By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
10alert.com10alert.com10alert.com
  • Threats
    • WordPress ThreatsDanger
    Threats
    A cyber or cybersecurity threat is a malicious act that seeks to damage data, steal data, or disrupt digital life in general. Cyber threats include…
    Show More
    Top News
    The Big Four Banking Trojans- Kaspersky Daily
    1 year ago
    Kaspersky Lab’s Guide to protecting your system from malware during the FIFA World Cup
    1 year ago
    SMS Trojan Bypasses CAPTCHA and Steals Money
    1 year ago
    Latest News
    Patchstack Becomes Member Of Open Source Security Foundation
    14 hours ago
    PDF Phishing: Beyond the Bait
    17 hours ago
    Update ASAP! Critical Unauthenticated Arbitrary File Upload in MW WP Form Allows Malicious Code Execution
    20 hours ago
    Fake CVE Phishing Campaign Tricks WordPress Users Into Installing Malware
    2 days ago
  • Fix
    Fix
    Troubleshooting guide you need when errors, bugs or technical glitches might ruin your digital experience.
    Show More
    Top News
    Missing Sum at Bottom Right Corner in excell (FIX)
    1 year ago
    Windows 10 build 19044.1889 (KB5016616) outs for 21H2, 21H1, 20H2
    1 year ago
    How to reset Windows Update on Windows 11
    1 year ago
    Latest News
    How automatically delete unused files from my Downloads folder?
    10 months ago
    Now you can speed up any video in your browser
    10 months ago
    How to restore access to a file after EFS or view it on another computer?
    10 months ago
    18 Proven Tips to Speed Up Your WordPress Site and Improve SEO | 2023 Guide
    11 months ago
  • How To
    How ToShow More
    A year in recap: Windows accessibility
    20 hours ago
    How to stop, disable, and remove any Android apps — even system ones
    3 days ago
    Bigger, Better, Cooler in a 2U1N form factor
    Bigger, Better, Cooler in a 2U1N form factor
    4 days ago
    Vulnerability in crypto wallets created online in the early 2010s
    5 days ago
    Use Windows 11 features to inspire creativity, speed up everyday tasks
    6 days ago
  • News
    News
    This category of resources includes the latest technology news and updates, covering a wide range of topics and innovations in the tech industry. From new…
    Show More
    Top News
    Set up Threads from Meta app on Windows 11 (two ways)
    5 months ago
    How to set Print Screen key to screenshot with Snip & Sketch on Windows 10
    4 months ago
    How to upgrade Windows 10 to 11 23H2
    3 months ago
    Latest News
    How to disable news feed from Widgets on Windows 11
    18 hours ago
    How to fix performance issues after upgrading to Windows 11 23H2
    18 hours ago
    How to disable updates on Windows 10 Pro and Home
    2 days ago
    Change screen brightness on Windows 11
    4 days ago
  • Glossary
  • My Bookmarks
Reading: Reflecting on 20 years of Windows Patch Tuesday
Share
Notification Show More
Aa
Aa
10alert.com10alert.com
  • Threats
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
  • Threats
    • WordPress ThreatsDanger
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
Follow US
Windows

Reflecting on 20 years of Windows Patch Tuesday

Andra Smith
Last updated: 12 November
Andra Smith 3 weeks ago
Share
9 Min Read

This year marks a very important milestone for the history of Microsoft, the Windows product and for greater computing: 20 years of Patch Tuesday updates. With more than 1.4 billion monthly active Windows devices in service, and billions more devices served along the journey of Windows, our goal is to keep users around the world protected and productive.

Contents
Patch Tuesday’s origin and history2003–20072008–20122013–20172018–PresentOur principle-based Patch Tuesday evolution

In today’s security climate, our work across the company and greater industry to keep this critical ecosystem secure is more important than ever. And while we also ship bug fixes and other new features via continuous innovation, in the end security is job one. Monthly Patch Tuesday updates serve as a vehicle for just that. Created from a 2002 company-wide initiative, Patch Tuesday has become a well-known industry standard, keeping not just Windows but the people, companies and institutions that depend on it protected and productive for 20 years.

In this article, we’ll share a bit on the history of Patch Tuesday and how it continues to evolve through a principle-based approach.

