In this article
Few messages are dismissed as often as “An update is available.” Yet keeping software current is one of the simplest and most effective things anyone can do to stay safe online.
Key facts
- 20% of breaches studied in Verizon’s 2025 Data Breach Investigations Report began with attackers exploiting a software flaw.
- 34% rise in that type of attack compared with the previous year’s report.
- Credential abuse, such as stolen passwords, remained slightly more common at 22%.
- Automatic updates remove most of the effort for home users.
Why updates fix security holes
All software contains mistakes. Some mistakes let an attacker run their own code, read data or take control of a device. When developers discover such a flaw, they release a fix, called a patch. Until the patch is installed, the flaw stays open.
The race after a patch is published
Once a fix is public, criminals can study it to understand the weakness and then target people who have not updated. The days after an important update are therefore a period of higher risk, not lower. Some flaws are exploited before any fix exists; these are called zero-day vulnerabilities, and they are one more reason to install fixes as soon as they appear.
The trend is clear in Verizon’s 2025 Data Breach Investigations Report, one of the largest annual studies of real incidents. Exploiting vulnerabilities was the first step in 20 percent of breaches, up 34 percent on the year before, with many attacks aimed at internet-facing equipment such as VPNs and firewalls.
| How breaches started | Share of breaches |
|---|---|
| Credential abuse (stolen or guessed passwords) | 22% |
| Exploiting a software vulnerability | 20% |
The top route, stolen passwords, is best blocked with two-factor authentication. The second is best blocked by updating.
Why Two-Factor Authentication Matters for Every Account
More than security
- Updates improve speed, battery life and compatibility with new websites and devices.
- Older versions eventually stop receiving support at all. After that date, any new flaw stays open forever, so plan to replace devices and software that have reached end of support.
How to make updating painless
- Turn on automatic updates for your operating system, browser and main apps.
- Restart regularly. Many updates only take effect after a restart.
- Update routers and smart devices too. Check the manufacturer’s app or website; these are often forgotten.
- Only download updates from official sources. A pop-up on a website saying you must install an update is a common trick; see our guide to recognizing phishing.
- Remove apps you no longer use. Fewer programs means fewer things to keep updated.
For businesses: organizations often test updates before rolling them out, to avoid breaking important systems. That is sensible, but critical security fixes, especially for internet-facing equipment, should be prioritized and applied within days, not months.
How long devices receive updates
Every device eventually stops receiving security updates. Knowing the date helps you plan a replacement before you are left unprotected.
| Product | Update support |
|---|---|
| Windows 10 | Free support ended on 14 October 2025; paid or enrolled Extended Security Updates run to October 2026 for home users |
| Google Pixel 8 and later | Seven years of Android and security updates from release |
| Samsung Galaxy S24 and later flagships | Seven years of Android and security updates |
| Apple iPhone | No fixed promise; recent models have typically received updates for six years or more |
What “end of support” really means
When software reaches end of support, the developer stops releasing fixes. The software keeps working, which is why many people keep using it, but every new flaw discovered after that date stays open permanently. Attackers know this and specifically target old systems.
A simple rule: if a device or program you use for banking, email or work no longer receives security updates, plan to replace or upgrade it. For older phones and laptops that still work well, you can reduce risk by using them only for low-risk tasks.
Frequently asked questions
Should I wait a few days before installing updates?
For most people, no. The risk from attackers exploiting a known flaw is usually greater than the small risk of an update causing a problem. Businesses with critical systems may test first, but should still move quickly.
Are automatic updates safe?
Yes, when they come from the operating system or the app store. Be suspicious of update prompts that appear inside web pages or emails.
What should I do with a device that no longer gets updates?
Replace it if possible, or at least stop using it for banking, email and shopping, and never expose it directly to the internet.



