Bonum Certa Men Certa

Microsoft Hides Its Own Flaws, Cheats Customers

Haha, very funny pig
Even swine flu vaccines are delivered
more quickly than Microsoft patches



Summary: Microsoft delivers patches only after customers are attacked (despite having prior warnings) and then cheats when it comes to the number of patches it issues

ACCORDING TO PC Magazine, Microsoft neglects to look for its own bugs.

Sotirov noted that it's TippingPoint's and VeriSign's customers who were paying for this research and that Microsoft should be paying too. Surely, I asked, Microsoft does vulnerability research on their own product. At this point another famous researcher, Dino Dai Zovi, piped in to say no: "Apple is the only vendor that I know of that releases patches for vulns found internally."

This rang true; I know I've read Apple advisories that credited internal research and I couldn't recall a Microsoft advisory that credited their own. I looked and not a single vulnerability disclosure (so far) in 2009 was credited explicitly to Microsoft. I asked Microsoft about it.

Their answer... Well, of course they look for and find these things, but not so much.


Microsoft's negligence may justify lawsuits. To make matters worse, Microsoft lies about security, usually by hiding known flaws. The following new report from IDG is very damaging: "Microsoft knew of just-patched IE zero-day for months"

Microsoft may not have hustled as fast as researchers thought when the company patched a zero-day bug in Internet Explorer (IE) just 18 days after exploit code went public.

According to VeriSign iDefense, Microsoft had information about the browser bug nearly six months before the researcher dubbed "K4mr4n" posted attack code to the Bugtraq security mailing list on Nov. 20.


More hidden patches have just arrived.

Microsoft Releases Surprise Advisory



Hidden behind the Patch Tuesday updates, Microsoft released two separate security advisories and one set of updates that were not mentioned in the advance notification.


Regarding the latest Internet Explorer (IE) flaw that we wrote about before [1, 2, 3], Microsoft gives too little, too late, and being a zero-day flaw, damage has already been done.

Probably the most important update for most users is the one for Internet Explorer, which corrects five critical flaws in IE 6, 7 and 8. These are vulnerabilities that attackers could exploit to quietly install malicious software on your machine if you browse with IE to a hacked or booby-trapped site.


This only justifies the use of non-IE Web browsers. The way in which Microsoft delivers security updates is already being exploited [1, 2] to actually push malware rather than a fix.

Malware distributors continue resorting to the fake software update lure for their email spam campaigns. The latest attack poses as a notification regarding a Windows security bulletin, which links to a malicious executable.

The rogue emails impersonate Steve Lipner, Microsoft’s Director of Security Assurance, who allegedly informs the receiver about a high-priority security update for all versions of Windows. "Please notice that Microsoft company has recently issued a Security Update for OS Microsoft Windows. The update applies to the following OS versions: Microsoft Windows 2000, Microsoft Windows Millenium [sic], Microsoft Windows XP, Microsoft Windows Vista and Microsoft Windows 7," the fake message reads.


It remains the job of some GNU/Linux-powered gateways to keep Windows more secure. ⬆

Recent Techrights' Posts

Contemptuous Law Firm Accusing Others of Contempt of Court
Keeping a running tally can help
Links 10/10/2026: Let's Encrypt Making Changes (Problem for Small Sites/Operations), Quartz is Officially a Slopfarm (Busted)
Links for the day
Brigading Against Women - Part XXV - No Anonymity for People Who Did Illegal Things
"Empathy is the sunlight to the vampire of culture."
 
