Bonum Certa Men Certa

Conficker is Alive, Windows Vista is Critically Vulnerable and Microsoft Office Likewise

Magaphone
Patchy Tuesdays always get you down



Summary: New evidence for the lingering pattern of vulnerability, arrogance, and lack of responsibility at Microsoft

Conficker has been a colossal PR problem for Microsoft and security headache to its customers. For the uninitiated, here are some previous posts that we wrote about Conficker:



Microsoft would rather pretend that Conficker is history, but it's far from history. In fact, new variants of it are now appearing and Symantec has issued warnings. For the latest details, see:

i. Conficker Worm Strikes Back With New Variant

The Conficker/Downadup worm managed to slither onto millions of PCs worldwide at its height, but after it initially infected a computer it only really acted to spread itself, and didn't cause further harm. Until now.

Symantec reports today that it has found a new variant of the virulent worm that will identify antivirus software or security analysis tools running on the infected PC, and attempt to shut down those programs. This is a strong signal that the worm's mysterious creators haven't abandoned their creation in the face of worldwide attention, as some in the industry have theorized, but may still have plans to make a buck off their work.


ii. Conficker gets upgraded with defenses

Researchers at Symantec have discovered what could be a significant development in the ongoing Conficker worm saga: a new module that is being pushed out to some infected systems.

In a couple of ways, the new component is designed to harden infected machines against an industry consortium that is actively trying to contain the prolific worm. For one, the update targets antivirus software and security analysis tools to prevent them from removing the malware. Not only does it try to disable anti-malware titles, it also goes after programs such as Wireshark and regmon.


It gets worse. The illusion that Windows Vista can be secured is long dead, so no update or upgrade can redeem the user from becoming a zombie (even Vista 7 is open to hijackers [1, 2, 3], long before release). It's the same old routine now that Windows Vista is discovered to be suffering from another "critical" flaw (or set thereof) which has not been patched yet.

March's Patch Tuesday will see yet another critical fix for Microsoft's flagship operating systems.


Users of Microsoft Office will be left vulnerable for at least another month:

Vole said that it will not be fixing a critical Excel vulnerability, which allows attackers to launch malicious code remotely on users' computers via an infected Excel spreadsheet file.


From IDG:

Microsoft Corp. today said it will deliver three security updates on Tuesday, one of them ranked as "critical," but will not fix an Excel flaw that attackers are now exploiting.

All three updates spelled out in today's notice will tackle vulnerabilities in Windows, but as is its practice, Microsoft did not drill any deeper than to specify which versions will be affected.


As usual, Microsoft is hiding the real scale and the real number of vulnerabilities. InformationWeek wrote about this also.

"Our products just aren't engineered for security."

--Brian Valentine, top Windows executive



"It is no exaggeration to say that the national security is also implicated by the efforts of hackers to break into computing networks. Computers, including many running Windows operating systems, are used throughout the United States Department of Defense and by the armed forces of the United States in Afghanistan and elsewhere."

--Jim Allchin, top Windows executive

Comments

Recent Techrights' Posts

At The Register MS, Fake 'Articles' Sponsored by WIntel (Windows+Intel)
We've meanwhile noticed that there's new sponsored spam in at The Register MS and it might be slop
In Addition to National Delegates, Contact the French or Portuguese Governments (Politicians) Regarding António Campinos
Someone needs to step into the EPO and open up all the closets
EPO People Power - Part IV - Sexism, Chauvinism, and Lines of Cocaine at Europe's Second-Largest Institution
Recently, one reader told us about Berenguer, who made the "mistake" of using cocaine in the open market
The Web Has Become Extremely Rude
If you cannot behave, go offline
Like Clickfraud Spamnil (Swapnil Bhartiya) But for Hate Mongering: What Twitter Has Become
If you still waste time in Social Control Media, consider changing course
EPO People Power - Part II - Talking About Corruption
European media must "grow a pair" and start writing about EPO corruption
Circular Funding
Passing around capital that does not exist (for PR's sake, but there are ramifications)
 
