Bonum Certa Men Certa

Bad September for Microsoft Security, Symantec Buyout Rumours

buying a book



Summary: As loads of security problems occupy the world of Windows, Microsoft resorts to seeking help from security firms it competes with and more botnets thrive nonetheless

Microsoft is having a tough month dealing with many security problems caused by its own weaknesses. This post is a quick accumulation of some issues from the past 2 weeks.



Viruses



Earlier in the month we wrote about the 'Here You Have' virus, which got a lot of news coverage [1, 2, 3]. It was politically motivated:

THE HACKER claiming credit for the 'Here you have' Trojan, written as a blow against the invasion and occupation of Iraq, might be located in Spain.


Cisco says that this virus caused brief havoc. It affects everyone to a certain extent.

Stuxnet



Stuxnet is real bummer which we covered in [1, 2, 3, 4, 5, 6, 7, 8, 9]. "Holes used by the Stuxnet worm remain in Windows XP," said this recent report (there are more) and it is exploiting zero-day flaws. Microsoft liaises with Kaspersky in hopes of tackling this problem. Eventually some patches arrived [1, 2, 3, 4] but only after a lot of damage had been done. It turns out that Symantec -- not just Kaspersky -- helped Microsoft here:

Microsoft has credited security partners at Kaspersky Lab and Symantec for helping to close a critical Windows vulnerability that was being exploited by a sophisticated worm that has attacked industrial plant


Symantec



Earlier this month Symantec created a tie-up with Microsoft's Fog Computing [1, 2]. Then came speculations that Microsoft was looking to buy Symantec. It was just a rumour (likely false), but investors took it seriously and Symantec surged [1, 2, 3, 4, 5]. The stock being driven up like this may always lead to suspicion that someone spread the rumour just to make money in a short-term period. That's illegal of course and the SEC should keep an eye open.

Speaking of acquisitions by Microsoft, "PopCap Rejected $5 Million Microsoft Buyout" says this one report among many more [1, 2, 3]. This one says that "Microsoft tried to convince PopCap it was only worth $5 million, but the studio didn't believe it." To quote another item, 'During an interview with Develop, Jason Kapalka, creative director at PopCap, explained how even Microsoft tried to buy them, but the offer price was a joke: "We had a couple of funny instances in the early years of PopCap where we were talking to Microsoft about a possible acquisition – I think it was in 2002 – and they sat us down and gave us this long speech about why our company was worth 5 million dollars, at a time when we had four million in the bank."'

Fakes



Back to insecurity, an older rogue antivirus attack gave trouble to Windows users this month [1, 2, 3, 4, 5]. It's a form of malware. In an operating system where antivirus software is not necessary, this would hardly be an issue.

ASP.NET



Microsoft is acknowledging that there is a security problem with ASP.NET, as mentioned here last week.

Microsoft has released a security advisory about a vulnerability affecting Web applications built on ASP.NET.


Here is another article about it.

It's already being exploited, based on today's reports:

Attackers have begun exploiting a recently disclosed vulnerability in Microsoft web-development applications that opens password files and other sensitive data to interception and tampering.

The vulnerability in the way ASP.Net apps encrypt data was disclosed last week at the Ekoparty Conference in Argentina. Microsoft on Friday issued a temporary fix for the so-called “cryptographic padding attack,” which allows attackers to decrypt protected files by sending vulnerable systems large numbers of corrupted requests.

Now, Microsoft security pros say they are seeing “limited attacks” in the wild and warned that they can be used to read and tamper with a system's most sensitive configuration files.


Malware



There are many new stories about malware, such as:

i. Report: More Than 1 Million Web Sites Serving Malware in Q2 [via]

Web anti malware firm Dasient has published data claiming that more than 1 million Web sites were compromised in the second quarter, 2010 - a sharp increase.

More than one million Web domains were infected with malicious code in the second quarter of 2010 - around one percent of all active Web domains, according to data released by Web security firm Dasient, Inc.


ii. Pirate Bay beset by tainted ads

The tainted ads exposed visiting surfers to Windows Trojans via drive-by download attacks. Pirate Bay has experienced similar problems in the past, and it's unclear how long it will take to clear up the latest issues.


iii. Study: 33% of SMBs Have Been Infected With Malware From Social Networks

About one-third of small and medium-sized businesses have been infected with malware from social networks like Facebook and Twitter, according to a recent study released by Panda Security, a company specializing in cloud security.


iv. Windows malware dwarfs other viral threats

The vast majority of malware - more than 99 per cent - targets Windows PCs, according to a new survey by German anti-virus firm G-Data.

