windows

ComputerWorldIndependent

The case against knee-jerk installation of Windows patches

Credit to Author: Woody Leonhard| Date: Mon, 17 Jun 2019 03:10:00 -0700

Heresy. Yes, I know. Any way you slice it, from my point of view anyway, Windows Automatic Update is for chumps.

Just like the “users must be forced to change their passwords frequently” argument that’s no longer au courant, the “users must get patched immediately” argument is based on old, faulty, and totally unsubstantiated claims that make security people feel better — and little else.

With a few notable exceptions, in the real world, the risks of getting clobbered by a bad patch far, far outweigh the risks of getting hit with a just-patched exploit. Many security “experts” huff and puff at that assertion. The poohbahs preach Automatic Update for the unwashed masses, while frequently exempting themselves from the edict.

To read this article in full, please click here

Read More
ComputerWorldIndependent

Microsoft is better at documenting patch problems, but issues abound

Credit to Author: Woody Leonhard| Date: Thu, 13 Jun 2019 03:55:00 -0700

I don’t know about you, but I’ve given up on Microsoft’s ability to deliver reliable patches. Month after month, we’ve seen big bugs and little bugs pushed and pulled and squished and re-squished. You can see a chronology from the past two years in my patching whack-a-mole columns starting here.

For the past few months, though, we’ve seen some improvement. Microsoft has started identifying and publicly acknowledging big bugs, shortly after they’re pushed. Consider:

To read this article in full, please click here

Read More
ComputerWorldIndependent

Save yourself a headache: Make sure Windows automatic update is off

Credit to Author: Woody Leonhard| Date: Mon, 10 Jun 2019 04:22:00 -0700

Read More
ComputerWorldIndependent

NSA, Microsoft implore enterprises to patch Windows' 'BlueKeep' flaw before it's too late

Credit to Author: Gregg Keizer| Date: Wed, 05 Jun 2019 13:16:00 -0700

The U.S. National Security Agency (NSA) on Tuesday called on IT administrators to apply security updates issued by Microsoft three weeks ago, adding to a chorus of voices urging haste.

“The National Security Agency is urging Microsoft Windows administrators and users to ensure they are using a patched and updated system in the face of growing threats,” the NSA said in a June 4 advisory.

The agency’s advice followed by several days that of Microsoft itself. On Thursday, May 30, a company official reminded users of the updates – which the company released May 14 – and implied that time is short. “We strongly advise that all affected systems should be updated as soon as possible,” Simon Pope, the director of incident response at the Microsoft Security Response Center (MSRC), wrote in a blog post.

To read this article in full, please click here

Read More
ComputerWorldIndependent

It’s time to install the May Windows and Office patches

Credit to Author: Woody Leonhard| Date: Tue, 04 Jun 2019 05:08:00 -0700

May 2019 will go down in the annals of Patch-dom as the month we all ran for cover to fend off another WannaCry-caliber worm, but a convincing exploit never emerged.

Microsoft officially released Windows 10 version 1903 on May 21, but I haven’t yet heard from anyone who’s been pushed. All of the complaints I hear are from those “seekers” who went to the download site and installed 1903 with malice and forethought. A triumph of hope over experience.

This month, if you let Windows Update have its way on your machine, you may end up with a different build number than the person sitting next to you. Blame the gov.uk debacle for that: Folks with Windows set up for U.K. English get an extra cumulative update pushed onto their machines, whilst those who don’t fly the Union Jack will get the fix in due course next month.

To read this article in full, please click here

Read More
SecuritySophos

No permita que su servidor SQL le ataque con ransomware

Credit to Author: Naked Security| Date: Mon, 27 May 2019 16:44:32 +0000

Si los ciberdelincuentes quieren infiltrarse en su sistema, tienen bastantes opciones. Podrían atacar usando vulnerabilidades y exploits para evitar las medidas de seguridad que tiene y engañar a sus servidores para que ejecuten un software que no deberían. O podrían descubrir cómo entrar sin ningún tipo de truco de bajo nivel, usando la entrada oficial [&#8230;]<img src=”http://feeds.feedburner.com/~r/sophos/dgdY/~4/h90no2fXwsE” height=”1″ width=”1″ alt=””/>

Read More