings, General, Software Update to install the most current update.

watchOS 5.3.3 and 6.1 are security updates. Use the Watch app on your iPhone to install the most current version.

tvOS 13.2 is a security update. Use System, Software Update to install the most current version.

Google Chrome OS 78.0.3904.92 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Fedora 31-1.9 is a major update. This version is now released only as a 64-bit release. Though 32-bit apps are still supported the CPU architecture now requires 64-bits. New features include the Fedora Toolbox (an improved launcher), updated packages, improved stability and bug tracking, removal of YUM, improved security, and Cgroups v2 support.

Adobe Flash Player 32.0.0.270 is a security update.
Win: https://12pd.com/click?flash
Win: https://12pd.com/click?flashie
Mac: https://12pd.com/click?flashmac

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Catalina (10.15) means that macOS Sierra (10.12) and older are no longer supported. If you can not install at least macOS High Sierra (10.13) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (1903) will cause your computer to feel unusually slow until it is installed. This is a side-effect of the Windows 10 upgrade cycle, which pushes out 3-6 GB through Windows update to get you to the latest Windows 10 release every 6 months. If you don’t let it finish and you’re on a slow connection, it will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Intel Driver and Support Assistant 19.10.42 improves the installer and resolves several bugs. This is not a security update.
https://www.intel.com/p/en_US/support/detect

Crucial Storage Executive 5.05 doesn’t provide a changelog so should be treated as a security update.
https://www.crucial.com/usa/en/support-storage-executive

nVidia 441.20 resolves several bugs, improves compatibility, and adds support for newer hardware. This is not a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Browser Updates

One or more of these are likely to be of interest to everyone.

Google Chrome 78.0.3904.97 is a security update. Use Menu, Help, About to install the most current version.

Firefox 70.0.1 is a security update. Use Menu, Help, About to install the most current version.

Firefox ESR 68.2.0 is a security update. Use Menu, Help, About to install the most current version.

Vivaldi 2.9.1705.41 is a security update. Use Menu, Help, About to install the most current version.

Email Updates

One or more of these are likely to be of interest to everyone.

Mailspring 1.7.2 resolves several bugs. This is not a security update.
https://getmailspring.com/

Thunderbird 68.2.0 is a security update. Use Menu, Help, About to install the most current version.

OutlookAttachView 3.30 adds option to scan only unread messages and set the read flag on mesages on extraction. This is not a security update.
https://www.nirsoft.net/utils/outlook_attachment.html

Internet Updates

One or more of these are likely to be of interest to everyone.

WinSCP 5.15.5 is a security update.
https://winscp.net/eng/index.php

FreeFileSync 10.17 adds private key support for SFTP and resolves several bugs. This should be treated as a security update.
https://www.freefilesync.org/download.php

Java 8u231 is a security update. You should remove Java instead of upgrading if you are not 110% sure you require it.
https://www.java.com/en/download/manual.jsp

MaxMind GeoIP2 201911 is a data refresh.
http://dev.maxmind.com/geoip/

Npcap 0.9984 is a security update.
https://nmap.org/npcap/

BrowsingHistoryView 2.26 adds the ability to configure what happens on double-clicking an item in the results.
https://www.nirsoft.net/utils/browsing_history_view.html

Media Updates

These are unlikely to be of interest to most people.

iTunes 12.10.2 is a security update.
https://www.apple.com/itunes/download/

Picard 2.2.3 resolves several bugs. This is not a security update.
https://picard.musicbrainz.org/

Game Updates

These are unlikely to be of interest to most people.

Steam 2019.11.06 replaces the Library with a new interface, resolves several bugs, improves stability. This is not a security update.

Office Updates

One or more of these are likely to be of interest to most people.

Atom 1.41.0 updates libraries and resolves several bugs. This should be treated as a security update.
https://atom.io/

LibreOffice Still 6.2.8 resolves several bugs. This is not a security update. This is the stable version of LibreOffice, so if you’re upgrading you should install Still.
https://www.libreoffice.org/

LibreOffice Fresh 6.3.3 resolves many bugs. This is not a security update. This is the beta version of LibreOffice, so if you’re upgrading you should install Still.
https://www.libreoffice.org/

Notepad++ 7.8.1 (Free Uyghur Edition) resolves several bugs. This is not a security update.
https://notepad-plus-plus.org/

Adobe Reader DC 19.021.20049 resolves several bugs. This should be treated as a security update. Use Help, Check for Updates to get the most current version.

