Bonum Certa Men Certa

Security Propaganda From Microsoft: Villains Become Heroes

Robin Hood



Summary: A survey of security news and an analysis of Microsoft spin, namely how the company diverts attention away from its failures and portrays itself as a security leader

YESTERDAY we caught up with 3 weeks of Microsoft (in)security news, adding to our record more evidence to show what we had argued earlier this month. While the former Microsoft executives who now run Juniper Networks help protect Windows from those many vulnerabilities (some of which are hidden), there is no denying of the fact that Windows vulnerabilities are on the rise [1, 2]. To highlight bits from the news, vulnerabilities multiply fast and they are found by the dozens:

VUPEN Security Discovers Critical Vulnerabilities in Microsoft Software



VUPEN Security, the world leader in vulnerability research and analysis, today announced that the VUPEN Vulnerability Research Team (VRT) has been working with Microsoft for six months to address twenty-one vulnerabilities discovered by VUPEN in major Microsoft software.


Also in the news:

Windows full of holes, ready for Microsoft patch

In case you were wondering, the previous record was 34 in late 2009, which makes the number 49 seem even bigger. You have to wonder if we are getting better or worse about this security thing.


Microsoft Issues Biggest Fix Ever For Windows, Explorer, Office

Microsoft releases security patches for Windows, IE, Office

Microsoft will roll out a whopper load of patches

Microsoft Preps Record Security Patch Tuesday

Microsoft Patch Tuesday expected to set record

Microsoft's Biggest Patch Tuesday Ever -- Better Update Your System, or Else

Microsoft sets Patch Tuesday record, fixing 49 security holes

Microsoft issues patches for a record 49 security holes

Patch Tuesday brings record harvest of security fixes

As that last one puts it: "Many of these holes allow a remote takeover of your computer, in some cases after you do nothing wrong beside visit the wrong Web page. One such opening has frequently been exploited by the Stuxnet worm that's been running around the world."

Microsoft has only just done something about Stuxnet, which we wrote about in:

  1. Ralph Langner Says Windows Malware Possibly Designed to Derail Iran's Nuclear Programme
  2. Windows Viruses Can be Politically Motivated Sometimes
  3. Who Needs Windows Back Doors When It's So Insecure?
  4. Windows Insecurity Becomes a Political Issue
  5. Windows, Stuxnet, and Public Stoning
  6. 1
  7. Has BP Already Abandoned Windows?
  8. Reports: Apple to Charge for (Security) Updates
  9. Windows Viruses Can be Politically Motivated Sometimes
  10. New Flaw in Windows Facilitates More DDOS Attacks
  11. Siemens is Bad for Industry, Partly Due to Microsoft
  12. 4
  13. Microsoft's Negligence in Patching (Worst Amongst All Companies) to Blame for Stuxnet
  14. Microsoft Software: a Darwin Test for Incompetence
  15. Bad September for Microsoft Security, Symantec Buyout Rumours
  16. Microsoft Claims Credit for Failing in Security
  17. Many Windows Servers Being Abandoned; Minnesota Goes the Opposite Direction by Giving Microsoft Its Data
  18. Windows Users Still Under Attack From Stuxnet, Halo, and Zeus


Now, any sane person would say that Microsoft and almost nobody else is to blame for these vulnerabilities and should therefore be held accountable. But not when Microsoft's spin machine occupies the news, though. Take the Bill Gates-funded Guardian [1, 2, 3, 4] for example. It serves as Microsoft's platform right now by publishing "Microsoft Removed 6.5 Million Bots From Windows Machines In Q2" and it's the same propaganda the MSBBC published some days ago, having previously (just a week beforehand) given Microsoft's Charney the platform yet again. It's rather astonishing that journalists are able to portray Microsoft as the "good guy" in this story by merely reciting reports from Microsoft. It's an example of the failure of today's journalism and it's hard to tell just how much impact the former Microsoft UK executives who run the BBC or Bill Gates' sponsorship of The Guardian have here. A few hours ago our reader told us that "Bill Gates on BBC breakfast news later." Later this week we'll write about that too.

