Bonum Certa Men Certa

Eye on Microsoft: The Security Comedy Resumes

Penguin bubbles



Summary: A roundup of Microsoft's latest examples of poor performance at securing its software

Microsoft's incapability with security has already cost the economy trillions of dollars. Some days ago we wrote about the impact on parts of national operations that are funded by taxpayers; they too pay the toll.

Conficker borks London council



[...]

The May incident took several days to clean-up and landed the west London council with a bill of €£500,000 in lost revenue and repairs, The Guardian reports. Because IT systems were borked, the council was unable to process more than 1,800 parking tickets, at an estimated cost of €£90,000, libraries lost out on €£25,000 in fines and booking fees, council property rent went uncollected, and €£14,000 was spent in overime sorting out delayed housing benefit claims.


Some time ago we also wrote about IIS coming under siege. It is getting worse:

New IIS attacks (greatly) expand number of vulnerable servers



[...]

Attackers have begun actively targeting an unpatched hole in Microsoft's Internet Information Services webserver using new exploit code that greatly expands the number of systems that are vulnerable to the bug.


3rd parties jump to Microsoft's (or their customers'/users') rescue. This is also covered in:



Exploit code affecting the FTP module for certain versions of Microsoft IIS has been posted online. US-CERT recommends taking countermeasures.


Another press release heralds another security problem in Microsoft's stack. Microsoft is investigating and denying it.

For more than a year, Microsoft has been sitting on a purported SQL Server vulnerability that could enable a malicious insider to obtain users' passwords, claims database security vendor Sentrigo.


There is also coverage in Dark Reading and net-security.org, which states:

Sentrigo has discovered a vulnerability in Microsoft SQL Server that allows any user with administrative privileges to openly see the unencrypted passwords of other users, or the credentials presented by applications accessing the server using SQL Server authentication.


More reasons are given to believe that Vista 7 will persist with the same security problems of Vista. A company warns about UAC.

While changes to Windows 7’s UAC benefit the home user market, enterprises must be aware that the new “slider” feature is only for administrators and may increase security risks.


Applications with an anti-viral goal still show that they may cause more trouble than it's all worth.

McAfee false alert snares innocent JavaScript files



[...]

Faulty virus definition updates from McAfee that flagged legitimate JavaScript files as potentially malign caused a headache for some sysadmins earlier this week.


In other news:

Compromised Computers Host an Average of 3 Malware Families



[...]

Unfortunately, we are talking about infected files and not doughnuts. According to security company ESET, the average compromised machine is home to 13 infected files as well as malicious programs from three different malware families.


Liability issues linger on:

An Illinois district court has allowed a couple to sue their bank on the novel grounds that it may have failed to sufficiently secure their account, after an unidentified hacker obtained a $26,500 loan on the account using the customers’ user name and password.


Given the scale of botnets, nobody should be left surprised. Systems which were not built to be secure in the first place can never be properly secured.

"Our products just aren't engineered for security."

--Brian Valentine, Microsoft executive

Recent Techrights' Posts

IBM is "Taking the PIP" (Piss), People 'Retire' 'Voluntarily' to "Focus on Family"
IBM has a billion bucks for 'the butcher', but not a million dollars for critical projects and initiatives in Free software
It Should be Uncontroversial to Say That Social Control Media is a Weapon
Democracy is not compatible with the likes of Kapo-Berg and MElon controlling public discourse of billions
Debian: Plagiarism OK, Just be "Responsible" About It
The result isn't the worst, but it's not good either
Don't Let Them Kill Activism
Are the oligarchs shutting the lid on activism and whistleblowers?
 