Security Software Updates

One or more of these is likely to be of interest to most people.

RogueKiller 13.5.6 resolves several bugs. This is not a security update.
https://www.adlice.com/softwares/roguekiller/

Capture Updates

These are unlikely to be of interest to most people.

SnagIt 2020.0.1 is a security update.
https://download.techsmith.com/snagit/enu/snagit.exe

Converter Updates

These are unlikely to be of interest to most people.

DVDFab 11.0.5.8 adds support for new encodings, adds cloud backup for configuration. This is not a security update.
https://www.dvdfab.cn/download.htm

MKVToolnix 40.0.0 resolves several bugs and improves automation. This is not a security update.
https://www.fosshub.com/MKVToolNix.html

Utility Updates

These are unlikely to be of interest to most people.

1Password for Mac 7.4.1 resolves several bugs. This is a security update.
https://1password.com/downloads/mac/

RoboForm 8.6.2 resolves several bugs. This is not a security update.
https://12pd.com/click?rf

8GadgetPack 31.0 improves compatibility. This is not a security update.
https://8gadgetpack.net/

Beyond Compare 4.3.2.24472 resolves several bugs and improves compatibility. This is not a security update.
https://www.scootersoftware.com/download.php?zz=dl4

BulkFileChanger 1.70 adds support for Office format date/time values. This is not a security update.
https://www.nirsoft.net/utils/bulk_file_changer.html

DesktopOK 6.71 adds new explore path feature. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

DevManView 1.60 adds option to Open Device Properties Window and option to create a shortcut to Device Properties window on your desktop. This is not a security update.
https://www.nirsoft.net/utils/device_manager_view.html

DriveLetterView 1.50 adds Open Device Properties Window option. This is not a security update.
https://www.nirsoft.net/utils/drive_letter_view.html

Etcher 1.5.63 updates libraries. This should be treated as a security update.
https://www.balena.io/etcher/

FolderChangesView 2.31 resolves a stability bug and changes keyboard accelerators for find and open in explorer. This is not a security update.
https://www.nirsoft.net/utils/folder_changes_view.html

GoodSync 10.10.12 resolves several stability issues and annoyances. This should be treated as a security update.
https://12pd.com/click?goodsync

IsMyHdOK 1.91 improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/IsMyHdOK

Ketarin 1.8.11 adds several new features including global “on update failed” command, variable sorting, and improved FileHippo integration. This is not a security update.
https://ketarin.org/

MS ISO Downloader 8.23 updates names and adds ISOs. This is not a security update.
https://www.heidoc.net/joomla/technology-science/microsoft/67-microsoft-windows-and-office-iso-download-tool

NTLite 1.8.0.7217 adds support for 20H1, resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

OSForensics 7.0.1005 adds several new features, resolves bugs, and improves reliability. This is not a security update.
https://www.osforensics.com/download.html

PointerStick 3.71 resolves a bug and improves compatibility. This is not a security update.
https://www.softwareok.com/?seite=Freeware/PointerStick

SearchMyFiles 3.06 resolves the time range bug. This is not a security update.
https://www.nirsoft.net/utils/search_my_files.html

TaskSchedulerView 1.53 adds an option to display only running tasks. This is not a security update.
https://www.nirsoft.net/utils/task_scheduler_view.html

USBDeview 2.81 adds an option to open Device Properties window. This is not a security update.
https://www.nirsoft.net/utils/usb_devices_view.html

WifiInfoView 2.55 adds ability to connect to an access point from within WifiInfoView and from the CLI. This is not a security update.
https://www.nirsoft.net/utils/wifi_information_view.html

WinScan2PDF 5.09 improves compatibility with certain hardware and WIA. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WizTree 3.30 adds enterprise licensing, improved treemap, in-app context menu improvements, and search improvements. This is not a security update.
https://antibody-software.com/web/software/software/wiztree-finds-the-files-and-folders-using-the-most-disk-space-on-your-hard-drive/

WSUS Offline 11.8.2 updates libraries, improves compatibility, and supercedence rules. This is not a security update.
http://download.wsusoffline.net/

Developer Updates

These are unlikely to be of interest to most people.

