Patch Tuesday Support Group February Webinar
Webinar Summary
This month Jake Shackelford filled in the security role and covered the month’s latest update releases. Then Bryan Dam spent far too long discussing the news of the month, per usual. Closing the February Patch Tuesday Support Group Webinar: Patch My PC’s very own David Stewart! We heard from David as he shared his knowledge of SCUP and talked about his experience helping build SCUP when he was at Microsoft.
Watch the Webinar Recording
Webinar Hosts
Bryan Dam
Patch My PC
Software Engineer
Jake Shackelford
Patch My PC
Infrastructure Engineer
David Stewart
Patch My PC
Engineering Manager
Patch Tuesday Support Group Webinar Recap
Patch Tuesday February News
Microsoft email accounts gets hacked by Russia — Midnight Blizzard: Guidance for responders on nation-state attack | Microsoft Security Blog
HPE hacked by Russia — Hewlett Packard Enterprise tells SEC it was breached by Russia’s ‘Cozy Bear’ hackers (therecord.media)
Mother of all breaches reveals 26 billion records — Mother of All Breaches: a Historic Data Leak Reveals 26 Billion Records | Cybernews
Water Hydra targets traders with Microsoft Defender SmartScreen zero-day — CVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day (trendmicro.com)
ConfigMgr 2401 TP released — New software update remediation dashboard, Search the entire console, HTTP-only is deprecated: use EHTTP or HTTPS, The 2403 release will require CMGs be deployed to VM scale net. Technical preview 2401 – Configuration Manager | Microsoft Learn
What’s New Intune — MacOS app size limit increased to 8 GB, 30 GB for Win32 apps, Bulk editing for driver policies, Enterprise Application Management blog, Microsoft Intune Advanced Analytics. What’s new in Microsoft Intune | Microsoft Learn
WUfB DS supports readiness deployments for expedite — Device readiness checks for expedited Windows quality updates | Windows IT Pro blog (microsoft.com)
WMIC is being Deprecated — WMI command line (WMIC) utility deprecation: Next steps | Windows IT Pro blog (microsoft.com)
Exchange Online – High Volume Email — Send High Volume Email in Microsoft 365 (ourcloudnetwork.com)
Updates on WinRE Patches — KB5034441: Windows Recovery Environment update for Windows 10, version 21H2 and 22H2: January 9, 2024 – Microsoft Support and KB5034957: Updating the WinRE partition on deployed devices to address security vulnerabilities in CVE-2024-20666 – Microsoft Support
Microsoft Patches of Note
View the full list of Patch Tuesday release notes at Patch Tuesday Blog Home Page – Patch Tuesday Blog
Updates Released: 133
Critical Severity: 89
Important Severity: 44
Third Party Updates from Patch My PC
Total Number of Updates: 2359
Total Number of CVES: 299
Critical: 56
Moderate: 1879
Important: 347
N/A: 10
Browser Patch Specifics
Chrome: 18 Patches
FireFox: 10 Patches (EN-US)
Microsoft Edge: 21 Patches
Opera: 14 Patches
Insight into CVEs
Critical CVEs: 5
Important CVEs: 66
Moderate: 3
N/A: 6
CVE breakdown
31 Remote Code Execution
16 Elevation of Priviledge
10 Sproofing
5 Information Disclosure
3 Security Feature Bypass
Patches of Note
AnyDesk Incident Response 5-2-2024 – This correlated directly with a re-release of their binaries and re-released software with a new signed certificate. AnyDesk Incident Response 5-2-2024