@brancht
Connections already and has always shipped with the secure version of TimThumb. Even more, the attack vector used in the attack well over a year ago is disable in the version that ships with Connections. Please do not use scripts that "updates" TimThumb on Connections.