AutoHotkey 1.1.31.01 resolves several bugs. This is not a security update.
https://www.autohotkey.com/download/

Android Studio 3.5.2 resolves several bugs. This is not a security update.
https://developer.android.com/studio/index.html

Inno Setup 6.0.3 and Inno Setup QuickStart 6.0.3 adds several new features including dark theme, new messages, and directives. This is not a security update.
http://www.jrsoftware.org/isdl.php

Node.js 13.1.0 resolves dozens of bugs. This is not a security update.
https://nodejs.org/en/

SQLite 3.30.1 resolves several bugs. This is not a security update.
https://www.sqlite.org/download.html

TortoiseGit 2.9.0 updates libraries and resolves many bugs. This is a security update.
https://tortoisegit.org/

TortoiseSVN 1.13.1 updates library and adds digital signature. This should be treated as a security update.
https://tortoisesvn.net/downloads.html

Visual Studio Code 1.40 resolves over 4600 issues. This is a security update.
https://code.visualstudio.com/

Virtual Machine Updates

These are unlikely to be of interest to most people.

VirtualBox 6.0.14-133895 resolves several bugs. This is not a security update.
https://www.virtualbox.org/wiki/Downloads

Web Package Updates

These are likely to be of interest only to web developers.

Adminer 4.7.4 is a security update.
https://www.adminer.org/en/

phpList 3.4.8 doesn’t provide a changelog, so should be treated as a security update.
http://www.phplist.com/download

Nextcloud Server 17.0.1 resolves several bugs. This is not a security update.
https://nextcloud.com/

Drupal 8.7.9 resolves several bugs. This is not a security update.
https://drupal.org/download

Joomla 3.9.13 is a security update.
https://www.joomla.org/

MailEnable 10.27 is a security update.
https://www.mailenable.com/

ScreenConnect 19.4.25759.7247 resolves several bugs. This is not a security update.
https://www.connectwise.com/software/control/download

WordPress 5.3 is a security update. This version adds the Twenty Twenty theme, improved block editor, accessibility and keyboard improvements, automatic image rotation, and more.
https://wordpress.org/

Akismet 4.1.3 improves compatibility and resolves several bugs. This is a security update.

bbPress 2.6.0 improves moderation, engagements, and several other features, adds compatibility with PHP 7.1+, and resolves over 400 bugs. This is not a security update.

Contact Form 7 5.1.5 improves the configuration validator. This is not a security update.

Custom Facebook Feed 2.12 resolves several bugs. This is not a security update.

myStickymenu 2.2.6 is a security update.

WooCommerce 3.8.0 doesn’t have a changelog so should be treated as a security update.

WP Mail SMTP 1.7.1 improves compatibility and resolves several bugs. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/

Updates 2019-10-08

Hi, Folks!

Today is Patch Tuesday for October 2019 and it’s pretty mild for anyone not using Apple products.

The next build of Windows 10, version 1909, will be released any time. This version will be minor compared to other Windows 10 upgrades and should be nearly indistinguishable from 1903. If you’re running 1903 now installing 1909 should have no negative impact. If you’re running an older version I recommend upgrading to 1903 before switching to 1909.

Windows 7 will fall completely out of support in only 3 months. Don’t run out the clock. If you are running a licensed version of Windows 7 you can still upgrade to Windows 10 and have a supported version of Windows for the foreseeable future. Get it done before it’s too late. Don’t want to do it yourself? Call me!
https://saferpc.info/contact/

This month we learned that sometimes the weakest link is support. ZenDesk, central to support for more than 120,000 companies from Airbnb to MailChimp to Vimeo, was hacked in 2016 and discovered it only last week. They’re doing things right: public exposure, contacting customers, describing the chain of events, getting outside help to research and resolve their issues. Unfortunately, this doesn’t eliminate the problems for the approximately 25% of their customers that were exposed in this breach.

Now back to our regularly scheduled program. The typical computer should see roughly 2 GB in updates today. Let’s get started.

Microsoft released updates for Windows, .NET, Edge, Internet Explorer, and MSRT (~ 1.1 GB). This includes security updates. A reboot is required.