Gemini Links 11/12/2025: Repairs, Wisdom of the Crowds, and AC Explorations
Links for the day
Those of Us Who Grew Up Playing Doom Must Remember What Microsoft Did to Its Creator
Doomed by Microsoft
We Need Your EPO Insider Stories
To date, the EPO and any other company/institution hasn't managed to remove even a single public page that we published
Yes, IBM is Also Laying Off Indians (Even in India)
that goes against the popular/hot narrative of "jobs moving to India"
Microsoft-Sponsored Wikipedia Spam About "AI", Added by Microsoft Operatives
When it comes to Wikipedia, follow the money (sponsors)
Keep on Pushing, EPO Management is in a State of Panic This Week
Contact your representatives today
If You Want Freedom, Follow Richard M. Stallman (RMS)
To be clear, I like Linux, I like its founder
EPO People Power - Part III - Challenging Corruption
The media - as in the national press - isn't interested in writing about it
The Flawed Notion of Criticising for Criticism's Sake
People who are highly critical of things are not "toxic"
A Lot More Than Techrights
you probably also want to follow the RSS feed of the sister site
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, December 10, 2025
IRC logs for Wednesday, December 10, 2025
Slopfarms Parrot Any Number That GAFAM Throws at Them, Even Totally Fictional Figures That Merit Fact-Checking
fake from Microsoft
Microsoft Lunduke Tailors His 'Content' for 4Chan
The latest from Lunduke "Journal"
Richard Stallman Was Also Right About Microsoft GitHub (It's Becoming a Botfarm)
trashing the platform
Democracy and Buzzwords
and hype
Five Years in Gemini Protocol
One might say we escaped to Geminispace 2 years before the deluge of slop on the Web
Keeping Up the Pressure on EPO Management
We want to thank our European readers who contacted their representatives
For New PCs and for Old (or Retro) PCs the Increased Cost of System Memory Benefits GNU/Linux and BSDs
GNU/Linux does not have this problem or barely has this problem
Gemini Links 10/12/2025: "Thousand Mile Journey" and The Art Of Chilling
Links for the day
Moving Away From Content Management Systems (CMSs) and Flocking to Static Site Generators (SSGs)
The SSG 'hype' is not based on marketing but a simple reality
IBM is Laying Off Workers in India (While Spending a Fortune Buying a Company for Buzzwords, a Box-Ticking Exercise)
So what is the overall strategy?
Just a Little Slop About "Linux"
Slop about Linux isn't that common anymore
Links 10/12/2025: McDonald’s Latest Slop Gaffe (After Dumping IBM's Slop) and "Scam Altman’s Panic Sweats"
Links for the day
Links 10/12/2025: Ransomware (Windows TCO) Has Crippled Economies, Slop (Fake) "Videos Have Flooded Social (Control) Media"
Links for the day
Y Combinator (YC) Funds Scams, Run by Scammers
Including Scam Altman
EPO People Power - Part I - Identifying Corruption
The EPO, at this stage, is a boat full of holes
IBM Has Become a "Plantation"
IBM is basically being destroyed for some cash at this point
It's Not Too Late to Send an E-mail to Your European Representative Regarding European Patent Office Abuses
If you live in Europe and have not done so already, please contact your national delegates, whose job is (at least on paper) to represent you
Almost a Thousand EPO Workers Have Voted for Industrial Action
Mandate given to SUEPO for action plan to stop the salary erosion of EPO staff
Why So Many Software Projects Are Quitting Microsoft and GitHub
Be more like LibreWolf. Move away from Microsoft and GitHub.
Many of the Attacks on Us Apparently Boil Down to Jealousy
Envy is a negative trait that leads people to self harm
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, December 09, 2025
IRC logs for Tuesday, December 09, 2025
Valuing One's Work by the Effort or Budget Taken to Undermine It
As long as what we publish is factual, nothing prevents its publication
IBM Says It Buys Another Company for "AI", So Why Does IBM Fire Its Own "AI" Experts?
As people rightly point out, this has nothing to do with "AI"
The Boundaries of Criticism
The harder the EPO will push back, the better the job we must have done
New EPO Series: Mafia Culture, Mobbing, Nepotism, and Illegal Drugs
The series shall start later today
Richard Stallman Was Right About "AI"
"Considering Stallman worked in the MIT AI lab in the era of symbolic AI, and has written GCC (an optimizing compiler is a kind of symbolic reasoner imo), I think he has a deeper understanding of the question than most famous people in tech."
With 3 Weeks Left (Sans Extensions) the Free Software Foundation (FSF) Has Already Raised About Half of the Money Set as Fund-Raising Goal
“Idiots can be defeated but they never admit it.” — Richard Stallman
Gemini Links 10/12/2025: Cranberry Juice and Gramophones
Links for the day
IBM: We Lay Off Tens of Thousands of People the Very Same Week We Spend 11 Billion Dollars (Debt) on "AI" Fantasies, Hiring About 8,000 People at Cost of 1.3+ Million Dollars Per Employee
Seems like IBM is run by fools
Google Still Promotes Plagiarism From WebProNews and Prolific Slopfarms
Google News seems lost and hopeless sometimes
Links 09/12/2025: Tariffs Causing Great Harm and "How to Leave the U.S.A."
Links for the day
Links 09/12/2025: "After the Bubble" (of Slop), "The Internet Forgets"
Links for the day
Gemini Links 09/12/2025: Lunar Observations and Programming
Links for the day
Linux Foundation Has Found a New Business: Pyramid Schemes
Linus Torvalds should have known better
They Won't Tell You This ("Revolution Won't Be Televised"), But the Slop Bubble Already Burst
We already wrote about it twice this morning
UbuntuPIT Started Experimenting With LLM Slop and a Month Ago It 'Died'
This is the typical trajectory of slopfarms
LibreWolf Will Turn Six in March, It Already (Probably) Has Millions of Users
It's not possible to know the number of users LibreWolf has
The Year of the New Dark Age
Something isn't right
Slopwatch May be Doomed
Slop isn't changing the world, certainly not in a good way anyway
BetaNews Still a Dodgy Site, It Seems to be Partly Run by Chatbots
The company that took over apparently tries to "monetise" the domain with slop
Tomorrow the EPO Administrative Council is Meeting to Discuss the EPO, Contact Your National Representative Today
Final versions of the EPO Administrative Council photo gallery
IBM's Total Debt is About to Hit Almost 80 Billion Dollars, the Company Can Only Raise $14.8 Billion Within 3 Months
Route towards insolvency, not just irrelevancy
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, December 08, 2025
IRC logs for Monday, December 08, 2025