Microsoft shipped fixes for nearly a thousand security flaws last week. Two of them were already being used to break into machines before the fix existed.
That's one Tuesday. It happens every month.
Both of the live ones did the same thing — they let an attacker who already had a small foothold on a computer promote themselves to full control of it.
Here's the part nobody likes hearing: the danger isn't really the flaw. It's the gap between the day Microsoft publishes the fix and the day it actually lands on your machines. Publishing a fix also tells every attacker exactly where the hole was. If your team has been clicking "remind me tomorrow" since June, that gap is your exposure.
For a 15-attorney firm this isn't abstract. It's a partner's laptop down for a day and a half, an assistant on the phone with a vendor instead of on the clock, and an awkward call to a client about why their documents aren't available.
And if you still have Windows 10 machines in the office, they only get these fixes if you're enrolled in Extended Security Updates.
Patching isn't strategy. It's maintenance. But it's the maintenance that decides whether a bad Tuesday is an inconvenience or a week you lose.
Worth a look before your next cyber renewal.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email