Apple released updates for macOS Catalina 10.15, macOS Mojave 10.14.6 Supplemental Update 2, Security Update 2019-005 High Sierra, Security Update 2019-005 Sierra, iCloud for Windows 10.7, iCloud for Windows 7.14, iTunes for Windows 12.10.1, iOS 12.4.2, iOS 13.1.2, iPadOS 13.1.2, Safari 13.0.1, Xcode 11.0, tvOS 13, and watchOS 6.0.1. These are security updates. Use Apple Software Update to install the most current versions.

macOS Catalina (10.15) is available! This is a large download and will take between 2 and 4 hours to install on most hardware. The release of macOS Catalina (10.15) means that macOS Sierra (10.12) is now no longer supported. If you can not install at least macOS High Sierra (10.13) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

iOS 12.4.2 and 13.1.2 are security updates. Use Settings, General, Software Update to install the most current update.

watchOS 6.0.1 is a security update. Use the Watch app on your iPhone to install the most current version.

tvOS 13.0 is a security update. Use System, Software Update to install the most current version.

Google Chrome OS 77.0.3865.105 is a security update. Use Menu, Help, About to install the most current version. A reboot is required.

Don’t forget to check your mobile devices, too! Many updates will also apply to your tablet, phone, kindle or television – so check your device-appropriate App Store and install updates.

Important Notes

Everything above this section should be checked by everyone on every computer. Chances are good that close to every single computer you touch will be affected by those updates. This is not the case with the items below, though you should still check each line item below to see if it applies to software you have installed.

The release of macOS Catalina (10.15) means that macOS Sierra (10.12) is now no longer supported. If you can not install at least macOS High Sierra (10.13) on your Mac then you should immediately remove it from the Internet and use it offline only. It will no longer receive patches or updates and can now no longer be secured.

The now-current release of the Windows 10 (1903) will cause your computer to feel unusually slow until it is installed. This is a side-effect of the Windows 10 upgrade cycle, which pushes out 3-6 GB through Windows update to get you to the latest Windows 10 release every 6 months. If you don’t let it finish and you’re on a slow connection, it will kill your Internet performance forever. If you don’t have the bandwidth to download the bits, I’m happy to provide loaner USB drives to our local clients, or, if you prefer to have me mail it to you please contact me for information.

Please remember that while I list many different applications within these updates, most people should ONLY install updates for a program if they already have a previous version of that program installed.

It is essential to maintain all the applications you have installed on your computer, but often you can minimize the time investment and the potential for exploitation simply by uninstalling software you do not need or use, reducing the attack surface.

Also note that using the applications own “check for updates” function, when available, will best preserve your current settings, and often avoid any crapware that might come with a fresh installer. Use this option if it’s available to you.

Finally, if you’re sick of doing this all yourself, let me! Call or email me any time, and we can set you up with subscription SaferPC updates which will be installed each month whenever necessary. Click, call or email for more details:
https://saferpc.info/updates/
209-565-12PD
shawn@12pointdesign.com

Driver Updates

If you’re using this hardware – these updates are for you.

Display Driver Uninstaller 18.0.1.9 improves cleanup, system restore, and resolves several bugs. This is not a security update.
https://www.wagnardsoft.com/display-driver-uninstaller-ddu

Intel Driver and Support Assistant 19.9.38 improves device detection. This is not a security update.
https://www.intel.com/p/en_US/support/detect

nVidia 436.48 adds support for newer hardware and improves performance. This is not a security update.
https://www.nvidia.com/Download/index.aspx?lang=en-us

Browser Updates

One or more of these are likely to be of interest to everyone.

Google Chrome 77.0.3865.90 is a security update. Use Menu, Help, About to get the most current version.

Firefox 69.0.2 resolves several bugs, but follows shortly on the heels of 69.0.1, which was a security update. Use Menu, Help, About to get the most current version.

Vivaldi 2.8.1664.40 resolves several bugs. This is not a security update.
https://vivaldi.com/

Email Updates

One or more of these are likely to be of interest to everyone.

Thunderbird 68.1.1 is a security update. Use Menu, Help, About to get the most current version.

Internet Updates

One or more of these are likely to be of interest to everyone.

Prosody 0.11.3 resolves several bugs and improves reliability. This is not a security update.
https://prosody.im/download/start

Trillian 6.2.0.12 resolves several bugs. This is not a security update.
https://www.trillian.im/

aria2 1.35.0 updates libraries and resolves several bugs. This is a security update.
https://aria2.github.io/

BrowsingHistoryView 2.25 adds support for Waterfox. This is not a security update.
https://www.nirsoft.net/utils/browsing_history_view.html

DNSDataView 1.60 adds TTL. This is not a security update.
https://www.nirsoft.net/utils/dns_records_viewer.html

FileZilla Client 3.45.1 resolves several bugs and adds stale version detection. This should be treated as a security update.
https://filezilla-project.org/

MaxMind GeoIP2 201910 is a data refresh.
http://dev.maxmind.com/geoip/

PuTTY 0.73 is a security update.
https://www.chiark.greenend.org.uk/~sgtatham/putty/download.html

WinSCP 5.15.4 is a security update.
https://winscp.net/eng/index.php

Media Updates

These are unlikely to be of interest to most people.

