Bonum Certa Men Certa

Microsoft's Latest Harms to the Web and Shallow Press Coverage That Neglects to Name Culprits

Duck gossip



Summary: Coverage about security issues is abundant, but the cause of many of these issues is simply not named

MANY companies in the West had their security measures superseded and breached due to an Internet Explorer hole that Microsoft had knowingly ignored for 5 months [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12]. Microsoft is now warning that Internet Explorer is under another attack:



In an advisory, the company warned that a new vulnerability was being targeted in attacks against Internet Explorer 6 and 7. IE 8 is not believed to be affected. According to Microsoft, the vulnerability is due to an invalid pointer reference being used within IE and can be exploited by tricking users into visiting a malicious or compromised Web page.


This is a Windows problem because Internet Explorer is a part of Windows, which therefore inherits all the weaknesses of one piece of software that ought to have been isolated. The consequences of Windows' insecurity can also be seen in the following news:

1. Vodafone ships malware infested mobiles

Upon further investigation, the phone was found to be infected with not one but three nasties, including the Conficker worm, a Mariposa bot client and a Lineage password divulger. The firm found that the Mariposa bot client was calling home to receive further instructions.


With a "password divulger", banks are at risk:

2. Online banking fraud losses rise 14%"

Number of 'phishing' attacks have risen to 51,000 from just 1,700 five years ago, according to the UK Cards Association


Also:

3. Twitter Fights Phishing, Malware with Link Scanning Service

Twitter has announced it will begin scanning links posted by users to thwart phishing attacks and the spread of malware on the site.


Notice how the articles typically neglect to say that such malware only affects Windows users. On we move to:

4. 10 Reasons Why Security Problems Persist at Microsoft

News Analysis: As much as Microsoft would like security problems to just go away, they won't. The chances of Microsoft eliminating most of the software flaws that invite new attacks are slim to nil. But there are many things that Microsoft should do to improve the situation. We take a look at why security issues continue to haunt the software giant and what Microsoft can do about it.

[...]

2. Windows is an easy target

Windows is a nightmare when it comes to security. The operating system is filled with holes that, over the years, have been patched with varying degrees of success. Windows 7 is the most secure operating system Microsoft has released to date, but it's probably rife with flaws that Microsoft hasn't heard of yet. And no doubt hackers are ceaselessly searching for them. Unless Microsoft does something drastic with the next iteration of Windows, its operating system woes will likely continue.


We do not agree with the article as a whole, but it does raise some important points. The security weaknesses of Windows produce botnets rather easily:

5. Zeus botnets suffer mighty blow after ISP taken offline

At least a quarter of the command and control servers linked to Zeus-related botnets have suddenly gone quiet, continuing a recent trend of takedowns hitting some of the world's most nefarious cyber operations.


This is a Windows botnet (but it doesn't even say "Windows botnet"). What's sickening is that Microsoft is only mentioned in this article where it's given credit. It says: "Late last month, Microsoft was able to disrupt the Waledac botnet by obtaining a court-issued order against scores of domains associated with the spam-spewing menace."

Giving Microsoft credit for the Waledac takedown [1, 2, 3, 4] is like giving DuPont credit for some minimal cleanup after the Bhopal disaster. Microsoft employees are given credit for fighting a problem that they themselves created. It's truly amazing, especially given that those Windows botnets are costing huge amounts of money that is hard to estimate (dependent upon definitions and methods).

Here is the EFF discussing Microsoft's takedown of an important Web site, not a Windows botnet.

We often criticize DMCA takedown abuse here at EFF, but last week's Cryptome snafu highlights another facet of the problem: how a DMCA takedown for one item can result in the removal of lots of lawful material.

To recap, Cryptome posted Microsoft’s global criminal compliance manual. Microsoft sent a DMCA takedown notice to Cryptome’s domain name registrar and web hosting provider, Network Solutions, alleging that the post infringed copyright. Under the DMCA, a web hosting provider is protected from copyright infringement liability if, among other things, it “expeditiously” disables access to material properly identified in a DMCA takedown notice. Network Solutions asked Cryptome to remove the Microsoft compliance manual. Cryptome refused explaining that the document was posted in order to help the public better understand Microsoft's practices, and followed up with a DMCA counternotice. Network Solutions promptly shut down the entire Cryptome website. Thus, a complaint about a single document caused significant collateral damage to the perfectly legal material on Cryptome.


We have already covered this in another post. Microsoft can stop people who leak evidence of its warrantless spying, whereas those who empty bank accounts through compromised Windows PCs are not a priority. There are hundreds of millions of them.

Comments

Recent Techrights' Posts

Legal Attacks on Techrights Have Made Techrights More Popular and More Widely Read
The misogynists will have plenty of work to do this summer
SLAPP Censorship - Part 142 Out of 200: GemText is Not a Webpage, Gemini Protocol is Not the Web, and Capsules Are Not Websites
our intention to appeal (escalate to the Court of Appeal)
 
Links 08/08/2026: "Palantir Paid No Federal Income Tax" and "Who's Responsible for This Mess?"
Links for the day
Retained: The Time IBM's Red Hat Tried to Hijack or Take Offline Site of Critics, Failed on All Grounds (Meritless Action Intended to Harass Critics)
Replicated from adrforum.com
IBM's 'Final Solution': Censor Sites Not Controlled by IBM, Sites Where Dissent is Expressed
IBM has no culture of free speech
More Mass Layoffs Coming IBM's Way (Ones IBM Cannot Hide, Cannot Convince Enough People to Leave or Unjustifiably PIP Them When They Say No)
The company that was like a "father of modern computing" is now stingy when it comes to travel. Not a good sign.
What Will it Take for Mainstream Media to Report Silent or Secret Layoffs at IBM?
"Silent" or "secret" sometimes because the media won't cover them
Is the Future of IBM Red Hat Temporary Staff, Contractors?
They want cheap, obedient lemmings
Gemini Links 08/08/2026: Tribute to Lloyd Center, Radio Amateurism, Homeworlds
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, August 07, 2026
IRC logs for Friday, August 07, 2026
Microsoft Uses Slop to Find Defects and Then Uses Slop to Replace Code, What Could Go Wrong?
Botspam is the problem, it's not a constructive approach in any shape or form
analytics.usa.gov: GNU/Linux Up Some More This Week
Days ago it said 6.4%, now it's up to 6.8%
RA-pocalypse: IBM Tells Workers "Taking a Hike" is Their "Next Step" ('Voluntary' Layoffs), Now It Prepares to Sack Lots of Contractors
There definitely is something going on
Kai Stephens (Barkley Walsh) & British Democrats in Clacton by-election hustings
Reprinted with permission from Daniel Pocock
Daniel Pocock 'Punching' Nazis in the UK
The so-called "cult" of so-called "Debianism" was left with nothing but massive legal bills
Microsoft: Our August 2026 Layoffs Are Not Layoffs Because... Reasons
That's like IBM making "spin-offs", then pretending that no layoffs are happening
Links 07/08/2026: UMG and Anthropic in Trouble Over Copyright Infringements Sold as "Training" (Slop)
Links for the day
Links 07/08/2026: "BMW Is Showing Commercials On Their Car's Dash Screens And They Want You To Think It's A Treat", Software Patents on Drones
Links for the day
What We Said About Red Hat's Fate Under IBM Turned Out to be Right on the Money (That IBM Lacks)
There are no layoffs at IBM
IRC Networks Show No Signs of Going Away, IRC Enters Its 39th Year
That IRC daemons are still actively developed and patched in summer of 2026 (over 38 years after IRC was born) says a lot about IRC's importance
Social [Control] Media Needs to Die
I am a bit shocked to recall that I wasted a lot of time on it
Some Malware is Legal Because It's Made and Distributed by Politically-Connected GAFAM
In reality, the security non-experts 'championed' (and salaried) by GAFAM are anti-security people who advocate back doors
The GNU/Linux Anniversary is Next Month, Not This Month
It'll turn 43
At Clacton by-election Hustings Event Daniel Pocock Says "Social [Control] Media Has Contributed to Some of the Anti Social Behaviour."
No doubt many problems in society are caused or at least amplified/accentuated by this horrible phenomenon
IBM Insiders Explain Why IBM is in Very Serious Trouble
Will IBM last long enough for any "quantum" deliverables to become a reality?
The Register MS Took Money From Broadcom to Publish Fake 'News' With "AI" Mentioned 35 Times
not legitimate or authentic journalism.
GNU/Linux Approaching 20% in Georgia (the Country)
Usage of GNU/Linux was near 0%, as measured by statCounter, several years ago
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, August 06, 2026
IRC logs for Thursday, August 06, 2026
Gemini Links 07/08/2026: Radio Amateurism, Summer Updates, and Programming "Taste"
Links for the day
Links 06/08/2026: Billboard Chart Contaminated by Slop Plagiarists, Sheinbaum Blasts Social Control Media
Links for the day
A Long Break and What's Coming Next Year
Some time next year we definitely plan to show how the EFF failed women, failed bloggers, and basically prioritised GAFAM
Daniel Pocock on a "metre-long ballot paper"
The Debian "cult" (as he calls them collectively) is simply jealous of him
Links 06/08/2026: Disney and Fentanylware (TikTok) Deal, "Hearing Aids Shenanigans"
Links for the day
IBM Mass Layoffs Began Yesterday, They're Sold as "Voluntary", the "Offer" Runs for Two Weeks (Last Day August 19th 2026)
IBM will self-detonate while using contractual agreements to force people to smile
Start of September 2026 'Voluntary' Mass Layoffs at IBM, Start of October Red Hat Employees Forced Into the 'Bloodbath' (After Collapse of IBM's Shares)
Red Hat is in trouble
Many GNU/Linux PCs Are Not Connected to the Net or Don't Use the Web
Saying GNU/Linux user-agents are just "bots" (Microsoft Lunduke and other Microsofters say this) is like asserting that the Twin Towers fell not because of two giant planes but because of explosives
They Call Occupations "Professions" Because the "Pro" Means Something
If you want to find tech news online
New Conference Paper (Science of Cyber Security) Credits RMS With Delaying Passwords
When it comes to passwords, RMS was "right"
Removing Gender Barriers in Computer Science
It is not that "women aren't good at maths"
In Brunei, GNU/Linux Approaches International Average of 8.5%
a sharp rise from 0% to about 7.5% happened in a few years
15% of IBM Staff Marked for Layoffs ("RAs"), the Workers' Objective is to Find Another Employer and Leave
"That's not a workforce, that's a waiting room."
Maintenance to be Completed Tonight (IPv6)
Notice how, after 25+ years, we're still not fully adopting IPv6, we're only about 50% there
A Data Centres Hub Puts Everyone at Risk, Especially People Who Live Near Them at Times of War/s
Spoiler: Datacentres are military targets, they attract missiles, some with nuclear warheads
GAFAM Mass Layoffs and Mountains (Trillions of Dollars in 'Secret' or 'Off-the-Ledger') Debt
GAFAM is having layoffs this month
August 2026 Microsoft Layoffs Confirmed by Staff This Week
It's hard to assess how many are impacted but signed an NDA, preventing them from speaking about what really happened
analytics.usa.gov Says 7% of Sessions Come From GNU/Linux and ChromeOS. If ~40% (Mobile) Get Omitted, It's More Like 11%.
In desktops and in laptops GNU/Linux has become a big player
IBM Cannot Survive for Much Longer, There Are Limits to RAs and Offshoring, IBM Now Asks Workers to Quit
IBM is in very serious trouble
SLAPP Censorship - Part 141 Out of 200: Brett Wilson LLP Failed to Learn From the Mistakes of the European Patent Office (EPO)
my solicitor, David Allen Green, put them in their place
Texts of the Claims From Balabhadra (Alex) Graveley and Matthew J. Garrett Almost Identical, I am Suing for Abuse of Process
Half a decade ago Balabhadra (Alex) Graveley from Microsoft and GNOME was arrested for strangulation in Texas
Gemini Links 06/08/2026: "Eat That Frog", Mutt Terminal Email Guide, and BASICODE
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, August 05, 2026
IRC logs for Wednesday, August 05, 2026