Welcome back. The Ridge took a few weeks off while the day job got loud. Back on schedule, and shorter from here on, which is probably an improvement.

The Big Story: the number went up. The work didn't.

Last month I told you Microsoft patched about 400 vulnerabilities and that, for a business your size, it came down to roughly three things to do.

This month Microsoft patched somewhere around 970. Biggest Patch Tuesday in the company's history, more than double August, and by one researcher's count they've now fixed more vulnerabilities this year than in the previous two years combined.

Here's the honest read on why: Microsoft has been pointing AI tools at its own code to find bugs, and the tools are good at it. So the number is exploding because they're finding more, not because the world suddenly got more dangerous. Expect the headlines to keep getting scarier while your actual risk stays roughly where it was. That gap is going to be exploited by people selling things. Now you know.

Two of this month's bugs were being used in real attacks before the fix existed. Both are the same type as August's: an attacker who is already on the machine uses them to take full control of it. Neither one lets anybody in the front door. They make a break-in worse, which is exactly why attackers value them and exactly why the fix matters.

About 970 patches. Two were actually being exploited.

What to do: let Windows Update run, and reboot when it asks. That's the entire response to the biggest patch release in Microsoft history.

There were also some genuinely alarming-sounding ones in Exchange Server and Remote Desktop. If your email is in Microsoft 365 or Google Workspace, and nobody at your company remotes into an office server, those do not apply to you. If you're not sure whether they apply to you, that uncertainty is worth resolving once, permanently. Reply and ask.

We'd Tell You If You Needed Us

Two issues in, you may notice a pattern: the answer keeps being "install the updates and restart."
That's not me running out of material.

That's what the data actually says. The businesses that get hurt are almost never the ones who missed some exotic vulnerability. They're the ones where updates sat pending for four months, or six people shared one login, or a former employee's account still worked.

Boring, unglamorous, free. That's the whole job most weeks.

So: this week's list is one item long. Reboot your computers.

See you in two weeks.

Forwarded this? Subscribe here — practical security for small businesses, every other Tuesday.