Eye on Microsoft: Windows (In)Security in the News
- Dr. Roy Schestowitz
- 2009-04-24 10:24:19 UTC
- Modified: 2009-04-24 10:24:19 UTC
●
Windows Trojan That Infected Over 3.6 Million PCs Evolves with Worm Behavior
One of the top families of malicious code targeting the Windows platform has evolved with the addition of worm behavior, Microsoft warns. According to data made public via the Microsoft Security Intelligence Report, the Win32/Vundo Trojan infected over 3.6 million computers in the second half of 2008, and occupies the third position in a malware ranking behind Renos and Zlob. Vundo is a family of malware with various components that are designed to serve victims 'out of context' pop-up advertisements following infection. Microsoft warns that the Vundo family of malicious software can also
be used to download and execute arbitrary files.
●
One bot-infected PC = 600,000 spam messages a day
TRACElabs concluded that Rustock and Xarvester, the latter perhaps linked to the down-and-out Srizbi botnet, are the most efficient spam spewers of the nine bots. Each is capable of sending up to 25,000 messages per hour, or 600,000 per day, and 4.2 million per week.
●
Updated research of the largest base of real-world vulnerability data
4. Exploitation - Eighty percent of vulnerability exploits are now available within single digit days after the vulnerability’s public release. In 2008, Qualys Labs logged 56 vulnerabilities with zero-day exploits, including the RPC vulnerability that produced Conficker. In 2009, the first vulnerability released by Microsoft, MS09-001 had an exploit available within seven days. Microsoft’s April Patch Tuesday included known exploits for over 47 percent of the published vulnerabilities. This law had the most drastic change from the Laws 1.0 in 2004, which provided a comfortable 60 days as guidance.
Recent Techrights' Posts
- Writing and Coding Isn't Always Enough
- Last year we had to assume a role we didn't have before: litigants
- Autumn Has Come
- Autumn should be exciting in all sorts of ways; it'll also mark our anniversary
- IBM Has Taken Control of GNOME
- Don't expect a successor to be found any time soon
-
- Links 01/09/2025: Fresh Backlash Against Slop and "Norway’s Electricity Crisis is About to Hit Britain"
- Links for the day
- Links 01/09/2025: Catching Up (Mostly via Deutsche Welle), "Windows TCO" Effect in UK
- Links for the day
- Gemini Links 01/09/2025: Linguistic Barriers and "Web 1.0 Hosting"
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, August 31, 2025
- IRC logs for Sunday, August 31, 2025
- The UEFI 9/11 - Part IV - External Interference
- They all seem to be playing a role in crushing Software Freedom and self-determination for users
- Links 31/08/2025: Baggage Claim Scams, an Insurrectionist’s War on Culture, and a Sudden Robotics Hype
- Links for the day
- Gemini Links 31/08/2025: Reviewing Netsurf and Slightly Less Historic Ada Design
- Links for the day
- Links 31/08/2025: Google Gmail Data Breach and LF Puff Pieces for Pay
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Saturday, August 30, 2025
- IRC logs for Saturday, August 30, 2025
- This is What Google News Has Become
- Moments ago
- The Slopfarm WebProNews Has Turned Google News Into a Laughing Stock Full of Plagiarism by Slop
- If Google News dies of neglect, that's one thing. It's starting to seem like active neglect by Google is a form of participation.
- Do What is Moral, as What's Legal Isn't Always Moral
- Do what's objectively moral, no matter the costs and the risks
- Slopwatch: Google News Assisting Plagiarism and Anti-Linux FUD, Serial Slopper Rips Off Linux-Centric Journalists
- This makes the Web a much worse place and lessens the incentive to do journalism
- Links 30/08/2025: NVIDIA Fakes Results to Hide a Bubble Already in Implosion Phase, Data Breaches Galore, Important Win for Workers' Union in Canada
- Links for the day
- Representing and Speaking for Animals
- If I ever choose to take this matter to tribunal with animals-centric NGOs on my side, it'll get some press coverage for sure
- The UEFI 9/11 - Part II - Campaign of Censorship and Defamation Against Critics
- In dictatorships, humour serves an important role. It's tragic.
- In Kazakhstan, Yandex Estimated to be 20 Times Bigger Than Microsoft
- Bing is measured as down this month
- Shutterstock Not Enough? The Register MS Uses Slop Images in Articles (Seemingly More and More Over Time)
- Cost-saving trajectory amid office shutdown?
- Gemini Links 30/08/2025: Games, PostmarketOS, and Slop
- Links for the day
- Links 30/08/2025: Imgur Uproar and Many Ukraine Updates (Mediazona Reports Over 200,000 Russians Died for Putin)
- Links for the day
- How Not to Build Software
- code forges that need a Web browser perhaps fill some 'niche' demand
- GAFAM and "MATA"
- The use of dark humour there hopefully helps illuminate what a lot of "modern" technology became like and how it interacts with human civilisation (to what ends and whose gain)
- Birds Are Not "Pests and Vermin", Privacy is Not a Crime, and GNU/Linux is Not 'Hacking Platform'
- I could not help but think of Free software analogies
- The Sites Should Be Very Fast Again
- That issue is now resolved
- Flying in 2025
- worse than ever before
- Activists, Including Technical Activists, Need Not Pursue Affirmation
- Techrights doesn't play or participate in a "popularity contest"
- The UEFI 9/11 - Part III - Chaos is Scheduled to Happen Second Thursday of September (No Matter What the Microsofters Tell You)
- The clock is ticking
- Downplaying the Impact of "UEFI 9/11" is a Losing Strategy
- we won't publish much whilst on holiday
- Government Sites Should Run Free Software
- Not proprietary bloatware with buzzwords
- LLM Slopfarms Take No Breaks
- When people run sites by bots they don't need to worry about "breaks"
- GNOME Having a Meltdown Again
- Thanks and farewell to Steven Deobald
- Gemini Links 30/08/2025: Low Tech and Hunchbin 1.0.6
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Friday, August 29, 2025
- IRC logs for Friday, August 29, 2025