“It's rather astonishing that journalists are able to portray Microsoft as the "good guy" in this story by merely reciting reports from Microsoft.”Anyway, here is a rant about what Microsoft is trying to do here and here are a few more examples of the Microsoft spin [1, 2, 3]. So fake news is good news? It should not be the case. Either way, it's clear that they portray Microsoft as the saviour, not the culprit, even though the problem itself was caused by Microsoft's continued negligence [1, 2, 3]. Earlier this morning we gave an example of similar spin. Here is the same propaganda with a "Zeus" flavour [1, 2]. The latter says that "Zeus-created botnets, known as Zbots, control many millions of computers -- mostly Windows XP machines --- in almost 200 countries." Okay, so why give Microsoft any credit? That's just mastery of spin. We wrote about Zeus in posts such as [1, 2, 3, 4, 5, 6, 7].

Watch out for the spin, some of which originates in the 'Microsoft press' (e.g. Kurt Mackie). As usual, Microsoft will just blame the users, even though zero-day flaws mean that any Windows computer can be hijacked even if it's fully patched. As for those who patch early, they take other types of risks and this bit of news is why people are reluctant to patch:

On Tuesday, Microsoft released updates for both Microsoft Office 2004 and 2008 to correct some security vulnerabilities in the software, but a number of people are having difficulties opening some Excel spreadsheets in Office 2004 after the update.

As mentioned by CNET member and MacFixIt reader Kurt in the comments of our article announcing the update:
"After applying the update yesterday, some Excel documents refuse to open. For a fraction of a second the open progress bar shows up, then nothing happens."
This problem has been echoed by numerous other Office users here at CNET as well as at the Office for Mac forums, and Microsoft's Mac team is currently investigating the issue.


Yes, that's why many people won't patch, either. Even those whose machine is not fully patched can sometimes blame Microsoft's poor quality of patches.

Comments

Recent Techrights' Posts

The European Patent Office Cannot Attract Proficient Patent Examiners Who Master Their Domain
They are enablers and facilitators of corruption
[Meme] 9AM Meeting at Brett Wilson LLP
Brett Wilson LLP in space
 