G-Data reckons 99.4 per cent of all new malware of the first half of 2010 targeted Microsoft’s operating system. Just 0.6 per cent of the 1,017,208 new malware programs discovered in 1H2010 targeted other systems, such as Apple Mac boxes and servers running Unix.


Botnet



When one in two Windows computers is said to be a zombie PC, there is clearly a problem, especially when it goes on for years, still unresolved. Some of the latest Windows botnets stories are:

i. A botnet for hire springs up

Insecurity outfit Damballa revealed that the creatively named IMDDOS (I'm DDoS) botnet can be hired out as "pressure test software" by those who are willing to cough up some cash and download an application. The application is little more than dialogue box allowing the user to point the botnet to a particular IP address and port number and start hitting it with spurious requests.


ii. Microsoft Helps Cox Identify Infected Computers

iii. Microsoft gets legal might to target spamming botnets

iv. Microsoft gets superweapon for fighting botnets

Internet Explorer 8



The very latest version of Internet Explorer is still not so widely adopted because of Microsoft's hostility towards the Web which it still cannot reverse. Here is the latest vulnerability in Internet Explorer 8 [1, 2].

Late last week, a security flaw in Internet Explorer 8 was publicly disclosed to the Full Disclosure mailing list. The flaw allows attackers to steal private information from online services such as web mail and Twitter, allowing attackers to, for example, delete e-mails or send tweets from their victims' accounts.


Exchange



"Microsoft Exchange opens the door for hackers," says The Inquirer.

FIRMS RUNNING Microsoft's Exchange mail server could find that users of its Outlook Web Access (OWA) software have their sessions hijacked.

A security vulnerability in Exchange Server 2003 SP2 and Exchange Server 2007 SP1 and SP2 means that attackers can take control of a user's OWA session and issue commands up to the level permitted by security controls without the user knowing. OWA is a rich 'web mail' client that is offered by Exchange Server and has the look and feel of Microsoft's standalone Outlook software.


According to this, a well-selling Linux phone (not Ballnux) suffers from its reliance on Exchange.

There are rumors that the possible technical problem with the Microsoft Exchange is causing the delay of Android 2.2 Froyo push to Motorola Droid X devices. Multiple news outlets including Droid Life has confirmed the news.


Who needs Exchange anyway? It's just a brand. Android can do better than that and also avert the security problems.

Recent Techrights' Posts

Linux Kernel Tainted by Software Patents That Make Linux Worse and the 'Linux' Foundation is Compiling Bribes to Enable This (Promotion of Monopolies and Tolerance of Software Patenting)
Why you need to reboot when a serious bug is found in Linux? "Licencing"...
Links 04/05/2026: Energy Shortages Become More Visible, Germans Reject Military Service, Merz Says US 'Humiliated' Over Iran
Links for the day
KDE's Cornelius Schumacher Explains Why You Should be Slop-Free
Output is not measured by quantity of words
Links 03/05/2026: Insolvent US Bailing Out Google, Microsoft, Amazon, Nvidia, Oracle, OpenAI, and SpaceX
Links for the day
 
