Bonum Certa Men Certa

Latest Security Dangers Are Windows Only

More than a million PCs turned to zombies

NOT A WEEK goes by without new dangers to users of Windows, and it's only fair to list the latest examples since it falls within our scope.

USB drives continue to be a risk to Windows because of the way the operating system handles devices insertion (namely execution) and the privileges it hands over to untrusted code.

Businesses who may not have applied a Microsoft patch issued last year are now being attacked by a worm targeting the vulnerability.

Multiple security organizations have issued warnings about the worm, deemed Downadup, which attacks the vulnerability outlined in the Windows Server service flaw, MS09-067, that was patched last October, Zdnet.com reports. The worm uses a dictionary attack in an attempt to crack user passwords, as well as using "server-side polymorphism and modification to the Access Control Lists."


According to this report from The Register, the Major League Baseball (MLB) Web site is serving malware which is only Windows compatible. The click-to-install or drive-by-install (ActiveX) paradigm takes its toll.

Once again, Major League Baseball's website has been caught serving ads designed to infect its considerable base of visitors with malware that trashes their machines.


With so much malware afloat, it's hardly surprising that almost 1 in 2 PCs is a zombie PC and it keeps getting worse. (emphasis below is ours)

The Storm Worm has been causing havoc for over two years now, transforming more than a billion computers into drones. Following a surprisingly unsuccessful mission by Microsoft’s Malicious Software Removal Tool around 100,000 drones still remain.


This fight is being taken to the Web as well. NATO's Web site has just been cracked, as well as Web sites of the United States military.

The attacks on Thursday took down the Web sites for The United States Army Military District of Washington and the NATO Parliamentary Assembly, according to Zone-H, a Web site that tracks defacement activity.


The IRS, which is most likely operating in a Windows-based environment, may suffer a similar fate.

Auditor: IRS Still Vulnerable to Cyber Breaches



"These deficiencies represent a material weakness in IRS's internal controls over its financial and tax processing systems," the GAO report said. "Until IRS takes these steps, financial and taxpayer information are at increased risk of unauthorized disclosure, modification, or destruction, and the agency's management decisions may be based on unreliable or inaccurate financial information."


Well, at least no lives at risk this time around... 'just' people's finances. How reassuring.

breaking the bank
Cracking the bank

Recent Techrights' Posts

What Really Matters to Companies is Net Income or Profit (Bankruptcy is Possible Even With High Revenue)
We ought to stop talking about revenue without focusing on actual profit
Carole Cadwalladr Talks About How Big Business Tried to Silence Her (and Why You Might be Next)
Our story is very different from Cadwalladr's for many reasons
LLM Slop and SEO SPAM Take Us Further Away From Facts (the Case of IBM Layoffs)
Some of these can impact Red Hat as well
Microsoft SLAPPs Against Techrights Losing Momentum
It always backfires
 
Links 14/04/2025: Russian Attack on Sumy Shows No Intention of Peace, Virgin Australia Admits Overcharging People
Links for the day
The Dilemma of Web Browsers Lying About What They Are (in Order to Bypass Discriminatory Gateways Like Clownflare) Worsens Due to LLM Slop
LLM crawlers/scrapers have made sites more restrictive and hostile towards browsers that are potent but not "famous"
Companies Conspiring to Keep Salaries Down and Undermine Competition
People who do all the practical work are being paid less and made to work for much longer
Links 14/04/2025: Disinformation, Public Disdain for LLMs, and "Lessons on Tyranny"
Links for the day
Gemini Links 14/04/2025: Ween and Historic Ada Project Management
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, April 13, 2025
IRC logs for Sunday, April 13, 2025
Influencers: Red Hat, Inc's IPO, 1999, post-mortem on the directed share offer to open source developer community
Reprinted with permission from Daniel Pocock
Links 13/04/2025: Microsoft Cuts to "AI" and Azure (It's Failing), ‘Ghiblification’ Shows Slop Doing Much Harm
Links for the day
Links 13/04/2025: Tariff Remorse and Chatbots Leak Again
Links for the day
Gemini Links 13/04/2025: No CSS, Spring Scripting
Links for the day
Richard Stallman Turns 72 and Will Be Giving Talks in Europe Soon
We have many local copies of his talks as WebM, having converted files uploaded to YouTube
Revisionism and Lies by LLM Slop and Lazy "Media"
What happened to investigation of issues?
Exposing Corruption and Crimes Against Women Isn't a Crime, It's an Imperative
When evil and greedy people are so desperate to silence you it typically gives you more motivation - not less - to do more of the same
EPO Likely Breaking the Law Yet Again, This Time by Using Slop for Patents (to Lower Costs While Producing Monopolies That Cause Ruinous Lawsuits)
Nobody authorised this
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, April 12, 2025
IRC logs for Saturday, April 12, 2025
Links 12/04/2025: Tariffs Standoffs and Spam 'Articles' About Patents
Links for the day
Gemini Links 12/04/2025: Isle Release 0.0.4 (Alpha) and Pokemon
Links for the day
Links 12/04/2025: Science and "DEI" Dismantled Further in the US
Links for the day
Links 12/04/2025: "Part of the Problem" and "Facebook Is Just Craigslist Now"
Links for the day
New EPO Leaks: Replacing Patent Examiners and Classifiers With Deficient Bots (Without Even Asking for Permission)
Any consultation about it? Any media coverage? No.
The Consensus is Changing and Web Sites View LLMs as Evil, a Malicious Force of Plagiarism and a Source of DDoS
It's not about "AI" but about plagiarism of sorts
Slopwatch: Lots of Fake Articles About "Linux" Infect the Web, Google News Still Promotes These as 'News'
people who go to a site like google.com or Google News or even social control media (where users get links from Google) will be directed to read slop, i.e. pure garbage.
Gemini Links 12/04/2025: Sigrblot and Conway Calamity
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, April 11, 2025
IRC logs for Friday, April 11, 2025