Bonum Certa Men Certa

Eye on Security: Windows Malware, Emergency Patches, and BeyondTrust's CEO from Microsoft

Summary: Security holes -- some of which highly critical -- continue to be found in Microsoft software; Justification of skepticism when it comes to new 'research' from former Microsoft staff, based on Microsoft-supplied data

OVER the past few days we have gathered more evidence to show that security problems only affect/target Windows and that those who flatter Windows for security are often tied to Microsoft (Window Snyder is just one example).



Windows-only Threats



Download Squad has this new post which compares Norton's Security Scan to malware (it sure takes up a lot of resources). Those who think it's bizarre should check out this minor piece of FUD and the rebuttal from The Source.

Right, so the Murphy’s Law headline is “Stop Supporting Open-Source Bloat“, where the author goes on to decry shady tactics of several programs, like:

* Revo Uninstaller * Digsby * ImgBurn

…NONE OF WHICH ARE OPEN SOURCE


Ignorance or deliberate deception? Either way, it looks bad for Maximum PC. Windows problems are now being described as "Open-Source" for no apparent reason.

TechDirt shows how copyright scare is being used to install malware/back-doors on people's Windows machines. This relies on the infamous click-to-execute mentality that's so prevalent in the Windows world. Actually, Microsoft software also tends to execute arbitrary code when one just visits a Web page (Active X is notorious for this reason).

Microsoft Emergency



The security flaws are so serious that Microsoft has just released an "emergency" patch for no less than 10 holes in Internet Explorer (which Microsoft neglected to patch for many months, leading to otherwise-preventable chaos [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12]).

From The Inquirer:

SOFTWARE INSECURITY SISYPHUS Microsoft has released an out-of-cycle patch for users lazy or ignorant enough to still be using an old version of Internet Explorer.

It's generally rare that threats are deemed serious enough for Microsoft to not wait until its next Patch Tuesday, which would be April 13th now, but a vulnerability hit Internet Explorer 6 and 7 that left them open to potential remote code execution.


More at CNET:

Microsoft issued an emergency security update on Tuesday to plug 10 holes in Internet Explorer, including a critical vulnerability that has been exploited in attacks in the wild.

The cumulative update, which Microsoft announced on Monday, resolves nine privately reported flaws and one that was publicly disclosed. The most severe vulnerabilities could lead to remote code execution and a complete takeover of the computer if a user were to view a malicious Web site using IE, Microsoft said in the bulletin summary.


Internet Explorer 8 is also affected.

BeyondTrust is Hard to Trust



BeyondTrust logo



Judging by previous incidents, past Microsoft employees who become 'researchers' typically produce output that's biased in Microsoft's favour. That's why we decided to take a careful look at BeyondTrust. Their web site is all Microsoft stack-based (showing the lower probability that they understand security) and their CEO "spent seven years at Microsoft Corporation in a variety of executive sales and marketing positions," according to the company's own pages. "Sales and marketing," eh? Now, we have already covered security problems Vista 7 suffers from, in a wide range of posts including:



“Statistics must not depend on Microsoft's own data and presented in a favourable way by design.”This brings us back to BeyondTrust (wow, what a name!). Their latest promotion of Windows for security is quoted a lot by Microsoft boosters like Emil this week. They are measuring the wrong thing by wrongly assuming that Microsoft tells the truth about its patches. Microsoft is patching its software secretly a lot of the time. We saw that many times before and thus we urge people to be skeptical. Statistics must not depend on Microsoft's own data and presented in a favourable way by design. Remember that there are "lies, damned lies, and statistics," according to Benjamin Disraeli and others. There may also be reason for bias here.

Speaking of potential connections to Microsoft, an anonymous reader told us to "beware that TurboHercules might be financed by Microsoft". This reader has not produced evidence to show what led to such suspicions (it may give away the identity), but as we recently showed, TurboHercules did join a Microsoft front. It aligned itself with Microsoft and companies/campaigns that are partly owned by Microsoft. ⬆

Comments

Recent Techrights' Posts

Brigading Against Women - Part VII - 'Trolling' Courts and Legal Systems in America and in the UK (Europe) Costs a Lot to Taxpayers
They only attend hearings after being arrested
Dejan Panovski Outs linuxize.com as a Slopfarm, Another Site That Sold Out and Became LLM Garbage
From what we can gather, both images and text are slop
A Microsoft Lunduke OS (LCOS) is Not Even in Top 100 in DistroWatch, Microsoft Lunduke Just Games the Numbers Like Linspire Did (and Got 'Banned' for It)
Linspire used to send people to 'its' DistroWatch page to make the illusion of popularity
 
