Bonum Certa Men Certa

Eye on Security: BBC Propaganda, Rootkits, and Stuxnet in Iran's Nuclear Facilities

Sadeh fire festival



Summary: Some of the latest security news which affects only Windows users (or people whom Windows is using)

HERE are some security news picks from the past week.



MSBBC



Not a week goes by without some BBC propaganda such as this. Since many former Microsoft UK employees took leading positions in the BBC, new articles like this neglect to mention major facts like the scary story only referring to Windows and not computers by and large (BBC Click is encouraging similar narrow-mindedness right now).

"BBC's usual high standards: no mention of MS Windows," wrote Glyn Moody in response to it. Gordon from TechBytes wrote: "Yet another Windows only story "forgetting" to mention either "Microsoft" or "Windows" #fail !BBC" (he claims to have had a "deja-vu, found another the other day").

Ask the BBC to call out Windows and thus inform the public. "Computer" is not the same as "Microsoft Windows" and taxpayers who fund the BBC deserve to know this.

The rest of the security news is tediously repetitive (yet new), so we just add it below categorised.

Rootkit



i. More Layers, Please

M$ has put many coats of paint on the old barn to secure that other OS but the malware writers have discovered a way to alter the MBR data so that rebooting turns off some of the layers of protection. The result is rootkits on the beloved 64bit “7″. Fortunately, our 64bit machines run Debian GNU/Linux. You need physical access to the machine or root access to alter the MBR with GNU/Linux. That other OS provides the tools by default… The modifications to UAC after the Vista fiasco opened the door to this rootkit. Malware artists have been going through this door since August.


ii. Rootkit able to bypass kernel protection and driver signing in 64-bit Windows

The 64-bit version of the Alureon rootkit / bot is able to bypass the special security features included in the 64-bit versions of Windows 7 and Vista and insert itself into the system. The tricks used have been known about in theory for several years, but until recently had not been used by malware in the wild. The 32-bit version of Alureon made headlines early this year, when the installation of a Microsoft patch left many systems unable to boot. The problem was caused by the previously unnoticed presence of the rootkit, which the patch effectively unmasked.

The 64-bit version of Alureon (aka. TDL) deactivates checks for driver signing and, even during the boot process, reroutes specific API calls in order to bypass the kernel's PatchGuard mechanism. Driver signing is intended to ensure that Windows only loads drivers from known vendors. PatchGuard is intended to protect the operating system kernel from being modified by malicious code.


Stuxnet



i. Stuxnet has a double payload

According to the latest analysis, Stuxnet is aimed not at disrupting a single system, but at two different systems. According to control systems security firm Langner Communications, the worm is not just designed to interfere with specific, variable frequency, motor control systems – it also attempts to disrupt turbine control systems. According to Langner, this would mean that, in addition to Iran's uranium enrichment plant at Natanz, the country's Bushehr nuclear power plant may have been a further target of the Stuxnet attack.

Specialists have been puzzling over the worm's target for several weeks, with early rumours circulating that it was aimed at sabotaging Natanz or Bushehr. However, no-one initially suspected that its aim was to sabotage both plants, although clues that this might be the case have been emerging for some time. Stuxnet attacks Siemens control system types S7-300 (315) and S7-400 (417). The attack modules appear to have been created using different tools – probably even by different teams.

The code for the S7-417 system – used in the turbine control systems at Bushehr – is reported to be much more sophisticated than that for the S7-315 system. The code carries out what amounts to a man-in-the-middle attack in order to pass fake input and output values to the genuine plant control code. User code running on a programmable logic controller (PLC) does not usually query I / O ports directly, but instead reads from an input process image and writes to an output process image. Mapping of physical ports to logical ports is intended to ensure that I / O values do not change during processing cycles.


ii. Stuxnet virus could target many industries (from AP, copyright maximalist and fair use squasher)

A malicious computer attack that appears to target Iran's nuclear plants can be modified to wreak havoc on industrial control systems around the world, and represents the most dire cyberthreat known to industry, government officials and experts said Wednesday.

