惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
D
Docker
GbyAI
GbyAI
Y
Y Combinator Blog
Google DeepMind News
Google DeepMind News
G
Google Developers Blog
P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
雷峰网
雷峰网
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Stack Overflow Blog
Stack Overflow Blog
WordPress大学
WordPress大学
小众软件
小众软件
Engineering at Meta
Engineering at Meta
酷 壳 – CoolShell
酷 壳 – CoolShell
I
InfoQ
B
Blog
H
Help Net Security
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 聂微东
The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
B
Blog RSS Feed
Microsoft Security Blog
Microsoft Security Blog

The Register - Software: OSes

Fedora: Microsoft is all aboard, but Deepin is dumped Microsoft promises to do better, but it has a long way to go First big Microsoft update after vow to 'win back fans' Who needs ghost train scares when Windows is such a fright? Microsoft boss tells investors the company is working to 'win back fans' Microsoft boss says company is working to 'win back fans' Linux cryptographic code flaw offers fast route to root Fedora 44 is out – countless versions of it Microsoft sets its sights on the past with 86-DOS and PC-DOS Microsoft updates the Windows Update Experience Windows second-chance setup hurts IT, productivity Ubuntu Resolute Raccoon drops Xorg, keeps X11 apps alive More ancient Linux device support facing the ax WSL9x hacks Linux into ancient Windows 9x systems UK tribunal sends £2B claim accusing Microsoft of overcharging for licensing to trial Zorin OS 18.1 released - and the Lite edition reappears Task Manager's CPU%: an obituary for the recent past Linux 7.1 will have an optional new NTFS driver Microsoft releases Windows Server update to fix April update 20-year-old Enlightenment E16 bug finally gets patched 20-year-old Enlightenment E16 bug finally gets patched Raspberry Pi OS ends open-door policy for sudo Firefox Nightly adds Web Serial after years of saying no Windows Update: Torture chamber for seldom-used PCs Windows Update: Torture chamber for seldom-used PCs Notepad loses Copilot icon as Microsoft gives subtlety a try Notepad loses Copilot icon as Microsoft gives subtlety a try Microsoft attempts to untangle Windows Insider program Adobe finally patches PDF pest after months of abuse NHS pays £46K to prep next Microsoft licensing round
Hotpatching goes default in Windows Autopatch whether you...
2026-03-11 · via The Register - Software: OSes

From the department of "what could possibly go wrong?" comes news that Windows Autopatch is enabling hotpatch security updates by default.

The change starts with the May 2026 Windows security update, and controls to opt out will be available from April 1.

According to Microsoft, the company has "changed the game" with the launch of hotpatch updates. The feature installs security updates without requiring a restart, meaning changes take effect immediately. The process does require one baseline update with a restart to kick things off. However, after that, hotpatch updates install silently, with no reboot needed. That said, every quarterly baseline update still demands a restart.

Windows Autopatch manages the rollout of updates across an organization. It uses "testing rings" – sample device groups – to roll out updates progressively and halt or reverse them if problems emerge.

Enabling hotpatch by default from May 2026 won't override existing policies. Microsoft states that "Windows Autopatch respects your configuration of quality update policies," meaning update deferrals and ring settings still apply.

However, on any device that meets the prerequisites (running Windows 11 24H2 or later, using an eligible license, and with the April 2026 security update installed), hotpatch updates will start rolling in automatically.

Microsoft's recommendation is, unsurprisingly, to leave hotpatch updates enabled. It argues that "hotpatch updates are the quickest way to get secure."

Administrators who need more time before the change happens (less than two months isn't a lot of notice) or want to stick to the previous patching method can opt out at the tenant level or via a policy for a group of devices.

Microsoft has had a rocky start to the year on the update front. Its ring-based deployment strategy does not limit the blast radius when something goes wrong, and making hotpatching the default adds another variable that could produce unexpected consequences.

Administrators who prize tight control over their environments won't love this change, which makes the tenant-level and policy-level opt-outs genuinely welcome additions. The compressed timeline is harder to defend. ®