Microsoft released five security bulletins as part of its June 2013 Patch Tuesday updates yesterday, and while the bulletin count is one of the lowest released by the software titan in recent memory, experts recommend applying them straight away.
Users, and particularly organizations, are advised to download and apply the patches as soon as possible to protect themselves and their networks against cyberattacks.
Gelo Abendan of Trend Micro believes that there is no reason to wait and delay the updating of systems, as hackers from the group Anonymous are said to be readying up to launch OpPetrol on June 20 — an attack targeting organizations around the world:
“Some users may take this few bulletins lightly and delay updating their systems with these fixes. However, now is not the right time to be lax security-wise (there’s actually no ‘right’ time to be lax when it comes to security).
Such attacks usually exploit vulnerabilities to penetrate their targets’ networks, usually to get more information which they can use to further harm their victims. Every little vulnerability can be taken against you, thus it is important to guard your systems from attacks.”
Another security firm, GFI Software has also issued similar guidance to organizations.
Their new report particularly highlights the fact that the Internet Explorer vulnerability that was recently patched by Microsoft can (and probably will) be exploited for phishing attacks. According to Cristian Florian, the product manager at GFI Software:
“Phishing attacks look to exploit software vulnerabilities, whether it is a Microsoft or third-party application, and it is therefore important to deploy all critical patches for any affected software.
However, with every update there is a chance that things can go wrong, and it is important that businesses ensure their Patch Tuesday doesn’t turn into a Crash Wednesday once all patches have been deployed and employees restart their machines.”
As always users are recommend to apply the latest patches via the Windows Update tool. Organizations, on the other hand, are advised to deploy these patches after testing their impact first — particularly those involving server side updates.