MusicBrainz Picard 2.2.2 resolves dozens of bugs and adds several new features. This is not a security update.

Flickr Downloadr 3.2.3.1 resolves a JSON length bug. This is not a security update.

iTunes 12.10.1 is a security update. Use Apple Software Update to install the most current version.

Game Updates

These are unlikely to be of interest to most people.

Steam 2019.09.19 resolves a beta bug. This is not a security update. Use Steam to update Steam.

PlayStation PS4 7.00 is a major update that doubles the size limit of parties to 16, improves networking, adds chat transcription, improves voice audio, adds Remote Play to more devices, and resolves several bugs. This is not a security update.
https://www.playstation.com/en-us/support/system-updates/ps4/

Office Updates

One or more of these are likely to be of interest to most people.

Artweaver 7.0.2 improves online update and error reporting, resolves several bugs. This is not a security update.
http://www.artweaver.de/

Krita 4.2.7.1 resolves several bugs, improves color selector, layer controls, and adds new brushes. This is not a security update.
https://krita.org/en/download/krita-desktop/

LibreOffice Fresh 6.3.2 resolves dozens of bugs. This is not a security update. (“Fresh” is the Beta version so stick with “Still” unless you don’t mind stability issues.)
https://www.libreoffice.org/

OpenOffice 4.1.7 resolves several bugs and adds support for OpenJDK. This is not a security update.
http://www.openoffice.org/download/

Paint.net 4.2.5 adds support for WebP format and resolves several bugs. This is not a security update.
https://www.getpaint.net/

Adobe DNG Converter 11.4.1 adds support for newer hardware. This is not a security update.
macOS: https://supportdownloads.adobe.com/detail.jsp?ftpID=6743
Windows: https://supportdownloads.adobe.com/detail.jsp?ftpID=6741

Security Software Updates

One or more of these is likely to be of interest to most people.

OpenSSL 1.0.2t is a security update.
https://indy.fulgan.com/SSL/

RogueKiller 13.5.2 resolves several bugs, improves performance for large files, and improves stability. This is not a security update.
https://www.adlice.com/softwares/roguekiller/

Wireless Network Watcher 2.21 updates the internal MAC database. This is not a security update.
https://www.nirsoft.net/utils/wireless_network_watcher.html

PureOS 9.0 is a new major release of PureOS, updates libraries, dependencies and forging the way for the final release of the Librem 5. This is a security update.
https://pureos.net/download/

Converter Updates

These are unlikely to be of interest to most people.

MKVToolnix 38.0.0 resolves several bugs, improves immutability, adds new default output (console) to mkvextract. This is not a security update.
https://www.fosshub.com/MKVToolNix.html

DVDFab 11.0.5.3 adds support for new encodings, updates libraries, resolves several bugs. This is not a security update.
https://www.dvdfab.cn/download.htm

Education updates

One or more of these are likely to be of interest to most people.

e-Sword 12.1 updates the downloader to support eStudySource. This is not a security update.
https://www.e-sword.net/

Utility Updates

These are unlikely to be of interest to most people.

1Password for Windows 7.3.712 resolves several bugs, adds support for new features. This is a security update.
https://1password.com/downloads/windows/

Agent Ransack 2019.2929 is a major update that adds high-DPI support, improves performance, improves PDF search, resolves several bugs. This is not a security update.
https://www.mythicsoft.com/agentransack/download/

BgInfo 4.28 doesn’t provide a changelog, so should be treated as a security update.
https://live.sysinternals.com/

Sysmon 10.41 resolves a configuration parsing bug. This is not a security update.
https://live.sysinternals.com/

DesktopOK 6.59 resolves several bugs and improves color detection. This is not a security update.
https://www.softwareok.com/?seite=Freeware/DesktopOK

Etcher 1.5.57 resolves a startup bug. This is not a security update.
https://www.balena.io/etcher/

