Transcript
The agenda today, I will start with a general view on the Suze Pass. After that, Kensi will do the in-depth news, and then we will do the bulletins and releases on the Suze Pass. The month of October or August, it was quite active since July. So there are still a lot of things to cover. Especially if we look, for example, I will show you a screen. Wait, stop sharing. I will show you my screen quickly. If you don't mind. Windows, entire screen. Share. I'm waiting for it to come back up. So here is a website, Patchpalooza, I don't know if you know it, but it's a Microsoft website. So it's all about Microsoft patches. And then I'm going to make a little chart for Suze Pass. And we can see that last July, Microsoft released 571 CVEs. And this time, they almost doubled to 998. So there are still a lot of things patched. That's why we have a lot of bulletins on the Suze Pass too. We can't discuss everything in detail, but the most important thing we're going to tell you. At the same time, we have other sites, as Ask told you, that you also have information about security patches. That's in English. There is also the CVE Security Database. So there is a database with CVEs. So you can do research, etc. And of course, you also have ANSI here for security in France. So these are some websites that we also use for our research. We're going to look for articles, we're going to look for information, etc. You have CERT, you have ANSI, you have other sites too. But in general, I use this site a lot. We will now share. Yes. Cancel. There you go. So, we talked a lot about patch apocalypse in the United States, because of artificial intelligence. There are a lot of discovered bugs. I'm going to calculate. Among other things, for Adobe and Microsoft. On this slide, we don't have a lot of Google, but in the bulletins, we also have Google, because Google provided us with the information a little late. So we couldn't incorporate it into the slide. But you should know that Google has released more than 200 patches. And with these patches, there is also a 0D that is covered. So we'll see that later in the bulletin. Thank you, André. So, in the news, what do we have this month? In any case, do not hesitate to go to the first link, which is a blog by Eventi that summarizes Patch Tuesday, on everything we are saying, and even more. So it's quite interesting, with links, with a lot of information. What is new too, is everything that has to do with management with IA. Indeed, what happened is that there was this rise in vulnerability related to IA, and that everyone panicked a little bit. But finally, according to some articles and some specialists, it can be better managed, this patching process, better than what we were afraid of at the beginning of April, where there was this huge amount of vulnerability found by IA. So this study indicates that IA really accelerates this discovery of vulnerability considerably. But companies are better armed, better built, better organized, to face this increase that at the beginning, precisely the first articles did not think of, especially with the famous patch apocalypse. So of course, everything is based on the ability to validate quickly, hierarchize, etc. Everything that concerns the management part of the patches. So it's a pretty interesting article, which is the second link here in this slide. There is also something new that concerns Google Chrome, it is the Chrome Web Store. Indeed, they were caught red-handed in terms of theft of crypto-currencies and navigation data. That is to say, everything that happened is related to the extensions of Google Chrome and Edge, which spread an evil framework. This one deployed modules intended to steal crypto-currencies, sensitive data, etc. And why not also inject click-fixed lures? According to researchers, there are 19 malicious modules that have been identified within this campaign. And suddenly, these extensions remain highly extensible. So the idea is that this operation has been updated by Socket, a company specialized in security. And what is most worrying is that these extensions have been active since 2024. So it's something quite old. And the last one is Microsoft, which is starting to remove the WMC tool, which is used a lot by cybercriminals to be able to launch command lines. In any case, it is from all the versions of 2024, 2021, 2024 and 2025 H2, which are starting to be deleted, and also in the beta version this week. So here it is, WMC is a command line user. I had even forgotten that it still existed, this one. So here it is, it is the removal of this tool that allowed cybercriminals to exploit things, thanks to this tool. Is there anything for the next beta? So, there are still two patches exploited, that is to say two 0D published on Tuesday. It was published, these two patches, two days ago, on Tuesday of the Tuesday