Patch Tuesday’s origin and history

On January 12, 2002, Bill Gates published a company-wide email announcing the creation of the Trustworthy Computing (TwC) initiative. It represented a paradigm shift, pushing security teams to shift their thinking toward securing features themselves across the breadth of our products. From this important initiative, we consolidated our security update process into a predictable cadence of monthly Patch Tuesday updates. Highlights from the 20-year tenure of Patch Tuesdays below show the ongoing evolution of this critical, well-established practice:

2003–2007

  • Patch Tuesday updates begin. They introduce supporting patch management processes, including Windows Update and Microsoft Update services.
  • Windows Vista and later Windows 7 are released. Both incorporate enhanced security features, User Account Control (UAC), Windows Defender and improved firewall capabilities.

2008–2012

  • New out-of-band (OOB) updates address imminent threats like the Conficker worm vulnerability.
  • Security Development Lifecycle expansion provides a robust set of best practices and guidelines for developing secure software.
  • New tools help organizations deploy and assess the status of security updates. These include Windows Server Update Services (WSUS) and the Microsoft Baseline Security Analyzer (MBSA).
  • Windows 8 features improve security measures. We welcome Secure Boot, Windows Defender enhancements and further developments in User Account Control (UAC).

2013–2017

  • Windows 10 is introduced. It represents a fundamental shift towards a “Windows as a service” model. It’s accompanied by the inaugural release of the Windows update history pages, more commonly known as release notes.
  • New security enhancements aim to provide stronger protection against malware, unauthorized access and credential theft. Device Guard, Credential Guard and Windows Hello are developed and released.
  • Windows Update for Business goes live. It allows organizations more control over when and how to deploy Windows updates.
  • The quality and reliability of security updates continue to be the focus of the conversation. “In each new monthly quality update, we add another layer of security, one that tracks emerging and changing trends in malware and viruses” ( John Cable, September 20, 2017).
  • We take proactive steps to bolster transparency and align with General Data Protection Regulations (GDPR). Organizations gain the confidence they need to keep devices up to date.

2018–Present

  • An industry-wide collaboration begins around proactively patching firmware. It follows a public disclosure of Spectre & Meltdown hardware vulnerabilities. Monthly quality updates serve as a tool to expand microcode updates to devices.
  • The use of machine learning optimizes Windows update experiences as proactive measures across Windows updates continue. AI becomes a tool to serve Windows 10 feature updates.
  • Rigor and transparency grow: “The scale and diversity of the Windows ecosystem requires us to take a data-driven approach to quality and to leverage automation for testing, validation and distribution” ( Mike Fortin, former CVP, December 10, 2018). The discussion of quality validation efforts via Patch Tuesday includes the Pre-release Validation Program (PVP), Depth Test Passes (DTP), Monthly Test Passes (MTP), the Windows Insider Program (WIP) and the Security Update Validation Program (SUVP).
  • Windows release health dashboard offers everyone a single pane of glass to view known issues across feature and monthly quality updates.
  • In response to 2020’s COVID-19 emerging pandemic, remote work-related tools receive greater focus. We address vulnerabilities in Remote Desktop Services and Microsoft Teams, as well as extend End of Support for certain active versions of Windows.
  • Known Issue Rollbacks (KIRs) help devices quickly return to a productive state if inadvertently impacted by an update issue.
  • In August 2022, the newly announced safeguard holds with Windows Update for Business deployment service help organizations with rolling out updates.
  • That same year, Unified Update Platform (UUP) on premises is available for commercial organizations as a public preview. Integrated with Windows Server Update Services (WSUS) and Configuration Manager, it simplifies quality and feature update deployment. It hits General Availability in 2023.
  • Windows Autopatch emerges as a growing part of the Patch Tuesday experience.
  • Microsoft launches the Secure Future Initiative across Microsoft to pursue our next generation of cybersecurity protection.

Though there are more highlights and lowlights along that journey, Microsoft remains committed to our mission. Our investments help every individual and organization around the world to achieve more, while staying protected and productive with Windows.

Our principle-based Patch Tuesday evolution

The notions of security and productivity have evolved as drastically as the world of technology. As Brad Smith recently shared in his Nov. 2 blog post A new world of security: Microsoft’s Secure Future Initiative, those efforts are only intensifying. This means great challenges and opportunities for Microsoft’s vision to align on empowering everyone to achieve more through its products, including Windows.

