GCSE · Computer Science · AQA · Spec 8525

Automatic software updates

A free replacement lock arrives for a faulty one. Whose door is still easy to open? The one where it's still in the envelope.

Computer Science · Cyber security

Protected, or still exposed?

An attacker targets a weakness in the software. Is this system protected, or still exposed?

Still to sort

Protected against this attack (0)

The weakness is known, a fix exists and the fix has been installed.

Where the line is: Protected needs all three: known, fixed and installed. Miss any one and it belongs in the other column.

Still exposed (0)

There is no fix yet, or there is a fix that has not been installed.

Where the line is: A fix that exists but is sitting uninstalled protects nobody.

6 of 6 still to sort.

Six systems, six attacks. Decide each one before you read why.

Why it works

?

Reason it through

Why do automatic updates mean a system spends less time open to attack?

Link 1 of 4

First link · your turn

A weakness in a program is found. What does the developer release to deal with it?

2
Locked — reveal the link above first
3
Locked — reveal the link above first
4
Locked — reveal the link above first

Predict, then check

Anti-malware software also gets updates. Different job, same idea.

A piece of malware has only just been identified. Computer A's anti-malware has had its definitions updated since. Computer B's has not. What would you expect?

Judge it

Should automatic updates always stay on?

The claim

An organisation should always leave automatic updates switched on.

Place each piece of evidence to load the balance. Mark the strong ones — they count double.

  1. Known vulnerabilities are closed as soon as a fix is released.

    Evidence 1: does it support or challenge the claim?
  2. Nobody has to remember or choose to update, so protection does not depend on every user.

    Evidence 2: does it support or challenge the claim?
  3. Systems that are not kept up to date stay exposed to attacks on weaknesses that were already fixed.

    Evidence 3: does it support or challenge the claim?
  4. An update may occasionally cause compatibility problems.

    Evidence 4: does it support or challenge the claim?
  5. An update may require a restart.

    Evidence 5: does it support or challenge the claim?

WHAT YOU'VE LEARNED

A quick recap of today's lesson.

What you need to know

  • A vulnerability is a weakness or bug in software that an attacker or malware could exploit to reach a system or its data.
  • A software update, also called a patch, fixes security vulnerabilities.
  • Have a goDan says a patch is just something that slows your laptop down. In one line, what is a security patch actually for?

    It fixes a vulnerability, a weakness or bug an attacker could exploit.

    A patch is the fix, and the vulnerability is the weakness it closes.

  • Automatic updates download and install the developer's updates without the user having to start the process.
  • They close known vulnerabilities as soon as a fix is released, so the system runs vulnerable, unpatched software for less time.
  • They also remove the reliance on users remembering or choosing to update.
  • Have a goThe developer releases a fix on Monday. Your cousin will 'get round to it eventually'. With automatic updates on, who has to start the install?

    Nobody. It downloads and installs without the user starting it.

    That is why the protection no longer depends on your cousin remembering or choosing to update.

  • Updating anti-malware keeps its database of known malware definitions (signatures) current, so newly identified malware gets recognised and removed.
  • A system that is not kept up to date stays exposed to attacks on vulnerabilities already publicly identified and fixed.
  • Limit: an automatic update cannot protect against a vulnerability the developer has not yet discovered or fixed.
  • Have a goMaya says: 'Automatic updates are on, so no attack can get in.' What is missing from her reasoning?

    A fix can only exist for a vulnerability the developer has discovered and fixed.

    An update cannot protect against a vulnerability the developer has not yet discovered or fixed.

  • Updates may occasionally cause compatibility problems or need a restart, so some users and organisations delay or disable them.

The big picture

Automatic updates install the developer's fixes without the user having to start anything, which closes known vulnerabilities as soon as a fix is released. That protects a system only against weaknesses that are known, fixed and installed. It cannot help with a vulnerability the developer has not found yet.

Key points

1An update only protects a system once it is installed.
2Automatic updates install fixes without the user starting the process, so protection no longer depends on users remembering or choosing to update.
3They close known vulnerabilities as soon as a fix is released, shortening the time a system runs vulnerable, unpatched software.
4Updating anti-malware keeps its signatures current so newly identified malware can be recognised and removed.
5No automatic update can protect against a vulnerability the developer has not yet discovered or fixed.

Worked example

Problem

A school's computers were attacked through a weakness the developer had fixed and published months earlier. Explain how automatic updates could have prevented this.

⚠ Watch out

Believing that updates make a system safe from everything, or that they are optional extras. Updates fix known vulnerabilities. A system left unpatched stays open to weaknesses that are already fixed, and no update can protect against a weakness the developer has not yet found.

🧠

Memory hook

Known, fixed, installed: miss any one and the door is still open.

✓

Check yourself

Both computers have automatic updates on. Which attack did the update likely stop: a weakness fixed last year, or one nobody has found yet? Why?

Flashcards

(9)
What is a vulnerability?
A weakness or bug in software that an attacker or malware could exploit to gain access to a system or its data.
What does a software update (patch) do for security?
It fixes security vulnerabilities.
What makes an update 'automatic'?
The operating system or application downloads and installs the developer's updates without the user having to start the process.
How do automatic updates reduce risk?
They close known vulnerabilities as soon as a fix is released, so the system runs vulnerable, unpatched software for less time.
What reliance do automatic updates remove?
Reliance on users remembering or choosing to update.
Why do anti-malware programs need updates?
Updates keep the database of known malware definitions (signatures) current, so newly identified malware can be recognised and removed.
What happens to a system that is not kept up to date?
It stays exposed to attacks on vulnerabilities that have already been publicly identified and fixed.
What can an automatic update never protect against?
A vulnerability the developer has not yet discovered or fixed.
Why do some users and organisations delay or disable updates?
An update may occasionally cause compatibility problems or require a restart.

Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.

Learning with Lightbulb is opening soon

You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.

Keep me posted

More AQA GCSE Computer Science topics

See the full AQA Computer Science curriculum →

How this lesson was checked. This AQA GCSE Computer Science (specification 8525)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 9 October 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.