patch. So here we are in two patches that still concern Windows 10, 2012, so a lot of OS. So the idea of this 0D, in any case, is privilege removal. It allows a local attacker, in any case authorized, with low privileges, to access a new system level, without any interaction of the user who uses the machine. So really, it's very, very serious. So, of course, it's to deploy as quickly as possible, since it's a 0D. And there is a second 0D which is, here we are in a privilege removal impact, and its impact is a little less, more limited than the previous one, but in any case, it concerns Windows 11 and Windows 2025, but we will be careful to deploy quite quickly. OK, before I do the Linux thing, there is one thing that I wanted to alert you about, it is that at the data browser level, because there are some researchers who have found that if a final user has his Google, Gmail, Apple or Microsoft accounts that synchronize, there may be passwords, for example, in the enterprise that are synchronized with the user's personal account. So you can have a password leak because of that. So be careful at the synchronization level of everything that is Google, Apple, Microsoft, etc. for the personal account, not the Pro account. That's just what I wanted to alert you about, so that you are aware that there is a risk of data leak. For Linux now, there is a vulnerability, the ECVE, you can read the numeral, I will not read the numeral, but it is an SCP copy, and in fact it is an ECVE that has been around for 18 years, so it's quite a long time, but with the AI that the researchers do, they also find old vulnerabilities. So it's been around for 18 years. At the level of Ubuntu and Kubernetes, there is a rating of 9.8. Amazon's rates are a little more temperate, 7.0. We said that maybe Amazon's rates are a little more secure or something, but we still report it as important enough to patch as quickly as possible. This is the Netfilter Flow Table, it's the same, it's the commercial code, 9.8, so it's quite important. Oracle's score is a little lower, but Amazon's is 8, so it's still quite important. You can remove the Flow Table if you know how to do it, or you just have to update the kernel on it. This is the ECVE. So here, the ECVE that is not the Mac VLAN, in fact, it's the Container Host, so if you have another Linux that has Kubernetes or other containerization, you may be concerned about this ECVE, and we advise you to patch it as quickly as possible if you do that. Also, everything that is Linux at home, it's a partner of ours called TuxCare, and it's a partner that shows us, they are really specialized in Linux, they show us the Linux files regularly for the entire 2D patch. The kernel-sep-client, which is also on Linux, the only way to get rid of it is to update it. So you can't patch or configure it, you have to update it, and it affects the kernel 3.10 or more. So you really need to update it on 5.10 or 5.15, 6, etc. So you can see the mitigations, how you can fix it if you want. There is also everything that concerns the security updates for Ivanti, so this month, in September, Ivanti has released 10 ECVEs concerning the three EPMM products, that is, the Meruil management, the ITSM part as well, Ivanti now launches ITSM, and also Sentry, which is the MDM part. On the ITSM part, there are more ECVEs, so there are 8 ECVEs on the ITSM part. The administrators at the installation level have to apply them quite quickly, because ECVEs have a fairly high scoring, so to be able to retrieve them, you have to retrieve them from the license site, Ivanti on the license portal. On the other hand, version 2026.2 will include this ECVE directly natively, so the release is scheduled for September 21, 2026. Then on the EPMM part, yes, there is a vulnerability, so it concerns version 12.9 and also 12.8, everything that is previous. And at the Sentry level, it concerns versions 8.8 and 10.7. So this quality will also be included in the version that will be published soon, so if there is something that is planned, in any case, to migrate, to update, why not wait and have the date. At the moment, I don't really have the release date for this version, but on the ITSM part, it is already planned for September 21, so in just 10-11 days. So there is the Windows 10 lifecycle, it is still the 24H2 that arrives at the end, in about a month, so at the end of support, it is still to be planned, to start planning, for those who have not started, to migrate to the most recent versions, and also everything that is the Enterprise version, it is the same, which arrives soon, in a month at least, at the end of life, for version 23H2. Everything that is the channel also, for the server part, so there is still a little time, but still, 2016 is in a year where it ends support, so there is still, even if there is time, it is still things that take