Eye on Microsoft: Ransomware, Botnets, Critical Flaws, and Insecure Microsoft File Types
- Dr. Roy Schestowitz
- 2009-07-28 07:18:43 UTC
- Modified: 2009-07-28 07:18:43 UTC
●
Smut page ransomware Trojan ransacks browsers
Russian cybercrooks have come up with a variant of ransomware scams, which works by displaying an invasive advert for online smut in users' browsers that victims are extorted to pay to remove.
●
The Business of Botnets
Kaspersky Lab released some interesting statistics recently in a technical whitepaper. As part of its research into the cyber-underground, the company took a look at how botmasters are pricing the networks under their control.
●
Microsoft to fix critical hole in IE
In a rare move, Microsoft on Friday said it would be releasing security updates on Tuesday--outside of its monthly patch cycle--for a critical vulnerability in Internet Explorer and a moderate vulnerability in Visual Studio.
●
Microsoft to Issue Emergency Patches Next Week
The advance notification advisory that Microsoft released about these upcoming patches doesn't say so explicitly, but a spokesperson for the company confirmed that the updates will address a critical security flaw in collection of code that Microsoft uses in a number of places in Windows. Having a vulnerability in this so-called "code library" is especially dangerous because Microsoft also provides this library to third-party software makers to help them build programs that can leverage certain built-in features of Windows.
●
Insecure by design: MS Office formats
You see, when you're opening an Office document today, you're not just opening static words, images, or numbers. You're actually starting a program that uses Microsoft Office as its interpreter. And, no matter whether you're using Word 2,0 formats or the 2008's 7,000+ pages mis-mash of 'standard' ECMA-376 Office Open XML file formats, there is no built-in network security layer. Instead, there is a mis-mash of fixes for one problem or the other.
Also see:
Emergency, Botnets, and No Remedy
Recent Techrights' Posts
- Torvalds Capitulated on Rust and Slop, Now He's Paying the Price
- they are pushing Microsoft and slop for grifters and scammers
-
- LinkedIn Layoffs at Microsoft: Probably Well More Than 5% of Staff
- In short, it's difficult to believe only 5% are impacted
- It's Not Just a Widespread Theory, It's Apparently a Verified Fact: Home Appliances Not Made to Last Long
- Washing machine repair man asserts that the machines sold a decade ago could maybe last a decade; now they last barely 5 years.
- Whistleblowers Needed: We Are Seeing Many Layoffs in Red Hat (Not Just in China), We Want to Know More
- Last week we learned about some people who said they had left Red Hat or are leaving Red Hat
- Links 19/05/2026: More Obituaries for Peter G. Neumann, Taiwan Abandoned by Cheeto House for Don's Personal Gain
- Links for the day
- Links 19/05/2026: Online 'Storage' (Surveillance) Accounts Lower Thresholds (Gmail, Google Drive, and Google Photos), Slop Debacles Expand (False Promises Made to Staff Regarding Compensation)
- Links for the day
- SLAPP Censorship - Part 81 Out of 200: SLAPP Censorship Does Not Work If Your Sole Strategy is Revenge (and You Attack the Family)
- Both yours and others'
- Techrights at 20 (Soon)
- It does not seek popularity or affirmation from "Establishment" outlets
- We Pay More for Less, for Things That Last Less Time and Are Almost Impossible to Repair
- Ever noticed how "modern" or "smart" TVs come with dumber and dumber (worse) controllers?
- Vista 11 Turns 5 in a Couple of Months. Not Many People Use It.
