Microsoft silently fixes security holes in Windows 10 – dumps Win 7, 8 out in the cold


PS. Also run a custom-built kernel with non-standard configuration and make sure the kernel images, build tree, copies of the config, etc are not available to a potential attacker. This makes targeting a kernel exploit against you significantly harder in most cases, and if you have proper response to kernel panics/oopses it means the attacker only gets one shot.

This is one of the situations where you actually have a security advantage by running an OS you have the source for.