FolderChangesView 2.30 adds “*.” support to include/exclude files without filenames. This is not a security update.
https://www.nirsoft.net/utils/folder_changes_view.html

GoodSync 10.10.9 resolves several bugs and updates cipher list. This is a security update.
https://12pd.com/click?goodsync

NTLite 1.8.0.7165 adds new features, updates translations, and resolves several bugs. This is not a security update.
https://www.ntlite.com/download/

OSForensics 7.0.1004 adds clipboard viewer, AmCache viewer, auto triage, VM improvements, improved indexing, and resolves several bugs. This is not a security update.
https://www.osforensics.com/download.html

Password Security Scanner 1.46 improves reliability and adds support for Waterfox. This is not a security update.
https://www.nirsoft.net/utils/password_security_scanner.html

Recover Keys 11.0.4.233 adds support for over 1,000 new applications. This is not a security update.
https://recover-keys.com/en/download.html

RoboForm 8.6.1 impose periodic Master Password check, add difference check to Backup/Restore, add import from Sticky Password, resolves several bugs. This is not a security update.
https://12pd.com/click?rf

Rufus 3.8 resolves several bugs. This is not a security update.
https://rufus.ie/en_IE.html

SearchMyFiles 3.05 adds support to specify time range in GMT. This is not a security update.
https://www.nirsoft.net/utils/search_my_files.html

WakeMeOnLan 1.85 updates the internal MAC database. This is not a security update.
https://www.nirsoft.net/utils/wake_on_lan.html

WifiInfoView 2.47 updates the internal MAC database. This is not a security update.
https://www.nirsoft.net/utils/wifi_information_view.html

WinScan2PDF 5.01 improves drag and drop page re-order feature, multiformat output, adds support for multiple scan operations. This is not a security update.
https://www.softwareok.com/?seite=Microsoft/WinScan2PDF

WSUS Offline 11.8.1 improves detection of updates and resolves supersedence issues. This is not a security update.
http://download.wsusoffline.net/

Developer Updates

These are unlikely to be of interest to most people.

AutoHotkey 1.1.31.00 adds Switch and InputHook, improves support for long paths, and resolves several bugs. This is not a security update.
https://www.autohotkey.com/download/

Android Studio 3.5.1.0 resolves several bugs. This is not a security update.
https://developer.android.com/studio/index.html

Node.js 12.11.1 resolves several bugs. This is not a security update.
https://nodejs.org/en/

SQLite 3.30.0 adds support for aggregate filters, NULLS FIRST/NULLS LAST in order by, improves index, and resolves several bugs. This is not a security update.
https://www.sqlite.org/download.html

Virtual Machine Updates

These are unlikely to be of interest to most people.

PPSSPP 1.9.3 resolves several bugs. This is not a security update.
https://ppsspp.org/downloads.html

Web Package Updates

These are likely to be of interest only to web developers.

YOURLS 1.7.4 is a security update.
https://yourls.org/

Drupal 8.7.8 is a security update.
https://drupal.org/download

Joomla 3.9.12 is a security update.
https://www.joomla.org/

Nextcloud Server 17.0.0 adds remote wipe, improved 2FA, secure view, one-time login tokens, secure mailbox Outlook Add-in, and resolves several bugs. This is not a security update.
https://nextcloud.com/

Adobe ColdFusion 2018.5 and 2016.12 are security updates.
https://helpx.adobe.com/security/products/coldfusion/apsb19-47.html

phpList 3.4.6 resolves several bugs. This is not a security update.
http://www.phplist.com/download

phpMyAdmin 4.9.1 resolves several bugs. This is a security update.
http://www.phpmyadmin.net/home_page/news.php

BuddyPress 5.0.0 adds BP REST API, group invites, group membership requests, improved WP integration, and resolves several bugs. This is not a security update.

Smash Balloon Social Post Feed 2.11 (was Custom Facebook Feed) adds several new options, restores FB group access, and updates FB API to v4.0. This is not a security update.

myStickymenu 2.2.3 updates Pro features. This is not a security update.

Redirection 4.4.2 resolves several bugs. This is not a security update.

W3 Total Cache 0.10.1 resolves several bugs. This is not a security update.

That’s all for now folks. Keep it clean out there. 😉

Regards,

Shawn K. Hall
https://SaferPC.info/
https://12PointDesign.com/