It’s time to install most of July’s Windows and Office patches

With one glaring exception, July was a rather benign patching month. The Win10 versions got their usual two cumulative updates (the second considered “optional”). Visual Studio had some hiccups, but they’re fixed now.

Folks trying to upgrade from Windows 10 version 1803 or 1809 to 1903 encounter various problems, but for now there’s very little reason to push your machine onto 1903. We’ll be talking a lot more about that later this month.

When Win7 Security-only patches aren’t

The big pimple on the patching butt this month: The Win7/Server 2008 R2 “Security-only” patch. Without any warning or explanation from Microsoft, the July “Security-only” patch installs a full telemetry kit and hooks things up so information gets sent to Microsoft – precisely what most people are trying to avoid by taking the “Security-only” route.

We have late-breaking confirmation from Windows guru @abbodi86 that the July Security-only patch installs the same kind of telemetry found in the Monthly Rollups. Many (dare I say “all”?) of the folks who go to the bother of downloading and manually installing the Security-only patches specifically do so to avoid the snooping. But if you want the July security fixes, telemetry comes along for the ride.

Fortunately, there are ways to circumvent the telemetry, or at least minimize it. Details following.

McAfee Endpoint Protection conflicts – maybe

Again this month there are questions about McAfee Endpoint Protection’s interaction with Windows updates. Kevin Beaumont (@GossiTheDog) kicked off the latest round of suspicion and vituperations by posting:

