Bonum Certa Men Certa

Why Microsoft's Security Reports Are a Scam

Microsoft lies



Summary: Microsoft is caught lying again, by essentially patching serious flaws while hiding their very existence

TO PUT it bluntly but rather fairly or at least realistically, Microsoft is a company of systematic liars and nobody should ever trust a word that comes out of their mouths. They believe that these lies are acceptable because they serve some higher goal or that it's a white lie when it helps one's investors or bank account (or perceived sense of security). The examples we have given (e.g. [1, 2, 3, 4, 5]) are too many to list here exhaustively, so we won't attempt to list such examples in a more compelling way.



One point that we stressed and demonstrated several years ago is that Microsoft fakes its reports when it comes to security; people buy their software based on false premises, lack of disclosure, and outright lies.

Putting aside several examples from several years ago, we now have some new examples where Microsoft gets caught (which is hard to achieve because the code is secret). As Slashdot summarised it:

"Microsoft silently patched three vulnerabilities last month, two of them affecting enterprise mission-critical Exchange mail servers, without calling out the bugs in the accompanying advisories, a security expert said on Thursday. Two of the three unannounced vulnerabilities, and the most serious of the trio, were packaged with MS10-024, an update to Exchange and Windows SMTP Service that Microsoft issued April 13 and tagged as 'important,' its second-highest threat ranking. Ivan Arce, CTO of Core Security Technologies, said Microsoft patched the bugs, but failed to disclose that it had done so — which could pose a problem. 'They're more important than the [two vulnerabilities] that Microsoft did disclose,' said Arce. 'That means [system] administrators may end up making the wrong decisions about applying the update. They need that information to assess the risk.'"


Here is the corresponding article.

Microsoft silently patched three vulnerabilities last month, two of them affecting enterprise mission-critical Exchange mail servers, without calling out the bugs in the accompanying advisories, a security expert said today.

Two of the three unannounced vulnerabilities, and the most serious of the trio, were packaged with MS10-024, an update to Exchange and Windows SMTP Service that Microsoft issued April 13 and tagged as "important," its second-highest threat ranking.

According to Ivan Arce, the chief technology officer of Core Security Technologies, Microsoft patched the bugs, but failed to disclose that it had done so.


This has already been covered by The Register too:

A recent security patch from Microsoft silently fixed two severe bugs that were never disclosed even though they posed a risk to many of its customers, a security researcher said.

MS10-024 fixed two flaws that made it possible for adversaries to intercept victims' email messages sent by Exchange and Windows SMTP service, Nicolás Economou, a researcher with Core Security said. But the bugs - which made it "trivial" to spoof responses to domain name system queries - weren't disclosed and were never assigned a Common Vulnerabilities and Exposure identifier, sparking criticism that the critical bugs weren't properly disclosed.


Next time Microsoft shows any comparisons involving a number of flaws or severity of flaws, refuse to accept them. Microsoft is the boy who cried "Wolf!" and the above serves as an example of behaviour that has gone on for years (rarely detected though because it's hard).

Comments

Recent Techrights' Posts

At Least 23 Days of EPO Strikes
Why does the media not deem this newsworthy?
 
