Category
Applications (applications-patches)Windows Update third-party software coverage is the gap almost nobody has looked at. Windows Update updates Windows. Every other program on that computer updates itself, gets updated by a person, or does not get updated at all.
Count What Is On Your Computer →
Two minutes. It reads your computer and counts. It changes nothing, and there is no credit card.
The problem: Owners believe updates are handled, because something on the screen says updates are handled. Windows really does keep itself current, and it says so, in a green checkmark. What it does not say is that it is speaking only for itself.
What it actually feels like: Not fear. A small, specific irritation. You have a sense that there is software on those computers nobody has thought about in years. And no way to turn that sense into a list without asking somebody and hoping they answer well.
The straight answer: This is a counting problem before it is a security problem. You do not need to become an expert. You need a number, and three smaller numbers underneath it, and then you can decide what is worth doing.
Hey folks! I want to walk you through the most boring important story of the week, because boring is exactly why it works.
PaperCut makes software that counts and controls printing. If you have ever tapped a card on a copier at a law office or a school to collect your printing, that was probably PaperCut or something like it. The company says a hundred million people use it. That is their own marketing number, and I will label it as such, but nobody disputes that the thing is everywhere.
On Thursday, August 27, PaperCut published an urgent advisory. Their words: “We are aware of confirmed customer incidents and are treating this matter with the highest priority.” In plain words, that means people are already inside. They shipped an emergency patch the same day.
Here is the part I want you to think about. Researchers at Huntress and watchTowr went and looked at that patch, and found ways around it. So on Friday, August 28, PaperCut shipped Emergency Patch Release 2. In their own words, it “includes additional hardening beyond the original emergency patch,” meaning extra protection the first fix did not have. Then on Monday, August 31, CISA, the US government’s cybersecurity agency, added both flaws to its list of bugs criminals are already using. That is the government’s way of saying this one is real.
Two flaws, chained together. The first, CVE-2026-81578, rated 8.8, lets somebody get past the login without one. The second, CVE-2026-82078, rated 9.4 out of 10, lets them run their own code on your server. Put them end to end and a stranger on the internet owns the machine.
Versions 24, 25 and 26 got patched, twice. Version 23 and anything older got nothing, because there is nothing coming. PaperCut’s instruction for those is to upgrade to a supported version. Two customers of Huntress were being actively broken into while all this was going on.
That is not really a print server problem. It is a Windows Update third-party software problem, and the print server is just where it showed up. This is also the second time for this product. In 2023 the Clop and LockBit gangs used a pair of PaperCut holes as their way into corporate networks. The criminals know perfectly well that this is the kind of software nobody watches.
So let me name the thing we are actually fighting here, because it is not the criminals and it is not PaperCut.
It is the program nobody owns.
Every business has a few. It arrived years ago for a perfectly good reason, it did its job, and then whoever installed it moved on to something else. It is not on anybody’s list, because there is no list. It does not misbehave. It does not slow anything down. It never asks for a thing. It just sits there quietly going out of date, and then one Thursday it turns out to be the way in.
Sources: PaperCut security advisory and Emergency Patch Release 2 notes, August 27 and 28, 2026; reporting by BleepingComputer, Help Net Security, The Hacker News, SecurityWeek and Rapid7.
Now forget PaperCut, because PaperCut is just an example. If you do not run it, do not relax.
Here is the thing almost nobody has ever been told plainly. Windows Update updates Windows. That is the whole job. Microsoft ships fixes for Windows, Office and Edge, and has never claimed to do more.
So the honest answer on Windows Update third-party software is that there is essentially none. Every other program on that computer is on its own. Some update themselves quietly and do a decent job of it. Some pop up a box, and somebody clicks “remind me later” for fourteen months. Some never check at all.
Think about what is actually sitting on the machines in your business.
Not one of those is Microsoft’s problem. Every one of them is a door.
Before you read the next sentence, pick your number. How many programs do you think are running on the computer in front of you right now? Say it out loud or write it in the margin, but commit to it first, because the guess is the whole point.
Ask a room of business owners how many programs are on their computer and you will hear eight. Maybe twelve. Then you count, and the real number is usually somewhere between forty and eighty. That gap, between what people believe is on the machine and what is really on it, is the whole problem. Nobody is neglecting the list. There is no list. Whatever gap just opened between the number you picked and the real one, that is not a measure of how well you run your business. It is the size of the thing nobody was assigned.
And I want to be careful not to overstate this. Most of those programs are perfectly current, most of the time. The point is not that your computers are a disaster. The point is that you do not know, and neither does anybody else, and “probably fine” is not something you would accept about the money your customers owe you.
This week handed us a clean example of something I usually have to explain with my hands, so let me use it while it is fresh.
PaperCut version 24 and up were behind. There was a fix, it arrived, and then a better fix arrived the next day. Annoying, urgent, and entirely solvable. Somebody applies it and the problem is over.
PaperCut version 23 was no longer supported. Past the end of its life. There is no patch, there will not be a patch, and no amount of care or effort produces one. The only move is to replace it, which costs money and takes planning and probably breaks something else on the way.
They are two different problems with two different budgets, and businesses get into trouble because nobody ever separated them.
“Behind” is a repair job. Somebody should be doing it every week, and if they are, you will never hear about it again. “No longer supported” is a business decision, with a number attached, that belongs to you and not to whoever handles your computers. Nobody can make that one on your behalf, and a lot of businesses are carrying several of them without ever having been shown the list.
The reason I keep repeating this is that the second group is where the expensive weeks come from. A program that is behind can still be fixed today. A program with no updates left stays open to attack until you spend money to replace it, and it will still be open next year unless somebody decides otherwise.
