• 1 Post
  • 20 Comments
Joined 2 years ago
cake
Cake day: June 20th, 2023

help-circle





  • With Windows 10, Microsoft started performing a monthly cumulative updating schedule. Every second Tuesday of the month is “patch day” and a new monthly cumulative update is made available.

    There are exceptions to this, for security and bug fixes that can’t wait until the next monthly round-up. So perhaps this month was one of those? But trends are that updates are monthly. I can see it being perceived as more often, as the update is forced onto us, with a reboot, which can be frustrating.

    Azure servers now support reboot-less updating, hopefully that makes its way to consumer products, but who knows.

    Microsoft has always had a bad rep for their OS being full of holes and getting exploited. However some of this was due to users not updating. Microsoft would patch an issue, but huge swaths of unpatched Windows machines would be exploited and used as botnets. I think the forced updates were in response to this situation. Not that I agree with it.







  • Many malicious actors don’t trigger their payload that you would notice until after data has been mined.

    I’ve visited businesses to help put together basic infrastructure after their systems were encrypted and ransomed. We would bring up a backup from the night before only to find the system still infected. We would go back a week, 2 weeks, a month.

    These things lie in wait and only as the final nuclear option do they get noticed.