Eye on Microsoft: Emergency, Botnets, and No Remedy
- Dr. Roy Schestowitz
- 2009-07-26 08:50:30 UTC
- Modified: 2009-07-26 08:50:30 UTC
Summary: Self-explanatory news about Microsoft and security
●
Microsoft to issue emergency patches next week
Microsoft plans to issue two emergency patches next week that fix vulnerabilities in the Internet Explorer browser and Visual Studio developer suite that allow attackers to remotely execute malware.
●
Software Crackdown
Cyber attacks seem to be getting more sophisticated by the hour. A few weeks ago malware known as Zero Day was found to have exploited a vulnerability in Microsoft's Windows operating system that could allow online criminals to take control of a computer from anywhere in the world without being detected. The operation involved what is known as "drive by" attacks, in which visitors to legitimate Web sites are redirected to a page that secretly downloads the malicious software.
●
Microsoft admits it can't stop Office file format hacks
Microsoft's plan to "sandbox" Office documents in the next version of its application suite is an admission that the company can't keep hackers from exploiting file format bugs, a security analyst said today.
Recent Techrights' Posts
- The U.S. Patent and Trademark Office Hijacked Again by Patent Litigation Industry, as President Cheeto Prioritises Aggressors
- The "mafia" has taken over the "industry" and the Federal system (justice and constitutions trampled upon)
- Ubuntu Slop and FUD Manufactured With LLMs and Funded (by Oneself) 'Studies'
- Slop and FUD are ruining the Web
-
- Gemini Links 02/04/2025: Books and Cold Tea
- Links for the day
- Links 02/04/2025: More Layoffs, Nokia Again Takes Advantage of Illegal and Unconstitutional Patent Court With Nokia Staff as 'Judges'
- Links for the day
- Links 02/04/2025: Seizures and Returns to Windows of 24 Years Ago
- Links for the day
- LLM Slop Helps Obscure and Distort News About Layoffs (IBM, GAFAM)
- It's hard to find accurate information
- Links 02/04/2025: Microsoft Developers Are Threatening to Go on Strike, World Backup Day Noted
- Links for the day
- Gemini Protocol Has Growing Appeal (the Web Got Too Bloated and Full of LLM Slop)
- For any "data plan" with bandwidth limits or "tiers" it would be cheaper to use/browse Geminispace
- The Web Can Survive LLM Slop, But Only If We Collectively Shun and Discourage Serial Sloppers
- Doing nothing ought not be a possibility
- Amid Secret Shut-downs and Mass Layoffs at Microsoft (4 Waves of Layoffs in 3 Months of 2025) Some Microsoft Staff Expected to Go On Strike
- workers going on strike
- Gemini Links 02/04/2025: No more on Mastodon and Gemini Mention Script in Go
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Tuesday, April 01, 2025
- IRC logs for Tuesday, April 01, 2025
- My Motion Disbarring or “Striking Off” Brett Wilson LLP for Enabling Violent Americans Who Try to Crush Microsoft Critics in the United Kingdom by Multiple SLAPPs
- "Guns for hire" (for Microsoft people who received Microsoft salaries)
- Gemini Links 01/04/2025: Games and More
- Links for the day
- Links 01/04/2025: Apple Fined $162M for Privacy Abuses, Disinformation Online a Growing Concern
- Links for the day
- Why We're Reporting Brett Wilson LLP for Apparently Misusing Their Licence to Protect American Microsofters Who Attack Women
- For those who have not been keeping abreast
- Newer Press Reports Confirm That Microsoft Shuts Down 'Hey Hi' (AI) Labs Despite All the Hype
- The "hey hi" (AI) bubble is not sustainable
- Links 01/04/2025: Mass Layoffs at Eidos and "Microsoft Pulls Back on Data Centers" (Demand Lacking); "Racist and Sexist" Slop From Microsoft
- Links for the day
- Stefano Maffulli and His Microsoft-Funded OSI Staff Are Killing the OSI and Killing "Open Source" (All for Money!)
- This is far from over
- Gemini Links 01/04/2025: XKCDpunk and worldclock.py
- Links for the day
- 50 Years of Sabotage and a Gut Punch to Computer Science (and Science in General)
- Will we get back to science-based computing rather than cult-like following?
- Techrights Headlines as Semaphore
- "If you are hearing this, thank you"
- 3 Months in 2025, 4 Waves of Mass Layoffs at Microsoft, Now Offices Shut Down Permanently
- "A recent visit by the South China Morning Post confirmed that the office was dark, unoccupied, and had its logo removed."
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Monday, March 31, 2025
- IRC logs for Monday, March 31, 2025
- Links 31/03/2025: China Tensions, Bombs Falling in Myanmar After Earthquake
- Links for the day
- Gemini Links 31/03/2025: Falling Out of Love With Tech, Sunsetting openSNP
- Links for the day
- R.T.O. at IBM in Texas and Atlanta (State of Georgia) Expected as "Soft Layoffs" Catalyst This Coming Year
- It also sounds like more IBM layoffs are in the making
- Law Firms Can Also Lose Their Licence for Clearly Misusing It
- The bottom line is, never made the false assumption that because you can pile up SLAPPs in a docket you will not suffer from bad reputation or even get disbarred
- Link between institutional abuse, Swiss jurists, Debianism and FSFE
- Reprinted with permission from Daniel Pocock
- LLM Slop Piggybacking News About GNU/Linux and Distorting It
- new examples
- Links 31/03/2025: Press and Democracy Under Further Attacks in the US, Attitudes Towards Slop Sour
- Links for the day
- Open Source Initiative (OSI) Privacy Fiasco in Detail: The OSI Does Not Respect Anybody's Privacy
- The surveillance mafia that bans dissent or key people (even co-founders) with dissenting views
- Gemini Links 31/03/2025: More X-Filesposting and Dreaming in Emacs
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, March 30, 2025
- IRC logs for Sunday, March 30, 2025
Comments
David Gerard
2009-07-26 19:01:17
Roy Schestowitz
2009-07-26 19:28:25
Forget about malicious programs. When we have binary formats we also deal with malicious file formats and files that become malicious when merely interpreted, not executed.
David Gerard
2009-07-26 20:33:59
(a) in the '90s, Microsoft made a lot of their file formats dumps of C structs, for performance reasons;
(b) when this became incredibly hazardous with the Internet, and computers were powerful enough to check for malicious input ... they just kept on using the old code.
Then their master stroke of putting a complete programming language inside Office, thus inventing the macro virus.
Then their other master stroke of programs that execute any random instructions they happen to find in EMAIL MESSAGES.
INNOVATION!