IBM Agrees With Microsoft That Slop is Just for "Entertainment" and "at Your Own Risk"
So what can IBM sell now?
Microsoft Windows "Market Share" in USA Down to 40% According to Government Sites or 31% Overall
The world is changing, so do Americans
SLAPP Censorship - Part 45 Out of 200: Garrett and Graveley Cases Inherently the Same, Their Legal Team Can Barely Even Distinguish (Full Timeline)
"million-dollar men"
Gemini Links 13/04/2026: Pronouns for an LLM, Fakecoins Promotion Piggybacking Iran, "Your Face is Now a Search Query"
Links for the day
Links 13/04/2026: Higher Costs Hurt Both Rich and Poor Country, a "Landslide Win to Oust Orban"
Links for the day
Tens of Thousands of Days of Strike at Europe's Second-Largest Institution, Nobody in the Media Has Mentioned It
Since the "extraordinary general meeting"
SPAM That Mentions "AI" 16 Times (in "Security" Clothing, But Selling Back Doors), a Paid Placement in The Register MS
This will doom the reputation of the publication, The Register MS
Links 13/04/2026: Impersonating ProPublica Reporter, More Attacks on the Press (Occupation With Little and No Compensation, Only High Risk)
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, April 12, 2026
IRC logs for Sunday, April 12, 2026
Gemini Links 13/04/2026: Freiburg, GUIX, and Announcing Satellite Antenna (SA)
Links for the day
Links 12/04/2026: Climate, Conflict, and Change in Hungaristan
Links for the day
Gemini Links 12/04/2026: Passports, Science, and Lateral Thinking with Withered Technology
Links for the day
The Energy Crisis Will Likely Carry on and Kill the Slop Industry
To the slop charlatans, "this is the end, my friend..."
SLAPP Censorship - Part 44 Out of 200: Garrett and Graveley 'Copypasta' Sunday (Copy-Paste, Add One Word, Change 'T' to 't')
recycling text
EPO on Strike This Past Friday (All Major Sites), Massive Strike Continues Tomorrow
strikes have trebled, not trembled, compared to last month (in Munich)
Links 12/04/2026: SLAPPs Against Thai Journalists Who Expose High-Level Corruption, Maharlika (Philippines/Marcos) Threatens to Lawyer Up Against GAFAM to Demand Censorship of Critics
Links for the day
Racism and IBM
at IBM and Red Hat people who are hard-working and proficient are now being fired based on their ethnicity and nationality (or either)
When Cruelty is the Point (American SLAPPs in London, the United Kingdom, Europe)
Consider the following
Resistance to SLAPPs in the UK: Coalition Growing
thankfully awareness of SLAPPs in the UK is improving
Links 12/04/2026: Mass Rebellion Against Slop, UK Crackdown on Nudification by Slop
Links for the day
Gemini Links 12/04/2026: "Objective Truth" and Flutter
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, April 11, 2026
IRC logs for Saturday, April 11, 2026
Red Hat: We Kill People, But Please Obey the CoC or We'll Banish You
From Red Hat's own site
SLAPP Censorship - Part 43 Out of 200: Garrett and Graveley Particulars of Claims Almost Identical and 5RB Needs to Investigate Its Barristers (Its Reputation is at Stake)
Scrolling up and down in social control media
Gemini Links 11/04/2026: Floppy Disks on Linux and Junix
Links for the day
statCounter: Microsoft Windows Falls to All-Time Low This Month in France
French government agencies are ordered to move to GNU/Linux
Disgruntled IBMers Explain Why IBM is Circling Down a Death Spiral, Gerstner (Recently Deceased) Destroyed IBM in April 1993, and IBM Now Weaponises PIPs to Attack Its Own
We've just checked if anyone has covered mass layoffs at IBM Red Hat. Nope.
The Central Staff Committee of the EPO Explains Late March Meetings Coinciding With Commencement of the Non-Stop Strikes at Europe's Second-Largest Institution
The fifth meeting report and sixth meeting report show some of the concerns leading up to the mass strikes
Gemini Links 11/04/2026: Critique of Delta Chat and Why Trying to Emulate Centralised, Addictive "Facebook" is Misguided
Links for the day
Links 11/04/2026: Scam Altman’s Trust Issues at OpenAI and EFF Quitting Twitter
Links for the day
Links 11/04/2026: Twitter Presence Considered Harmful to News Sites, "The Future of Everything is Lies"
Links for the day
thenextweb.com (TNW) Appears to Have Become a Slopfarm, Fake Articles About France and GNU/Linux Flood the Web
If you're not against slop, you're part of the problem
Almost 3 Days Later, Still Zero Press Coverage (Except One Publisher) About Mass Layoffs at Red Hat, Almost 500 People Laid Off (Over 400 for Sure)
"A document posted by FOSS advocacy site Techrights appears to be that memo and explains that Red Hat has devised a location strategy under which it has identified key sites for prioritized hiring and strategic workforce investment."
The Register MS, About 6 Million Pounds in Debt, Helps Promote Microsoft's Gartner Group and Prop Up the Ponzi Scheme of Slop Plagiarism, Fake Article Mentions "AI" About 20 Times
What was now known as The Register UK not only works against the interests of the UK; it works for charlatans and frauds
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, April 10, 2026
IRC logs for Friday, April 10, 2026