a lot of time, especially on the server part, which allows us to anticipate. So everything that is the updates, the updates of interest, compared to Patch Tuesday, there is still this month, everything that concerns the SSUs, for Windows 2012, and also 2016, so of course for the servers 2012, you need the Extended Support Security Update, for those who have it, it is not to forget to update this package, in any case. And here we are, we arrive in the session, the bulletins and the releases, so André, what can you tell us here? Yes, as I said in the introduction, Chrome, Google, they still released 230 vulnerabilities, so 5 critical, and the server that is shown in red, it is exploited, so it is really important to patch as soon as possible, otherwise, since it is exploited, you run the risk. So for all browsers, so that's Chrome, but also everything that is Chromeium, so Edge is the same, in general, I do not understand Chrome, they must patch Edge too, and probably later in the bulletin, you will also see, there is Firefox, etc., that will follow too. So Adobe released a lot of bulletins too, there are no exploits, so it's patches, so you have to patch it, but you can patch it a little less urgently than 0D, or the one that is actively exploited, so it counts for Photoshop, but also for Illustrator, and for Animate. For Adobe, Adobe Acrobat Reader, or Acrobat and Acrobat Reader, there are still 32 vulnerabilities, but still no active export, so you have to update it, that's pretty important, on Windows and Mac, so both, but there is no immediate urgency, no absolute urgency to update it, but they are still critical vulnerabilities, so they are still quite important. So Windows 11, so Windows 11 has a lot of updates too, and as you can see on each slide, if the vulnerability is in red, it means that there is an exploit, so known, if you want, at the level of our presentation, you can click on the KB, and we'll bring you back to the KB, in the file, so you can check the bulletin yourself, if it concerns you or not. So, here we are, so this is a problem that has been known for a long time, it's a reporting problem, so it's been around for a long time, but it's not very embarrassing, if you want, it's just at the level of reporting that it's a problem. So, on Windows 10 and LTSB and server, there are still 70 critical vulnerabilities, 596 important, and almost the same server yesterday, so if you still have Windows 10, don't buy it, or Migrate to Windows, the latest version, if you can, if you can't, in this case, keep it, but don't buy it anyway, because it's quite important. So, the same, the same issue for Windows 10, it's the same as for Windows 11, so it's mostly a reporting problem, and it's been around for a long time, it's there, it's a little annoying, but it's not critical in itself. Thank you, André. Yes. Then we come to all the Office correctives, so, first, it's already critical severity, so, in terms of priorities, given the event side, it's really an important priority, so it affects all versions of Office 2016, so there are still a lot of vulnerabilities, so, it's critical, it just requires restarting the application, but in any case, there are no known problems, that's what's already important, in any case. There is also the Office 365 corrective, in terms of apps, so we see here, there is Office 2019, the LTSC part, it's almost all versions, in any case, it concerns, in any case, in terms of impact, it's remote execution, spoofing, etc. So, there are still 107 vulnerabilities, 21 of which are critical, so there are no known problems in relation to the installation of this corrective, it just requires a restart of the application. Then, in the SQL part, it concerns almost all the SQLs, so there are still quite a few CVEs, there are 5 that are critical, so it requires restarting the SQL, and there are still some known problems, so everything that concerns the link, it really requires a restart, there are problems in terms of the SQL, in terms of access, everything that concerns there is still a CVE in the link here, in the document, by the way, Frederic, I will give you the answer how to download the documents, and, in any case, these are two problems that are rather known, so that allows you to know what it is about in more detail on the links. There is also everything that concerns SharePoint updates, in any case, here we arrive in the important category, so it is slightly less critical, but still, you have to see it, you have to take it into account. So, here we are the same, in the remote execution code, distance, elevation, privilege, these are quite important impacts, so it corrects these vulnerabilities, so these are vulnerabilities that are not known or exploited publicly, it also requires a restart of the application, but in any case, there are no known problems, that's what's