Eye on Security: Microsoft Windows Emergency Patch, Botnets Grab Data, Malware Scam Analysis
- Dr. Roy Schestowitz
- 2010-08-06 12:12:28 UTC
- Modified: 2010-08-06 12:12:28 UTC
Summary: An update on problems Windows users may be experiencing
●
Microsoft rushes out emergency fix for critical Windows bug (
more about this emergency)
Microsoft on Monday rushed out an emergency patch for a critical vulnerability that criminals are exploiting to install malware on all supported versions of the Windows operating system.
●
Botnet with 60GB of stolen data cracked wide open
Most botnet command-and-control channels run on compromised webservers or web-hosting services designed for criminals, making it possible to dismantle the network by taking down the central server. Mumba, by contrast, makes use of fast-flux technology, in which the operations are carried out on thousands of compromised PCs. That allows the IP address and host machine to change every few minutes, a measure that frequently foils takedown attempts by researchers and law enforcement.
●
Anatomy Of An Attempted Malware Scam
The display media segment is the newest target of malvertising, the latest trend in online criminal methodology. The problem has escalated in recent months and despite many suppliers' best efforts, it continues to grow. The culprits behind many of these attacks are based in foreign states leaving little course to take action. While the best defense against malvertising is to prevent it from happening in the first place, this has proven to be a challenge for even the most astute publishers, networks and the like.
We were recently the targets of one such attempt, and while it certainly wasn't the first "fake agency" we've been besieged by (and that we've successfully stopped), it is one of the most organized efforts we've encountered so far. Below we've outlined the approach that was used and the findings of our investigation as an FYI to others who may be on the target list.
Recent Techrights' Posts
- Richard Stallman 'Unveils' His January 20 Talk in Montpellier, France
- It's free (gratis)
- Links 19/01/2025: Gaza Ceasefire and PR Stunt by Fentanylware (TikTok), Faking It by "Going Dark" to Incite American Addicts (Users)
- Links for the day
- They Won't Buy Vista 11 PCs or "Hey Hi" Copilot+++++++ PCs of Microsoft (With TPM)
- Windows at 8%
- No Time Left for President Biden to Pardon Julian Assange
- At least they tried
- Total Lock-down Ambitions - Part IV - The Latest Examples and the Perils (in Summary)
- For further reading take a look at Musial's nice outline
- FOSDEM is Called "FOSDEM" Because of Richard Stallman (RMS)
- The overlap there seems timely; yesterday RMS spoke in French-speaking (in part) Switzerland where questions in French were accepted
-
- Gemini Links 20/01/2025: Magnetic Fields, NixOS, and Pleroma
- Links for the day
- BetaNews Spreads Donald Trump Propaganda, Promotes Scams, and Publishes Fake 'Articles' About "Linux"
- This is typical BetaNews
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, January 19, 2025
- IRC logs for Sunday, January 19, 2025
- [Meme] Hardware RAID and Hardware Raid
- We're expecting attacks on the press in Trump's second term (no need to impress anyone for another election cycle) to be far worse than the first
- What's Running on the Laptops
- 12 months have passed
- [Meme] 404, Not Found
- Kuhn: I'd like to interject for a moment, we made an alliance with the Microsoft-dominated LF to outsource projects to Microsoft GitHub and rich people gave us money to do this
- Links 19/01/2025: TikTok (Fentanylware) Now Banned in the US, Convicted Felon Talks to Fentanylware CEO and Pooh-Tin About Undoing the Ban Despite the Supreme Court Unanimously Upholding It
- Links for the day
- FTC Realises Microsoft Buying Fake 'Clients' to Fake "Revenue" (Microsoft 'Buying' Services and Products From Itself!)
- Ponzi scheme
- Total Lock-down Ambitions - Part III - The Web Browser as DRM Pusher
- A lot of "streaming" stuff is DRM
- Video: University in Peru Honours Richard Stallman
- Tomorrow, January 20, Richard Stallman speaks in France
- IBM Termination Story and Information From Microsoft About Mass Layoffs
- In 2 weeks of 2025 Microsoft already had 2 waves of layoffs
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Saturday, January 18, 2025
- IRC logs for Saturday, January 18, 2025
- Links 18/01/2025: Restoring the Great Wall of China and Economic Expansion in China
- Links for the day
- Guardian Digital (linuxsecurity.com) is Spamming the Web With Microsoft's Promotional LLM Slop About UEFI 'Secure' Boot (Which is Against Real Security)
- This is an attack on honest journalism
- Links 18/01/2025: TikTok's Endgame, "Car Freedom", and Spying in Cars 'Fines' GM (Settlement)
- Links for the day
- January 20: Richard Stallman Talk in Europe
- evening time in Europe, around midday in the United States and Canada
- Links 18/01/2025: Apple Getting Out of Hey Hi (AI) Slop (Too Much Misinformation), Chaffbots/Chatbots Try to Settle Copyright Infringement Lawsuits
- Links for the day
- What Fake News Sites Are Doing to GNU/Linux
- The LLM slop about Linux serves two purposes
- Links 18/01/2025: Microsofters Upset at Microsoft's Ridiculous Rebrands (Excuse for Massive Price Hikes), Chaffbot Company ('Open'AI) Faces More Lawsuits
- Links for the day
- Gemini Links 18/01/2025: Surge in Illnesses, ctags, and Gemsync
- Links for the day
- Slopwatch: Too Lazy to Write Real Articles, Offloading to Chatbots Instead (LLM Slop About "Linux")
- The Web was already full of garbage before the LLM frenzy. Now it's even worse.
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Friday, January 17, 2025
- IRC logs for Friday, January 17, 2025