Links 04/05/2026: Economics of Slop Discredited, Democrat and Republican Voters Want Cuts to Data Centres
Links for the day
IBM's "FutureNow" is the Rebranding of the Client Innovation Center (CIC), for Lobbying Purposes by IBM While Halving People's Salaries
So says a new comment
Libera.​Chat Openly and Publicly Admits It Has an LLM Slop Problem (Chatbots in Its Channels)
If there's a policy that bans chatbots (not humans), there's even a moral imperative for it
Microsoft: Yes, We Are Losing Windows Users and Yes, We Have Problems With Payroll (So We Lay Off Essential Workers)
From what we can gather, "hey hi" is now the name of everything at Microsoft
Ubuntu.com While Ubuntu.com is Under DDoS Attack and Intermittently Offline Due to Windows Botnets: Don't Use Ubuntu, Use Windows Instead
Unbelievable, as this is their advice when Windows zombies hammer away at their Web site and general infrastructure
Links 04/05/2026: "DNC Covering Up Its 2024 Autopsy" and Rudy Giuliani in Critical Condition
Links for the day
ChromeOS and GNU/Linux Exceed 5% in New Zealand
Can we expect New Zealand and Australia to divest from GAFAM?
The Real News is Botnets (e.g. Windows With Back Doors), Not Iran
Let's focus on the botnets [...] Microsoft's aim is the opposite of security
SLAPP Censorship - Part 66 Out of 200: Alex Graveley Did Illegal Things, Then Asserted Mentioning Those Illegal Things is Privacy Violation
Alex Graveley "has suffered damage and distress" when the public found out he told women to kill themselves
The Corrupt Lecture the Non-Corrupt - Part XII - Outsourcing Everything to Microsoft, Which is Illegal
Today's EPO isn't about technology or law
Melissa Chan on Why Press Freedom Matters to Everyone, Not Just Journalists
dispelling a myth
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, May 03, 2026
IRC logs for Sunday, May 03, 2026
Gemini Links 04/05/2026: Another Old Web Pillar Gone and Simple Lobsters Mirror for Gemini
Links for the day
SLAPP Censorship - Part 65 Out of 200: Graveley and Garrett Claims Are Word-by-Word Similar (They Also Collaborated All Along)
We'll keep it short today
IBM Has a Long and Rich History of Showing Chatbots Bear No Business Prospects (From Jeopardy to Watson Healthcare and McDonalds)
Watson Healthcare is already in the dustpan, so they are rebranding it again
Europe Decoupling is Bad News for GAFAM, Especially Bad to Microsoft
Countries want independence
India Needs to Recognise That the World Wide Web is Monoculture in India
In the US, a judge with Indian roots dealt with a case related to this; why won't India?
All-Time Lows for Windows Down Under
seeing the demise of Windows in Australia (historically a slow or low adopter of GNU/Linux) is good news
IBM's Kyndryl Accounting Fraud Explained and More Recently the Insiders Talk About Mass Layoffs
Judging by how the media totally ignored 800+ layoffs at IBM's Confluent and 400+ layoffs at Red Hat a few weeks ago don't expect to hear anything about Kyndryl layoffs
Links 03/05/2026: Water Shortages Crises and Slop Fakes "Are Coming for Your Bank Account" (Slop-Enabled Fraud)
Links for the day
All-Time Lows for Windows in Spain and Portugal
data which became publicly available less than 24 hours ago in statCounter
The Corrupt Lecture the Non-Corrupt - Part XI - EPO 'Products' to Cement Asian and American Monopolies
Only a fool would believe Lame Duck Campinos
Microsoft Windows Falls Below 9% in South Africa
As one can expect, GNU/Linux is measured as going up in France
Gemini Links 03/05/2026: The Black Side of the Web, LiveJournal, Chimarrão
Links for the day
A Month Since Mass Layoffs at Red Hat (400+ Engineers Laid Off), The Media Didn't Cover It
We are very concerned about the state of the media
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, May 02, 2026
IRC logs for Saturday, May 02, 2026
Gemini Links 02/05/2026: Strange Psychosis and TUIs
Links for the day
Links 02/05/2026: Microsoft Has Begun Rebranding Vista 11 as 'XBox' (Because the Console is Dying), Slop Rejected by Oscars
Links for the day
IBM's CEO 10 Years Ago in IBM-Sponsored Forbes: "For those willing to embrace [blockchains], the future will indeed be bright."
How well did this prediction materialise?
SLAPP Censorship - Part 64 Out of 200: Not Amused by Repeated Threats (to "Shut Down" My "Existence" While Mentioning My Wife Too)
it's about censorship
RightsCon Cancellation as a Data Point in a World Gone Astray
RightsCon should not even be controversial
The NHS is Under Attack by Anthropic and Microsoft (or Their Lemmings That Infect the NHS)
They are kidding themselves if they seriously believe Web-facing source code repositories are the real threat to patients
cPanel is Not Linux, cPanel is Proprietary Software
It's fair to say I've used cPanel for 23 years
Links 02/05/2026: Gen Z is Turning Against Slop and OpenAI/Microsoft Rift Explained
Links for the day
Storage and Memory Prices Are Rising Not Because of High Demand (Production Can Match Demand), It's Partly Because of Price-Fixing (Same as Food Price Increases)
Sophisticated robberies are still robberies
Thousands of Layoffs at IBM, So IBM Pays Mainstream Media to Claim That IBM is Hiring (Paid Lies)
This is a story about the media failing us, not just IBM failing as a company
A Look at DataStax Bluewashing (IBM and Layoffs)
IBM is a place that many people leave or get pushed out of
Gemini Links 02/05/2026: Leaving Session, Alhena 5.5.7, and Slop Failing Customers
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, May 01, 2026
IRC logs for Friday, May 01, 2026