Microsoft has just released its largest security update ever: 570 security flaws fixed in a single month, including 59 rated Critical. A typical month sees between 60 and 120. This one is nearly five times that.
The headline numbers: 254 “elevation of privilege” bugs, 145 “remote code execution” bugs, 102 information disclosure bugs, 35 denial of service bugs, 17 security bypasses and 16 spoofing bugs.
In plain English: over half of these flaws are ways for an attacker to either get into your systems from the outside, or turn a small foothold – one compromised account, one infected machine – into full control of your network.
Three flaws the attackers found first
Three of the 570 are “zero-days” – flaws that attackers knew about before Microsoft had a fix ready. Two are already being used in real attacks.
One affects the Microsoft system many businesses use to handle staff sign-ins (AD FS): an attacker who gets in can quietly promote themselves to administrator. The other affects SharePoint Server – the flaw lets an attacker gain those powers over the network without needing a password at all.
The third involves BitLocker, the technology that encrypts the data on your laptops. Someone with physical access to a device – think a laptop left on a train or stolen from a car – could get at data that should be unreadable. It was made public before the fix existed, which means criminals have had the recipe.
One catch: some Dell PCs are on hold
There is a wrinkle this month. Microsoft has temporarily blocked the July update on certain Dell computers, because a clash with an Intel driver was causing machines to shut down unexpectedly, run hot and drain batteries. If you have Dell machines that say the update isn’t available yet, that’s deliberate – don’t force it on manually. Microsoft says a fix is days away.
In plain English: some of your Dell machines may be sitting unpatched through no fault of your own. They still need watching, and they should get the update as soon as Microsoft reopens it – which is easy to miss if nobody is checking.
What your business should do this week
Don’t panic – patch. Specifically:
The bigger picture
A 570-fix month is a reminder that patching isn’t an occasional chore – it’s a continuous process, and the gap between “fix released” and “fix applied” is exactly where attackers operate. Our managed clients don’t have to think about any of this: the updates are tested and rolled out as business as usual, the exploited flaws first, and the held-back Dell machines tracked until Microsoft clears them.
If you’re not certain every machine in your business has these fixes – or you’d rather never have to think about a question like that – get in touch.