you are viewing a single comment's thread
view the rest of the comments
[–] [S] 41 points 2 years ago (4 children)

In an enterprise environment, you rely on a service that tracks CVEs, analyzes which ones apply to your environment, and prioritizes security critical updates.
The issue here is that one of these services installed a release upgrade because Microsoft mislabelled it as security update.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 12 points 2 years ago (3 children)

    Should still be doing phased rollouts of any patches, and where possible, implementing them on pre-prod first.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 11 points 2 years ago*

    Pre-prod is ideal, but a pipe dream for many. Lots of folks barely get prod.

    We still stagger patching so things like this only wipe some of the critical infrastructure, but that still causes needless issues.

  • source
  • parent