And here is what that failure actually costs. It is almost never the computer you would have picked. It is the one machine your whole week depends on, running a program nobody was ever assigned. The one that prints the labels, or prints the invoices, or runs the machine out on the floor. It stops on a Thursday with the orders still sitting inside it. That is the morning you find out how much of your business was standing on it.
So the question was never whether your computers are fine. It is which one of them you could not run a week without, and when anybody last actually looked at it.
My father fell for a phishing email.
Mine. The man who has spent more than thirty-five years in cybersecurity and trains members of InfraGard, the FBI’s security partnership program. My own dad clicked the thing and gave scammers remote access to his computer, and they went straight to work hunting for his financial documents.
My step-mother noticed something was off and called me. I got in remotely and stopped them before they found the spreadsheet with all the bank credentials on it. We were lucky. We caught it in time.
What has stayed with me is not the scam. It is that I had never once looked at what was actually installed on his machine. I could have. I know how. I just assumed, the way everybody assumes, that a computer that seems to be working is a computer that is being maintained.
That is the whole reason ForwardToSafety exists. I asked myself what I would build if the person I was protecting was my own father, and the first answer was not a firewall. It was a list.
Maybe they do. Plenty of them are good, and I am not going to criticize an industry I have worked in since 1991.
But notice what that sentence is. It is a belief, not a document. And there is one question that turns it into a document, which is why I ask people to go and ask it.
“Can you send me the list of every program on our network that Windows Update does not touch, and when each one was last updated?”
What happens next tells you almost everything. Some send it inside the hour, because their tooling produces it on demand and they have been doing this properly all along. Some ask what you mean. Some do not reply for a week.
And here is the part that trips up good, careful operators. You did the responsible thing. You hired somebody so this would not be your job, and it was reasonable to then stop thinking about it. That is what hiring somebody is for. The gap is not that you were negligent. It is that nobody ever gave you the one piece of paper that would show you whether it is working, so you have been paying the bill and guessing.
Two things can be true at once. You can be running a very good business, and you can also have no way of knowing whether the software on your computers is current. Neither one says anything about you.
And to be fair to your provider: if they are doing this well, the list makes them look excellent, and they will be glad you asked. The only person who dislikes this question is the one who cannot answer it.
You do not have to take my word for any of this, and you do not have to wait for anybody to get back to you. You can go and find out in about two minutes, on the computer you are reading this on.
That is what our Reveal Scan does. It reads one computer and it writes you a sentence. It looks like this:
“We examined 68 things on this computer. 54 are current. 11 need updating. 3 are no longer supported at all.”
An example of the sentence it writes. Your numbers are your numbers.
Four numbers. The first makes it a measurement rather than an opinion. The second is the one nobody expects, because most of your software is fine and the report says so clearly. The third is a maintenance job. The fourth is the business decision.
What it does not do, so there are no surprises. It does not fix anything. It does not install anything. It does not change a setting or a file or move anything around. It reads, it counts, and it tells you. That is deliberate: I would rather give you a result you can act on however you like than have you feel pushed into something.
And this part is new. It used to be one computer, one run. Not anymore. Run it on your own computer. Run it on every computer in the building. Run it again next month, and the month after that. There is no credit card and no cap on how many times you use it.
Which matters more than it sounds, because this is not a one-time photograph. Software goes out of date on its own timing, not yours. The number that comes back healthy in September will have drifted by Christmas, and the only way to know is to count again.
And yes, I hear it. A security guy is asking you to click a link and run a scan on your computer. You are absolutely right to pause, because I tell people to pause every single week. So do the thing I would tell you to do with anybody else: look at the address bar. It only ever says forwardtosafety.com. If you want a human being to confirm we are who we say we are before you go any further, reply and you will get one.
Two minutes. Read only. No credit card.
Let me say back to you what I think you already believe. That there is software on your computers nobody has thought about in years. That you could not name half of it if I asked. And that this has been somewhere in your mind for a while, on the list of things to do later.
If that is roughly right, you are not behind. You are exactly like nearly every owner I talk to, including a fair few who pay somebody good money to handle it. The uncomfortable part was never that something is broken. It is that you have had no way to check, and checking has felt like it would require becoming a different kind of person.
It does not. It requires two minutes and a number.
Run the scan first, and run it this week. Labor Day is next Monday, and once September gets going, nobody I know has a spare two minutes until October. Nothing here expires and nothing is running out. Your calendar just gets worse. If the numbers come back healthy, you have answered a question that has been quietly using up your attention, and you owe me nothing for it. Run it and never speak to me again, and that is a fine outcome. I mean that.
If they do not come back healthy, you now have a specific list instead of a vague worry. Hand it to whoever handles your computers and ask what they intend to do about it. That is a much better conversation than the one you would have had yesterday.
For plenty of people the number is the whole job, and stopping there is a good outcome. If you would rather not manage that list at all, that is what Support & Defend is for. We patch what Windows Update never touches, watch your systems day and night, act when something goes wrong, and answer the customer’s security questionnaire when it arrives. It is my company, so if you book time you are talking to the owner and not a salesperson.
Already know you want to talk it through instead? Book fifteen minutes with Craig.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
Join thousands of security professionals who receive Craig Peterson's Insider Show Notes and cybersecurity updates.
Patch management is the process of identifying, acquiring, distributing, and installing software updates, known as patches, to fix security vulnerabilities or technical issues in systems. It is essential for maintaining network security and improving system performance by ensuring that software is up-to-date and compliant with regulations.
Join 10,000+ cybersecurity professionals