Debian Can Dump Blind Users Because I am Not Blind
the sort of mentality we're up against
Fascistic Policies Got 'Normalised' in 'Public Office'. Let's Not Let the Same Happen in 'Tech'.
Political discourse typically guides what's "normal" and what "good citizens" should believe/feel
Yes, Your Mastodon Instance Will Also Shut Down
Few people run a one-person instance in the Fediverse
The Demise of GAFAM Necessitates Greater and Broader Awareness
Morale at Microsoft is really bad
Free Software Foundation Reaches 75% of Funding Goal
Not bad for this "Fosschild"
Slopwatch: 7 New Examples of Fake 'Linux' Slop Pieces (Plagiarism With Misinformation)
Serial Sloppers need to be shunned
Links 19/07/2025: Kapo-berg Settles, Software Patents Challenged
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, July 18, 2025
IRC logs for Friday, July 18, 2025
Links 18/07/2025: Peace With PKK and Connie Francis Dies
Links for the day
Gemini Links 18/07/2025: Alhena 5.1.8 and Bornhack 2025
Links for the day
How to Top Up a "Limited Liability" With Even More Limitations (Dodging Accountability in the UK)
Some people call it a "shell game". Sometimes it's done for tax evasion purposes.
Free Software Foundation, Inc. (FSF) Inches Towards 75% of Fund-Raising Target
Will the cutoff date be extended again?
Gemini Space (or Geminispace) Grows, But Usage of Certificate Authority Let's Encrypt Drops Further
Ideally, all Gemini capsules should use self-signed certificates
Links 18/07/2025: More Microsoft Layoffs in Activision, The New Stack (Sponsored by Microsoft) Complains About Openwashing
Links for the day
Gemini Links 18/07/2025: OCC25 Gnus for Reading Usenet and RSS Feeds, Small Web Updates
Links for the day
Listing as Staff People Who Left the Company More Than Six Years Earlier
There are apparently no laws against that
Brian Fagioli Shovels Up LLM Slop (Plagiarism) Onto Slashdot, Then Uses Slashdot for Affirmation or as Badge of Honour
Notice how some of his latest slop is presented ("as featured on Slashdot")
Social Control Media Productivity
Snapping photos of the bone
The Law Firm SLAPPing Us For the Microsofters Lost 72% of Its Tangible Assets in the Past Year, According to Its Own Reports
That might help explain why they're willing to tolerate serial stranglers from Microsoft as clients
Slopwatch: LinuxSecurity.com Slopfarm and Slopfarms Propped Up by Google News
"As LLM slop is foisted onto the WWW in place of knowledge and real content, it now gets ingested and processed by other LLMs, creating a sort of ouroboros of crap."
Links 18/07/2025: Weather Events and Health Hazards
Links for the day
Microsoft's All-Time Low in Finland
Microsoft is in a freefall
Security: Shane Wegner & Debian statement of incompetence
Reprinted with permission from Daniel Pocock
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, July 17, 2025
IRC logs for Thursday, July 17, 2025
Gemini Links 17/07/2025: "Goodreads for Gemini" and Defence of "The Small Web"
Links for the day
Links 17/07/2025: Anger and Morale Issues at Microsoft, Wars and Conflicts Get Digital
Links for the day
CALEA / CALEA2 is the Real Problem, Not Chinese Operatives Exploiting CALEA / CALEA2 (as Any Other Nation Can)
CALEA / CALEA2 is more of a front door than a back door
99.99% Uptime in First Half of 2025
Since January there was only one noticeable outage
Nils Torvalds and Anna "Mikke" Torvalds (née Törnqvis) Hopefully Use GNU/Linux by Now
"Torvalds Family Uses Windows, Not Linus’ Linux"
Attack of the Slopfarms
FUD-amplifying bots with slop images, slop text (LLM slop)
When People Call a Best/Close Friend of Bill Gates a "Serial Rapist"
Good thing that the Linux Foundation keeps the "Linux" trademark ("Linux Mark") clean
Not My Problem, I Don't Care
Context/inspiration: Martin Niemöller
Honest Journalism About the European Patent Office Ceased to Exist After SLAPPs and Bribes to the Media
The EPO is basically a Mafia
Microsoft Bankruptcy in Russia, Shutdown in Pakistan, What Next?
It seems possible that in 2025 alone Microsoft will have laid off over 50,000 workers
Life Became Simpler When I Stopped Driving and I Don't Miss Driving When I See "Modern" Cars
Gee, wonder why car sales have plummeted...
Why I Believe Brett Wilson LLP and Its Microsoft Clients Are All Toast
So far our legal strategy has worked perfectly
EPO Jobs Are Very Toxic and Bad for One's Health
Health first, not monopolies
Response to Ryo Suwito Regarding the Four Freedoms
the point of life isn't to make more money
Microsoft's Morale Circling Down the Drain
Or gutter, toilet etc.
What Matters More Than "Market Share"
The goal is freedom, not "market share"
Tech Used to be Fun. To Many of Us It's Still Fun.
You can just watch it from afar and make fun of it all
Links 17/07/2025: "Blog Identity Crisis" and Openwashing by Nvidia
Links for the day
Greffiers and the US Attorney of the Serial Strangler From Microsoft
The lawsuit can help expose extensive corruption in the American court system as well
Credit Suisse collapse obfuscated Parreaux, Thiébaud & Partners scandal
Reprinted with permission from Daniel Pocock
The People Who Promoted systemd in Debian Also Promote Wayland
This is not politics
UK Media Under Threat: Cannot Report on Data Breach, Cannot Report on Microsoft Staff Strangling Women
The story of super injunction (in the British media this week, years late)
Victims of the Serial Strangler From Microsoft, Alex Balabhadra Graveley, Wanted to Sue Him But Lacked the Funds (He Attacked Their Finances)
Having spoken to victims of the Serial Strangler From Microsoft
Links 17/07/2025: Science, Hardware, and Censorship
Links for the day
Gemini Links 17/07/2025: Staying in the "Small Web" and Back on ICQ
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, July 16, 2025
IRC logs for Wednesday, July 16, 2025