Windows is a critical tool and more important than ever to how folks work and play. We will continue to focus on evolving the update experience. Specifically, we’ve raised the quality of learning, adapting and serving our increasingly diverse customer base around the world, adhering to four principles for the monthly Windows servicing process:

  • Predictability: The Windows monthly release cadence should align predictably to the second Tuesday of every month.
  • Simplicity: Everyone should be able to manage to a simple, regular and consistent patching experience. Doesn’t matter if you’re an individual Windows user or an IT manager overseeing your organization. You shouldn’t need to stop what you’re doing to rigorously test an update before deploying it.
  • Agility: In today’s computing landscape, security threats demand quick responses. We must provide all Windows users with updates quickly without compromising quality or compatibility.
  • Transparency: To simplify the update process for individuals and for businesses large and small, everyone should have access to as much information as they need. You should be able to understand updates in advance. This includes comprehensive yet clear release notes, guides for common servicing tools, access to assistance and a feedback system.

Releasing monthly Windows updates of the highest quality remains critical. Our commitment to improving and evolving Windows patch quality informs efforts and commitment towards quick detection of issues, rapid mitigations, clear and prescriptive communications, and continued learning and improvements. With new hotpatching technologies proving themselves across Azure Fleet and Windows Server Azure Edition, the future for patching is bright as we continue to pursue fast, reliable, secure updates for the best possible update experience. We’re also investing in new AI technology and talent, as well as in leadership and cross-team partnerships, to ensure that we can keep you protected and productive for the next 20 years of Windows.

source: blogs.windows.com

Translate this article

TAGGED: Authentication, Malware, PoC, Security, Social engineering, Software, Threat, Vulnerabilities, Windows
Andra Smith November 12, 2023 November 12, 2023
Share This Article
Facebook Twitter Reddit Telegram Email Copy Link Print

STAY CONECTED

24.8k Followers Like
253.9k Followers Follow
33.7k Subscribers Subscribe
124.8k Members Follow

LAST 10 ALERT

Patchstack Becomes Member Of Open Source Security Foundation
Patchstack Becomes Member Of Open Source Security Foundation
Wordpress Threats 17 hours ago
PDF Phishing: Beyond the Bait
Threats 20 hours ago
A year in recap: Windows accessibility
Windows 20 hours ago
How to disable news feed from Widgets on Windows 11
News 21 hours ago
How to fix performance issues after upgrading to Windows 11 23H2
News 21 hours ago

You Might Also Like

Patchstack Becomes Member Of Open Source Security Foundation
Wordpress Threats

Patchstack Becomes Member Of Open Source Security Foundation

17 hours ago
Threats

PDF Phishing: Beyond the Bait

20 hours ago
Windows

A year in recap: Windows accessibility

20 hours ago
News

How to disable news feed from Widgets on Windows 11

21 hours ago
Show More

Related stories

Several Critical Vulnerabilities including Privilege Escalation, Authentication Bypass, and More Patched in UserPro WordPress Plugin
BridesMaid – neuron writes toasts For those very occasions when you need to give out a powerful
The other day Yandex pleased us with the announcement of a new Midi station – an excellent reason to listen
REMIX – remixes of pictures from neural networksCreate, share and correct works
How to download Diablo IV for free and absolutely legallyBlizzard has opened a free
Rostelecom employees were forced to abandon Android and iOS in favor of Aurora.
Previous Next

10 New Stories

Update ASAP! Critical Unauthenticated Arbitrary File Upload in MW WP Form Allows Malicious Code Execution
Fake CVE Phishing Campaign Tricks WordPress Users Into Installing Malware
How to disable updates on Windows 10 Pro and Home
How to stop, disable, and remove any Android apps — even system ones
Patchstack Alliance Bounty Program Events for December
Your Smart Coffee Maker is Brewing Up Trouble
Previous Next
Hot News
Patchstack Becomes Member Of Open Source Security Foundation
PDF Phishing: Beyond the Bait
A year in recap: Windows accessibility
How to disable news feed from Widgets on Windows 11
How to fix performance issues after upgrading to Windows 11 23H2
10alert.com10alert.com
Follow US
© 10 Alert Network. All Rights Reserved.
  • Privacy Policy
  • Contact
  • Customize Interests
  • My Bookmarks
  • Glossary
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?