They warned that industries are becoming increasingly vulnerable to the so-called Stuxnet worm as they merge networks and computer systems to increase efficiency. The growing danger, said lawmakers, makes it imperative that Congress move on legislation that would expand government controls and set requirements to make systems safer.


iii. Stuxnet Was Designed To Subtly Interfere With Uranium Enrichment

"Wired is reporting that the Stuxnet worm was apparently designed to subtly interfere with uranium enrichment by periodically speeding or slowing specific frequency converter drives spinning between 807Hz and 1210Hz. The goal was not to cause a major malfunction (which would be quickly noticed), but rather to degrade the quality of the enriched uranium to the point where much of it wouldn't be useful in atomic weapons. Statistics from 2009 show that the number of enriched centrifuges operational in Iran mysteriously declined from about 4,700 to about 3,900 at around the time the worm was spreading in Iran."


iv. Clues Suggest Stuxnet Virus Was Built for Subtle Nuclear Sabotage

The malware, however, doesn’t sabotage just any frequency converter. It inventories a plant’s network and only springs to life if the plant has at least 33 frequency converter drives made by Fararo Paya in Teheran, Iran, or by the Finland-based Vacon.

Even more specifically, Stuxnet targets only frequency drives from these two companies that are running at high speeds — between 807 Hz and 1210 Hz. Such high speeds are used only for select applications. Symantec is careful not to say definitively that Stuxnet was targeting a nuclear facility, but notes that “frequency converter drives that output over 600 Hz are regulated for export in the United States by the Nuclear Regulatory Commission as they can be used for uranium enrichment.”

“There’s only a limited number of circumstances where you would want something to spin that quickly -– such as in uranium enrichment,” said O Murchu. “I imagine there are not too many countries outside of Iran that are using an Iranian device. I can’t imagine any facility in the U.S. using an Iranian device,” he added.


More links about Stuxnet:

  1. Ralph Langner Says Windows Malware Possibly Designed to Derail Iran's Nuclear Programme
  2. Windows Viruses Can be Politically Motivated Sometimes
  3. Who Needs Windows Back Doors When It's So Insecure?
  4. Windows Insecurity Becomes a Political Issue
  5. Windows, Stuxnet, and Public Stoning
  6. Stuxnet Grows Beyond Siemens-Windows Infections
  7. Has BP Already Abandoned Windows?
  8. Reports: Apple to Charge for (Security) Updates
  9. Windows Viruses Can be Politically Motivated Sometimes
  10. New Flaw in Windows Facilitates More DDOS Attacks
  11. Siemens is Bad for Industry, Partly Due to Microsoft
  12. Microsoft Security Issues in The British Press, Vista and Vista 7 No Panacea
  13. Microsoft's Negligence in Patching (Worst Amongst All Companies) to Blame for Stuxnet
  14. Microsoft Software: a Darwin Test for Incompetence
  15. Bad September for Microsoft Security, Symantec Buyout Rumours
  16. Microsoft Claims Credit for Failing in Security
  17. Many Windows Servers Being Abandoned; Minnesota Goes the Opposite Direction by Giving Microsoft Its Data
  18. Windows Users Still Under Attack From Stuxnet, Halo, and Zeus
  19. Security Propaganda From Microsoft: Villains Become Heroes
  20. Security Problems in iOS and Windows


Messenger



i. Microsoft disables Live Messenger links

According to the Vole's blog, disabling the feature was designed to prevent the spread of a malicious worm.

The worm requires users to click a link within a message, upon which it will load a webpage that downloads the worm to your PC and then it sends the same message to people in your contact list.

It only affected those who had not upgraded to the newest version of Messenger that uses Microsoft's Smartscreen, which shows up when you click on any link shared via Messenger.

A spokesperson said that the malicious worm was trying to spread itself through many of the world's largest instant messaging and social networks, including Windows Live Messenger 2009.


