The patch that closes the door attackers are already walking through.
Section 01Keep the door shut
Security software gets the headlines — the antivirus suites, the VPNs, the password managers — but the single habit that does the most to keep a computer safe is considerably less exciting: keeping software up to date. Not because updates are fun, but because the alternative is leaving known holes open, and attackers exploit known holes constantly.
Here is why that matters. When a vulnerability is discovered in a piece of software — a browser, an office suite, a media player — the developers patch it and publish a new version. Publishing the fix also, inevitably, signals that the flaw exists. Security researchers write it up. CVE databases log it. Sometimes proof-of-concept code follows within days. Anyone looking for a way in now has a map.
The window between a patch being released and a user installing it is exactly the window attackers care about. Running an outdated version of Firefox, LibreOffice or VLC is not a neutral act; it is an invitation to vulnerabilities that are already documented, sometimes with working exploit code available. This is why security professionals talk about "patch cadence" with as much seriousness as they talk about firewalls.
The same logic applies to open-source software as to proprietary software — sometimes more visibly. Because the source code is public, a committed fix in a repository is readable by anyone. The diff between a vulnerable version and a patched one can be reverse-engineered to reconstruct the original flaw. Open development has real advantages around trust and auditability, but transparency cuts both ways when a user has not yet updated.
Operating systems, browsers and popular applications are the highest priority because they have the largest attack surfaces and the most determined adversaries. Mobile operating systems are increasingly aggressive about pushing updates for exactly this reason. On the desktop, automatic updates — where available and trusted — remove the human delay from the equation. Where they are not available, checking periodically and applying updates promptly is the discipline that matters.
The principle extends to dependencies and plugins. A fully updated browser running an ancient plugin is not a fully updated browser. Thunderbird with an outdated add-on, or any application relying on an unpatched library, inherits the vulnerability. The chain is only as strong as its oldest link.
None of this is glamorous. There is no dashboard, no score, no notification that says "you are now protected." The protection is negative space — the attack that found no foothold and moved on. That is precisely why updating tends to be underrated: it works by preventing things that never visibly happen.
The most important security tool is already built in. Use it.

Key facts · the words used here
- CVE
- Common Vulnerabilities and Exposures; a public catalogue of known security flaws
- patch cadence
- how regularly a project releases security fixes
- attack surface
- the total set of points where an attacker could try to gain entry
- diff
- a file showing line-by-line changes between two versions of source code
- proof-of-concept code
- working code that demonstrates how a vulnerability can be exploited
Free Software Foundation
Referenced in this piece
organisation that promotes software freedom and publishes the GPL family of licences
Programs and organisations are named as examples, not recommendations. Where we link, we link the official project page. The desk hosts no files and ranks no vendors.
