Eye on Microsoft: Ransomware, Botnets, Critical Flaws, and Insecure Microsoft File Types
- Dr. Roy Schestowitz
- 2009-07-28 07:18:43 UTC
- Modified: 2009-07-28 07:18:43 UTC
●
Smut page ransomware Trojan ransacks browsers
Russian cybercrooks have come up with a variant of ransomware scams, which works by displaying an invasive advert for online smut in users' browsers that victims are extorted to pay to remove.
●
The Business of Botnets
Kaspersky Lab released some interesting statistics recently in a technical whitepaper. As part of its research into the cyber-underground, the company took a look at how botmasters are pricing the networks under their control.
●
Microsoft to fix critical hole in IE
In a rare move, Microsoft on Friday said it would be releasing security updates on Tuesday--outside of its monthly patch cycle--for a critical vulnerability in Internet Explorer and a moderate vulnerability in Visual Studio.
●
Microsoft to Issue Emergency Patches Next Week
The advance notification advisory that Microsoft released about these upcoming patches doesn't say so explicitly, but a spokesperson for the company confirmed that the updates will address a critical security flaw in collection of code that Microsoft uses in a number of places in Windows. Having a vulnerability in this so-called "code library" is especially dangerous because Microsoft also provides this library to third-party software makers to help them build programs that can leverage certain built-in features of Windows.
●
Insecure by design: MS Office formats
You see, when you're opening an Office document today, you're not just opening static words, images, or numbers. You're actually starting a program that uses Microsoft Office as its interpreter. And, no matter whether you're using Word 2,0 formats or the 2008's 7,000+ pages mis-mash of 'standard' ECMA-376 Office Open XML file formats, there is no built-in network security layer. Instead, there is a mis-mash of fixes for one problem or the other.
Also see:
Emergency, Botnets, and No Remedy
Recent Techrights' Posts
- FSFE (Ja, Das Gulag Deutschland) Has Lost Its Tongue
- Articles/month
- Ian Jackson & Debian reject mediation
- Reprinted with permission from disguised.work
- How to get selected for Outreachy internships
- Reprinted with permission from disguised.work
- Red Hat Corporate Communications is "Red" Now
- Also notice they offer just two options: MICROSOFT or... MICROSOFT!
- Links 26/04/2024: XBox Sales Have Collapsed, Facebook's Shares Collapse Too
- Links for the day
-
- Almost 2,700 New Posts Since Upgrading to Static Site 7 Months Ago, Still Getting More Productive Over Time
- We've come a long way since last autumn
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Friday, April 26, 2024
- IRC logs for Friday, April 26, 2024
- Overpaid lawyer & Debian miss WIPO deadline
- Reprinted with permission from disguised.work
- Brian Gupta & Debian: WIPO claim botched, suspended
- Reprinted with permission from disguised.work
- Microsoft's XBox is Dying (For Second Year in a Row Over 30% Drop in Hardware Sales)
- they boast about fake numbers or very deliberately misleading numbers that represent two companies, not one
- [Meme] Granting a Million Monopolies in Europe (to Non-European Companies) at Europe's Expense
- Financialization of the EPO
- Salary Adjustment Procedure at the EPO Challenged
- the EPO must properly compensate staff in order to attract and retain suitably skilled examiners
- Links 26/04/2024: Surveillance Abundant, Restoring Net Neutrality Rules (US)
- Links for the day
- Gemini Links 26/04/2024: uConsole and EXWM and stdu 1.0.0
- Links for the day
- Albanian women, Brazilian women & Debian Outreachy racism under Chris Lamb
- Reprinted with permission from disguised.work
- Microsoft-Funded 'News' Site: XBox Hardware Revenue Declined by 31%
- Ignore the ludicrous media spin
- Mark Shuttleworth, Elio Qoshi & Debian/Ubuntu underage girls
- Reprinted with permission from disguised.work
- Karen Sandler, Outreachy & Debian Money in Albania
- Reprinted with permission from disguised.work
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Thursday, April 25, 2024
- IRC logs for Thursday, April 25, 2024
- Links 26/04/2024: Facebook Collapses, Kangaroo Courts for Patents, BlizzCon Canceled Under Microsoft
- Links for the day
- Gemini Links 26/04/2024: Music, Philosophy, and Socialising
- Links for the day
- Microsoft Claims "Goodwill" Is an Asset Valued at $119,163,000,000, Cash Decreased From $34,704,000,000 to $19,634,000,000 and Total Liabilities Grew to $231,123,000,000
- Earnings Release FY24 Q3
- More Microsoft Cuts: Events Canceled, Real Sales Down Sharply
- So they will call (or rebrand) everything "AI" or "Azure" or "cloud" while adding revenues from Blizzard to pretend something is growing
- CISA Has a Microsoft Conflict of Interest Problem (CISA Cannot Achieve Its Goals, It Protects the Worst Culprit)
- people from Microsoft "speaking for" "Open Source" and for "security"
- Links 25/04/2024: South Korean Military to Ban iPhone, Armenian Remembrance Day
- Links for the day
- Gemini Links 25/04/2024: SFTP, VoIP, Streaming, Full-Content Web Feeds, and Gemini Thoughts
- Links for the day
- Audiocasts/Shows: FLOSS Weekly and mintCast
- the latest pair of episodes
- [Meme] Arvind Krishna's Business Machines
- He is harming Red Hat in a number of ways (he doesn't understand it) and Fedora users are running out of patience (many volunteers quit years ago)
- [Video] Debian's Newfound Love of Censorship Has Become a Threat to the Entire Internet
- SPI/Debian might end up with rotten tomatoes in the face
- Joerg (Ganneff) Jaspert, Dalbergschule Fulda & Debian Death threats
- Reprinted with permission from disguised.work
- Amber Heard, Junior Female Developers & Debian Embezzlement
- Reprinted with permission from disguised.work
- [Video] Time to Acknowledge Debian Has a Real Problem and This Problem Needs to be Solved
- it would make sense to try to resolve conflicts and issues, not exacerbate these
- Daniel Pocock elected on ANZAC Day and anniversary of Easter Rising (FSFE Fellowship)
- Reprinted with permission from Daniel Pocock
- [Video] IBM's Poor Results Reinforce the Idea of Mass Layoffs on the Way (Just Like at Microsoft)
- it seems likely Red Hat layoffs are in the making
- Ulrike Uhlig & Debian, the $200,000 woman who quit
- Reprinted with permission from disguised.work
- IRC Proceedings: Wednesday, April 24, 2024
- IRC logs for Wednesday, April 24, 2024
- Over at Tux Machines...
- GNU/Linux news for the past day