Originally posted here by karmine
the way i look at it, linux is less prone to virii, script kiddies, and the lot. even if script kiddies could compromise your security, what could they do....sit on your box for an hour reading their "linux for dummies" book while you sit there knowing youve been broken into wait for the next move?
http://en.wikipedia.org/wiki/Security_through_obscurity

Just because linux is "indie" doesn't make secure, you still have to update it like everyone else. This discussion would still apply regardless of the OS.

Back on track...
Get your patches from the official source, in your case the windows update site. You can't get it a more trustworthy way unless they mail you an update CD.