Links 29/08/2026: Stop the Hate, Goldfish Myths, and xmpp.nz
Links for the day
Links 29/08/2026: Wave of Social Control Media Bans, Suno Data Breach Class Actions
Links for the day
Links 29/08/2026: Microsoft GitHub Outage (Again), "Displaying Ads Directly on Your Monitor", and "Election Deniers Could Soon Control Elections"
Links for the day
Misuse of Bots (Now Sold as "Agents", "Hey Hi", "Automation", and "Efficiency")
They even try to rebrand robotics as "hey hi" and try to sell slop as "work"
SLAPP Censorship - Part 165 Out of 200: Two Years Since My Wife and I Sued
In early September 2024 we hit back
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, August 28, 2026
IRC logs for Friday, August 28, 2026
Gemini Links 29/08/2026: Death Notice, Systems Biology, and Gopher
Links for the day
Links 28/08/2026: Chatbot Pushers Admit They're Used Heavily for Social Engineering Scams, Strong Backlash Against "Smart Glasses" (CCTV on Legs)
Links for the day
Michael Catanzaro's Latest Blog Post Affirms Rumours of Red Hat Changes and RAs/PIPs at IBM
reading between the lines, IBM is "spitting out" Red Hat staff
If Linux Was Written in Rust, 80% or More of Linux Developers Would Not Understand It (Same If It's Composed by LLM Slop)
The licence (GPL) is not enough when there are ways to bypass it
Gemini Links 28/08/2026: Absurd Tomodachi Summer, Screen Piggery, and Jugulans 1.0.3 Released
Links for the day
Links 28/08/2026: "UK Power Grid Has a Phantom Data Center Problem" and "Growth at All Costs is Cancer"
Links for the day
SLAPP Censorship - Part 164 Out of 200: Patent Troll SLAPPs, Defamation Trolls, and Stranglers From America
You start to wonder if the core issue is insecurity
Rumours of More PIPs and Layoffs at Confluent Just Months After IBM Bought It
It is meanwhile apparent IBM will have mass layoffs next week (September)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, August 27, 2026
IRC logs for Thursday, August 27, 2026
After Many Waves of PIPs (Silent Layoffs) IBM Makes Non-Silent Layoffs, Effective Next Week (September)
What we heard is turning out to be true
Gemini Links 27/08/2026: Oklahoma, Tennessee, Haiku OS, Digital Resistance, and Staying Offline
Links for the day
Links 27/08/2026: Facebook to Pay Up to $17.1 Billion to Cover Up Known Harms, Nepal Landslide Kills Many
Links for the day
The Register MS Has Just Published Paid Spam That Says "AI" 19 Times
1.5 hours ago
Mainstream Media is Paid to Link "AI" Criticism/Boosting to Jeffrey Epstein Enablers, in Effect Showing How Corrupt This Media Became
Many readers will have noticed what was a paid-for PR campaign of a global scale
RSS is King: Why Having Subscribers or Followers in Sites You Neither Own Nor Control is Loss of Autonomy and Search is Mostly Slop (Plagiarising Sites, Not Linking to Them)
Because digital connections in third parties aren't assets; they endow another party with tremendous power over people (e.g. MElon getting to decide who can and cannot reach people or what messages to "dim down")
Claims of Tens of Thousands of 'Silent Layoffs' at IBM (and Red Hat)
Looking at recent activity in thelayoff.com, about 80% of the comments and posts are about PIPs
Links 27/08/2026: "Flock’s CEO Is Lying to Cops" and Microsoft's GitHub Actions Breaks Down Again (Too Many Layoffs, Loss of Knowledge)
Links for the day
Clownflare Sees GNU/Linux and ChromeOS at Over 13% in Bahamas
Narrowing down to desktops and laptops, and judging by Web requests that go through Clownflare, many people there use GNU/Linux or Google's 'bastardised' version of it (with spyware preloaded)
Richard Stallman Complains That Linux Gives a Bad Name to GNU and Asks for Feedback on What's Wrong with Systemd (and Wayland)
Maybe some people want to send him a detailed, polite explanation
GNU/Linux Does Not Need Social Control Media to Succeed
When it comes to Social Control Media, Richard Stallman was right
Increasing Focus on Patent Injustices
We'll soon cover the EPO a lot more
SLAPP Censorship - Part 163 Out of 200: Attack on Computer Science and on Computer Security (or Associating Back Doors and Kill Switches With "Security")
Nowadays there are many who pretend to be security professionals
There's No "Next XBox"
Nothing comes ahead except layoffs and price hikes
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, August 26, 2026
IRC logs for Wednesday, August 26, 2026
Gemini Links 27/08/2026: Conditioning, Lagrange 1.21, and Computer Games
Links for the day