Bonum Certa Men Certa

All Versions of Windows Vulnerable, Under Attack, So Microsoft Gets Botnets

Water



Summary: A US court gives Microsoft botnets-operating domains after Windows failed to stay in the users' hands (due to faulty design of Windows, lack of disclosure, and lack of urgent patches)

DUE TO Microsoft's insistence on silent patching, it is impossible to know just how many flaws in Windows require fixing (Microsoft is ranked worst for patching). Microsoft says that 13 more are coming, but the real number might be far higher because the company patches without disclosing (for secrecy/vanity purposes).



According to the company’s advance notification for this month’s Patch Tuesday, there will be a total of 9 bulletins (four rated critical) addressing flaws in all versions of Windows, including Windows 7 and Windows Server 2008.


Yes, the 'legendary' Vista 7 too is a block of Swiss cheese. Is anyone surprised? Now that Windows XP is being pulled (SJVN gave some dates and there is corroboration)), some of the world is left to rely on some 'newer' versions of Windows which are not necessarily more secure.

“[W]hen nobody is using Windows, there will be no botnets”
      --Eben Moglen
Professor Eben Moglen said quite recently that "when nobody is using Windows, there will be no botnets" (watch the video where he has even harsher words for Windows).

How about this new report from Ryan Naraine? All versions of Windows appear to be affected by a new worm and OpenBytes says that "victims include Disney, Nasa AIG and others," at least based on the sources Tim read.

Windows is reported to be yet again under attack and as usual it is the end-user who suffers. The BBC is reporting that a worm, spread by unsuspecting souls opening a PDF attached to an email, see’s their Outlook address book hijacked with the worm sending itself out to everyone contained therein.


Those E-mails are sent through botnets, which are of course zombie PCs running Windows. It's a brute force- and remote access-reliant cyber crime. Symantec is concerned:

A fast-moving email worm that began spreading on Thursday has been able to affect hundreds of thousands of computers worldwide, anti-virus provider Symantec warned.

The email arrives with the subject “Here you have.” An executable screensaver that's disguised as a PDF document then tries to send the same message to everyone listed in the recipient's address book. The .scr file is a variation of the W32.Imsolk.A@mm worm Symantec discovered last month.


Watch Microsoft responding. It "Acquired its Own Botnet," said Pogson, pointing to this new report. [via]

CONTROL OVER 275 DOMAINS that are used by operators of the malware botnet Waledac has been given to Microsoft by a US court.

Microsoft can now shut down the sites and the company does not expect an appeal against the judgment. It said that the botnet's operators have objected to the move in other ways, such as launching a denial-of-service attack on its legal team.


This is becoming an embarrassment. Microsoft is getting possession of botnets, which are still being created by the hundreds of millions (in terms of node count), so it's really just a futile attempt to correct the uncorrectable (unless Windows gets abandoned by everyone).

Recent Techrights' Posts

The U.S. Patent and Trademark Office Hijacked Again by Patent Litigation Industry, as President Cheeto Prioritises Aggressors
The "mafia" has taken over the "industry" and the Federal system (justice and constitutions trampled upon)
Ubuntu Slop and FUD Manufactured With LLMs and Funded (by Oneself) 'Studies'
Slop and FUD are ruining the Web
Gemini Links 01/04/2025: Games and More
Links for the day
Why We're Reporting Brett Wilson LLP for Apparently Misusing Their Licence to Protect American Microsofters Who Attack Women
For those who have not been keeping abreast
Stefano Maffulli and His Microsoft-Funded OSI Staff Are Killing the OSI and Killing "Open Source" (All for Money!)
This is far from over
Techrights Headlines as Semaphore
"If you are hearing this, thank you"
 
The Web Can Survive LLM Slop, But Only If We Collectively Shun and Discourage Serial Sloppers
Doing nothing ought not be a possibility
Amid Secret Shut-downs and Mass Layoffs at Microsoft (4 Waves of Layoffs in 3 Months of 2025) Some Microsoft Staff Expected to Go On Strike
workers going on strike
Gemini Links 02/04/2025: No more on Mastodon and Gemini Mention Script in Go
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, April 01, 2025
IRC logs for Tuesday, April 01, 2025
My Motion Disbarring or “Striking Off” Brett Wilson LLP for Enabling Violent Americans Who Try to Crush Microsoft Critics in the United Kingdom by Multiple SLAPPs
"Guns for hire" (for Microsoft people who received Microsoft salaries)
Links 01/04/2025: Apple Fined $162M for Privacy Abuses, Disinformation Online a Growing Concern
Links for the day
Newer Press Reports Confirm That Microsoft Shuts Down 'Hey Hi' (AI) Labs Despite All the Hype
The "hey hi" (AI) bubble is not sustainable
Links 01/04/2025: Mass Layoffs at Eidos and "Microsoft Pulls Back on Data Centers" (Demand Lacking); "Racist and Sexist" Slop From Microsoft
Links for the day
Gemini Links 01/04/2025: XKCDpunk and worldclock.py
Links for the day
50 Years of Sabotage and a Gut Punch to Computer Science (and Science in General)
Will we get back to science-based computing rather than cult-like following?
3 Months in 2025, 4 Waves of Mass Layoffs at Microsoft, Now Offices Shut Down Permanently
"A recent visit by the South China Morning Post confirmed that the office was dark, unoccupied, and had its logo removed."
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, March 31, 2025
IRC logs for Monday, March 31, 2025
Links 31/03/2025: China Tensions, Bombs Falling in Myanmar After Earthquake
Links for the day
Gemini Links 31/03/2025: Falling Out of Love With Tech, Sunsetting openSNP
Links for the day
R.T.O. at IBM in Texas and Atlanta (State of Georgia) Expected as "Soft Layoffs" Catalyst This Coming Year
It also sounds like more IBM layoffs are in the making
Law Firms Can Also Lose Their Licence for Clearly Misusing It
The bottom line is, never made the false assumption that because you can pile up SLAPPs in a docket you will not suffer from bad reputation or even get disbarred
Link between institutional abuse, Swiss jurists, Debianism and FSFE
Reprinted with permission from Daniel Pocock
LLM Slop Piggybacking News About GNU/Linux and Distorting It
new examples
Links 31/03/2025: Press and Democracy Under Further Attacks in the US, Attitudes Towards Slop Sour
Links for the day
Open Source Initiative (OSI) Privacy Fiasco in Detail: The OSI Does Not Respect Anybody's Privacy
The surveillance mafia that bans dissent or key people (even co-founders) with dissenting views
Gemini Links 31/03/2025: More X-Filesposting and Dreaming in Emacs
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, March 30, 2025
IRC logs for Sunday, March 30, 2025