Anderon Is Not a Real Company, It's an IBM Bailout Dressed Up or Wrapped Up In Buzzwords
It certainly does seem like they receive money from taxpayers for nothing, or for IBM to do mass layoffs/closure at Albany under the guise of "making a new spinoff"...
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, October 10, 2026
IRC logs for Saturday, October 10, 2026
Gemini Links 10/10/2026: Radio Romania International, Avoiding GAFAM, Open Camera, and Another Palm
Links for the day
The 2026 Slop Prediction (Slopfarms Perishing)
Morality in the "digital world" has deteriorated profoundly
netsplit.de (Survey of IRC Networks and History) Only Partly Functional This Month
Get well soon, netsplit.de
Microsoft Cuts
GAFAM enshittification
NVIDIA Acts Like It Cannot Pay Salaries (Too Many Obligations, Sales in Circular Financing, or Basically Accounting Fraud)
Masters of acting as clients of themselves
Paying for elections, Reform UK illegal confession in High Court
Reprinted with permission from Daniel Pocock
Microsoft Abuses PERM and Lays Off Workers in India
The US government has made it easier for Microsoft to hide the mass layoffs
The GAFAM Elections in the United States
If the election is run by platforms that have back doors "baked-in" and if the communications are overseen by GAFAM, you would not have to be a "nutty MAGAt" to dispute the outcome
More GAFAM Layoffs (Late on Friday Night)
They say they are worth trillions, but they don't even make money
Male-Dominated EPO Fails to Have "Concrete Measures to Support Female Staff"
Being a female at the EPO is exceptionally hard
Production Freeze at the European Patent Office (Opposing Monarchy, Institutional Maladministration and Corruption)
Eight reasons to participate
Links 10/10/2026: Microsoft 'Open' 'AI' Silencing Critics, "Data Centres are the New Front Line in the Russia-Ukraine War"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, October 09, 2026
IRC logs for Friday, October 09, 2026
Gemini Links 10/10/2026: Optimism, Stargazing, "Life Without Smartphone", and Fairphone 4
Links for the day
Links 09/10/2026: Stranded Busan Shark Still a 'Circus', Endangered Monkey Rescued, BBC Shells Out Money
Links for the day
Gemini Links 09/10/2026: Manifesto, Slop, Geminispace, and "Cryptography of the Internet"
Links for the day
Betanews is Still a Slopfarm, Articles About "Linux" Are Fake and Plagiarism by LLMs
Cheaters and plagiarists aren't journalists; they're people who rip off and harm journalists
The Register MS Sponsored to Hype Up "Datacenters" and "AI" (Bubble, Pyramid Scheme)
"Sponsored by Cisco" with "AI" 26 times in this page
James Bottomley Has Promoted Microsoft-Controlled Restricted ('Secure') Boot, His Blog Has Just Been Cracked
Does this meet IBM's and Microsoft's standards for "distinguished" (in security)?
Links 09/10/2026: "Internet Archive to Demo Wayback Machine at Friday’s Uniqlo Street Festival", France Wages Censorship War via DNS
Links for the day
Controlled Opposition
The underlying concept is hardly new
More Stallmans
We need more Stallmans, we don't need to change Stallman
SUEPO Munich (EPO Staff Union in the Main Headquarters) Opposes Monarchy ('Cocaine King' Campinos), Plans Online Meeting Next Week
They may have about 1,000 workers joining in
World Mental Health Day is Tomorrow and EPO Staff Talks About What the Job Does to Workers
In recent years we've written a great deal about mental health consideration in relation to work, with a focus on "IT"
GNU/Linux Flirts With 20% "Market Share" in North America Overnight
Who should we trust on GNU/Linux? Microsofters on an armchair or Cloudflare Radar?
You Definitely Do NOT Wish to Live Close to a Datacentre
put aside for a moment the noise, the pollution...
New Site Makes the Case Against Adoption of Omarchy, But Focuses Almost Entirely on Politics
Let's examine what the page says and what points it focuses on
Brigading Against Women - Part XXIV - Nobody's Name is Unspeakable
Names are not sacred
Microsoft is in Trouble (With the Regime It Sponsored)
It seems like Microsoft paying the existing regime/dictatorship wasn't enough
GGG Pot Calls the Kettle Black
"It means a situation in which somebody accuses someone else of a fault which the accuser shares, and therefore is an example of psychological projection, or hypocrisy. Use of the expression to discredit or deflect a claim of wrongdoing by attacking the originator of the claim for their own similar behaviour (rather than acknowledging the guilt of both) is the tu quoque logical fallacy."
In the United Kingdom, Rising Cost of Hardware Benefits GNU/Linux
GNU/Linux rose from about 4% to almost 6% in one year
Japanese Targets of Cyber Breaches or Insider Threats
Japanese government bureau and major firms experience data breaches
Gemini Links 09/10/2026: Optimism, Stargazing, and Solar MiniServer
Links for the day
The Microsoft Ban Should Go Further (Telecommunications Cybersecurity and Resilience Act Incompatible With Back Doors)
it's not difficult to see where to start
When Americans Export a 'Suicide Mission' to Other Continents
I worry that this culture of debt-taking and overconsumption is being spread from the US to Europe
The Register MS: "AI" Several Times in Same Headline, 31 Times in Page. The Register MS Was Paid to Do This.
The phenomenon is commercial (paid media), not scientific
The Outcome of Microsoft Ban Was Predictable
told you so
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, October 08, 2026
IRC logs for Thursday, October 08, 2026