- It is the only supported version of Windows; many people move elsewhere
- Head of GitHub Recently Left, Microsoft Need No Longer Report Mass Layoffs There (User Activity is Declining)
- We've long said that LinkedIn and GitHub, which Microsoft bought, would likely end up like Skype
- The Slop Bubble is Already Bursting
- Slop is not desirable and the general public is growingly impatient, seeing that slop has improved nothing for them
- Gemini Links 19/05/2026: Reliable Old Tech, Collection of Essays
- Links for the day
- The Corrupt Lecture the Non-Corrupt - Part XXVII - European Patent Office (EPO) Became a "Toxic Work Environment" When Cocaine Addicts Put in Charge
- They are putting at risk colleagues by abusing them
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Monday, May 18, 2026
- IRC logs for Monday, May 18, 2026
- Links 18/05/2026: Slop-induced Shortages, Solicitors Regulation Authority Says It's Unable to Deal With Complaints Load (So Regulation Does Not Really Exist)
- Links for the day
- Gemini Links 18/05/2026: Ghost Essay and World Wide Web Considered Broken
- Links for the day
- Cooperation and Collaboration, on a More Personal Level
- Rianne, to me, isn't just a wife; she is also my best friend
- IBM Has Payroll Problems (Just Like Microsoft)
- It's a good thing that many nations around the world are, accordingly if not proactively, divesting from GAFAM
- Links 18/05/2026: 25 Years of OLDaily and Dangers of "Living With Too Much Tech"
- Links for the day
- Trips to London
- London isn't a bad place, but it's a long journey and we'd rather stay in Manchester and write about technology
- SLAPP Censorship - Part 80 Out of 200: Having Run Out of Time to Meet a Judge's Deadline, Microsoft's Graveley Had Garrett's Lawyers Argued My ~190-Page Defence and CounterClaim (DCC) Was Unclear About My Position
- Nothing could be further from the truth
- Working in the Shell (and Fish)
- Yesterday we spent about 5 hours on the shells and fish
- The Corrupt Lecture the Non-Corrupt - Part XXVI - Campinos Has Put Unfit-for-Employment Drug Addicts in Charge of the European Patent Office (EPO)
- How many months has Campinos got left before the delegates show him the door?
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, May 17, 2026
- IRC logs for Sunday, May 17, 2026
- Gemini Links 18/05/2026: Poetry, Sauna, and GNU Taler
- Links for the day
- "The Society of Media Lawyers" (UK) is a Truly Malicious Anti-Media Lobby Which Helps Rich/Abusive Americans and Hostile Countries Attack Actual Media Workers in the UK
- They typically source their money from aboard to besiege domestic actors (like honest journalists or independent outlets that document suppressed beats/topics)
- Slop Still Waning, Its Momentum is Driven by Companies That Stand to Lose a Lot (or Everything) When the Bubble Pops
- When it comes to LLM slop disguised as news, it's just not working out
- Gemini Links 17/05/2026: arXiv Brings Down the Hammer, UnderPOWERed, and Slopping With Tcl/Tk
- Links for the day
- Links 17/05/2026: Amazon Employees Herded Into Slop, Taiwan Sold Down the River by Cheeto
- Links for the day
- Links 17/05/2026: Society of Media Lawyers (Brett Wilson LLP et al) Lobby for More SLAPPs in the UK, “Courage in Journalism Award” Given in Oppressive Country
- Links for the day
- Finland Needs to Dump Microsoft (Microslop) for National Security Reasons and the Same is True for Hundreds of Countries
- "I don't see why Ryssäs would want Finns to use microslop products..."
- Cyber Show UK is Already Available Over Gemini Protocol
- This past week the total number of active Gemini capsules hit all-time records several times
- Fight Til the End
- This comes to show that persistence pays off
- SLAPP Censorship - Part 79 Out of 200: They Will Soon Reach the 100 KG (Kilograms) Milestone; Wheelbarrows, Not Justice (Quantity of Legal Papers Sent to Us)
- It's about the quality, not quantity (unless your sole aim is to drown out or "flood the zone")
- The Corrupt Lecture the Non-Corrupt - Part XXV - Not Bringing Intelligence to the EPO, Not 'Artificial Intelligence' Either (But Intelligence-Eroding Drugs)
- The EPO was meant to be about science and law. In practice, however, it's about breaking the law and being stoned.
- The Cyber Show on Why Coding is Important and Slop Cannot Change or Replace That
- Hand-crafting one's site has plenty of advantages
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Saturday, May 16, 2026
- IRC logs for Saturday, May 16, 2026
- Gemini Links 17/05/2026: Music Theory, Reticulum Git Repos, and Releasing Kiln
- Links for the day