important. There is also a collective that concerns the Exchange server, so here we are, the same, in the whole panoply of impacts, remote code execution, privilege, stamping, spoofing, the need service, so there is really the whole list. It corrects nine vulnerabilities, so these are important vulnerabilities, and, the same, it requires a restart of the application. Here, we still have a lot of all the known problems, so, at the level of different types of servers, so it still concerns the cases, the APIs, so it's really, there are a few, not bad, because sometimes there are one or two known problems, but still, it concerns a little more known problems, but also because there are a lot of historical ones, often in this type of collective, so it's, still the first, it's something a fairly recent known problem, since it concerns rather, it appeared in August. There is also the monthly roll-up for the .NET, so here we are the .NET 3.5 and 4.8, so it's recent, the impact of remote code execution, there is a collective, a severe, in any case, a vulnerability. It does not require restarting anything, and above all, there are no known problems. So, that was the bulletin in relation to everything that is the collectives that we presented at the very beginning, when André explained to you a little bit the collectives of Microsoft, Adobe, etc. There, now, we go back to the session, what happened between the patches, and therefore, since the last one, which was in July anyway. And today, André, if you can explain something to us. Yes, Olivier, there are a lot, as we said, there are a lot of patches. It should also be known that from, I think, next month, the Cloud Security at the European Union will be active, and that means that the editors are obliged when they discover a bug, to report it with a CVE. In the past, for example, if an editor discovers a bug and then no one knows, they fix it under the hood and then neither seen nor known. After, I think next month, they are obliged by this act to report it. That means they can no longer do it under the hood. It's just to show that the bugs that exist, if ever you have a software of an old version, that you know that there is a bug in it. Because in the old version, if the bug was not published or not known, people could not know it. There is a logic why they have to report it. This is also one of the reasons why in the slides before, we also show you the CVE in our own product. So, we are the same, we are editors, so we publish our CVE. So, this is one of the reasons for which in the slides before, we publish our CVE. So, between the two patches, there are a lot of patches. So, if you look between the quotation marks, the number between the quotation marks, it's the number of patches that came out. So, there are a lot. So, this is the summary, if you want. Then, we will go into a little more detail. You have to know that the patches, it can be a security patch, but it can also be an update of functionality or, precisely, a summary of a closed file. So, yes, that was all. There, I didn't go to the first page, so there is a second page on it too. So, non-security updates, so, 1.1, Camtasia, Evernote, Genesys, Cloud Desktop, etc. But, you also have it on the first slide, here. Security updates without CVE, so without CVE, and also security updates without CVE. So, without CVE and with CVE, and here, you have non-security updates. So, but CVE, so, Adobe, so, and also Citrix, there is one thing that is very interesting in the CVE bulletin, so, here, for example, Citrix, you see C-T-X-W-A, and then it is 26-08-14. So, 26 is 2026, 08 is the month, August, 14. So, you have a patch that is released on August, 14, 2026. So, almost all publishers do this. So, Adobe is a little different, but it is 2026 anyway. This one, for example, is 2025, etc. So, it continues. There are a lot of patches as well because they are based on Java runtime. So, earlier, Oracle also released updates on Java. So, all the hosts that are under Java or that use GRE, you see here are based on Java. So, if you use Java, there is a CVE in Java and the product they use on runtime is the same CVE. So, that's why you see the same CVEs everywhere that come back on almost all versions. So, there are also patches based on Java. So, Chrome, we already talked about Google that released 230 patches and released a 0D. So, you see here, between the 12D patch, on Chrome version you have 327 patches that were patched. So, it's important to update the browser. We recommend updating the browser as fast as you can. So, as I said earlier, Oracle also updated Java. So, we recommend updating the Java version as fast as you can. And we want to update the version as soon as possible. And we want to update the Java version as fast as we can. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. appreciate it. Thank you. Thank you.