Links 28/09/2026: Microsoft Chatbot "Giving Extremely Specific Advice to a School Shooter on How to Maximize Casualties", ‘Suicidal Empathy’
Links for the day
Microsoft's Attacks on Courts in the Netherlands Result in GNU/Linux Growing to About 10% There
One core issue that justified this and led to this outcome is Microsoft's interference with the administration of justice
They Create the Conditions for People to Leave, This Way They Don't Call it "Layoffs"
We keep seeing many stories like these
Gemini Links 28/09/2026: Wildfire, DOS, and Backups
Links for the day
European Patent Office (EPO) Series: The Portuguese Talent For Bureaucratic Empire Building
Portugal’s success in securing senior executive appointments at the EUIPO and the EPO is a notable example of how countries seek to strengthen their influence within European intergovernmental institutions
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, September 27, 2026
IRC logs for Sunday, September 27, 2026
Gemini Links 27/09/2026: Writing Well, Productivity, and a Relaunch in Geminispace
Links for the day
Making This Site More Useful to More People
Search engines (as a concept) are under attack
Exposing Crimes of Americans (From the UK)
We must ensure UK prisons are never misused to punish/silence people who expose crimes in America
Spam and Chatbot Spam in Internet Relay Chat (IRC)
Maintaining one's own IRC network requires some housekeeping, but it's simpler than outsourcing to malicious companies
Search Engine of Techrights Improved for Better Signal-to-Noise Ratio
Our growing community needs more search facilities
Microsoft: We Love Layoffs, We Do Silent Layoffs, More Microsoft Projects/Teams/Studios Confirmed to be Shutting Down
XBox is dying. Piece by piece.
Brigading Against Women - Part VI - On Garrett and Lozza, Defamation, Attempts to Crack My Wife's Accounts, Social Engineering to Try to Take Sites Offline, Subscribing Us to Mountains of SPAM
tried swatting us
Links 27/09/2026: "Provost of Dartmouth Busted Using Hey Hi (AI) Slop for His Own Writing in Newspapers and Academic Journals" and "UK Government Enforcement Reform"
Links for the day
People and Sites Wish a Happy 43th Birthday to GNU (Today)
We've collected some examples
Links 27/09/2026: Microsoft Fired People a Day After Promotion, "Fragility of Online Journalism"
Links for the day
Brigading Against Women - Part V - SWATTING, Extortion Against Webhosts, and Lawfare Under Sworn Oath (Perjury Also)
Matthew Garrett has no qualm about still collaborating with Lozza
20 Years Later
There's a strong anti-democracy movement brewing in many places
Gemini Links 27/09/2026: Telescopes/Gskyer, Writing for Writing's Sake, and Writing Tools
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 26, 2026
IRC logs for Saturday, September 26, 2026
Gemini Links 26/09/2026: Computer Cases Dreary, Web Drowning in Botspam
Links for the day
Reform UK auditor: Electoral Commission accounts, Companies House accounts, a going concern or not?
Reprinted with permission from Daniel Pocock
European Patent Office (EPO) Series: Temporary Public Office or Permanent Personal Feather-Bed?
there are no visible signs that the Administrative Council has the slightest interest in contemplating a change in leadership at the EPO
Brigading Against Women - Part IV - Death Threats, Threats to Women, and Threats for Pointing Out, Correctly and Based on Hard Evidence, That Garrett and Lozza Talk to Each Other About Me Every Year (for 4 Years)
Brett Wilson LLP too is a toxic manosphere
More GAFAM Layoffs at Apple, Second Time in Weeks (Silent Layoffs Silently Target Older and "More Expensive" Staff)
How many layoffs happen at Apple silently and go unreported or very scarcely reported?
Gemini Links 26/09/2026: Rant About Slop Ruining Crafts (Drowning the Signal With Plagiarism) and "Going Mechanical"
Links for the day
Links 26/09/2026: Microsoft Says Notification Data Breach/Surveillance Hole There by Design, EU Rapidly Dumping Microsoft for Digital Sovereignty
Links for the day
The Former Linux News Site ostechnix.com is LLM Slop
Please do not link to sites that promote and/or spread slop
Links 26/09/2026: Volkswagen Recalling ~50,000 Cars, US Attacks Its Own Media
Links for the day
Making Oneself Obsolete With Slop
Dr. Lemire also puts on display a degree of hypocrisy
Brigading Against Women - Part III - Racism Looms Large, Not Just Sexism
threats from a racist
Microsoft CEO Calls Layoffs "Streamlining" and Says Microsoft Layoffs Are "Great to See"
The lack of honesty here is only to be expected from Microsoft
Media silence deafening as Reform UK on brink of administration
Reprinted with permission from Daniel Pocock
Gemini Links 26/09/2026: Travel, Group Insurance Death Spiral, Stargazing, and Lagrange Meets LLM Slop
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, September 25, 2026
IRC logs for Friday, September 25, 2026