A patch is not just for Christmas…
Full article332 words · extracted from securelist.com · click to collapse
Patching systems remains an essential part of an overall security strategy. For Windows, the easiest way to stay up-to-date is to enable Automatic Updates – you can find more information here.
Here’s a summary of this year’s patches:
| Critical | Important | Moderate | |
| January | 1 | 0 | 1 |
| February | 6 | 0 | 5 |
| March | 0 | 4 | 0 |
| April | 0 | 5 | 3 |
| May | 0 | 3 | 1 |
| June | 3 | 3 | 1 |
| July | 0 | 0 | 4 |
| August | 0 | 6 | 5 |
| September | 0 | 4 | 0 |
| October | 6 | 6 | 1 |
| November | 0 | 1 | 1 |
| December | 0 | 6 | 2 |
Patched security vulnerabilities in 2008
The figures above include not only regular ‘Patch Tuesday’ updates, but any out-of-band updates issued by Microsoft. So far this year there has been just one such update, in October.
However, you may have seen the recent Microsoft Security Advisory (961051) relating to a vulnerability found in Internet Explorer. So far no patch has been announced for this vulnerability, but we’ll let you know if that changes.
You’ll see that the numbers have remained relatively consistent over the last three years. You can find the 2006 chart here and the 2007 chart here.
Here’s a summary of the totals for the last three years:
| Critical | Important | Moderate | |
| 2006 | 49 | 23 | 5 |
| 2007 | 43 | 24 | 2 |
| 2008 | 45 | 31 | 2 |
Patched security vulnerabilities
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/a-patch-is-not-just-for-christmas/30473/