Windows will never be secure. "Our products just aren't engineered for security," said Brian Valentine, one of the top Windows executive at the time.

Comments

Recent Techrights' Posts

43rd Anniversary of the GNU Project Announcement
Coming soon
SLAPP Censorship - Part 187 Out of 200: Reminding Ourselves of the Great Damage Garrett Did to Linux (for Microsoft)
he rejects freedom
IBM's Anderon Another Opportunity for Debt-Loading, Publicity Stunts, Maybe Hidden Layoffs
Anderon is like Theranos
In Praise of 7 Years of Alex Oliva in the FSF, Not IBM
Thank you, Mr. Oliva, for 7 years of uncompressing advocacy and perseverance
Linux Kernel Becoming a Slopfest - Part 2 - Bribes From Slop Pushers Divide Us
Money can and does divide people
 
Links 17/09/2026: Studio Closures and Negative Rumours About Microsoft XBox Again
Links for the day
What's Wrong with Microsoft's GitHub, New Article by Jacob Bachmeyer and Richard Stallman
licensed under a Creative Commons Attribution-NoDerivatives 4.0 International License
EBay is Going to Die Soon
Users will flee
Red Hat PIPs. The Only Question is, How Many?
Insiders know what's coming soon
This Week The Register MS Published a Page With "AI" 34 Times in It and It Was, as Usual, Paid SPAM!
Does The Register MS understand that it is doing harm to its audience (for temporary gains)?
General Assembly (Meeting of All Staff) Starts in Hour Ago to Discuss Strikes at Europe's Second-Largest Institution (EPO), Strikes to Last Until End of 2026 (If Not Further)
The media absolutely does not cover this and that's intentional
Cancel Culture is a Cancer That Harms Democracy, Justice, and Science. It's Designed to Help Corporations Vanish Their Critics.
"Codes of Conduct" sounds benign; in practice, however, it is not
Links 17/09/2026: Class Action Lawsuit Over GAFAM's "NameTag" and Automattic Hides What It Did to CEO Mullenweg (or Why)
Links for the day
Gemini Links 17/09/2026: Google Signals the End, ROOPHLOCH Coverage, EBay Uses Offensive Bots to Falsely Accuse Users of Stuff
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, September 16, 2026
IRC logs for Wednesday, September 16, 2026
SLAPP Censorship - Part 186 Out of 200: Love (Always Commands)
This coming Friday we celebrate our wedding anniversary
With Half of September Finished Clownflare Radar Sees GNU/Linux at 7% "Market Share"
On desktops/laptops
Gemini Links 16/09/2026: Cards, Nature, and Conspiracy Theorists
Links for the day
Links 16/09/2026: Proprietary Chatbots Company Lets Humans Moderate Chatbots, "Putin Looking to See How Far he Can Push NATO"
Links for the day
The Only Still-Supported Version of Windows Breaks Itself (Again), the Microsoft Layoffs Will Carry on in Secret
In the US they marked about 7% for removal just this past summer
Wikileaks Turns 20 Just 18 Days From Now
it's fair to say they've endured online, but aren't lively/active
The Cyber Show Debunks the Alleged Intelligence in Slop
It's shorter than usual
Expecting Failure
Some things would not happen to technology (tech) experts because they know how things work and what to expect (or watch out for)
Links 16/09/2026: US Running Low/Out of Some Ammo Due to Wars, Slop Bots "Are Using an Outrageous Amount of Electricity"
Links for the day
"AI Slowdown" is Code Word for Bubble Imploding (Trying to Make This Slowdown Seem Wilful, an Act of Safety and Responsibility)
They help one another by inflating the bubble and making false excuses when expansion stalls
SLAPP Censorship - Part 185 Out of 200: What Reputation?
Helping monopolies and working for monopolies never made anybody popular
Gemini Links 16/09/2026: Slovenia, Catastrophe Ethics, and ROOPHLOCH 2026
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, September 15, 2026
IRC logs for Tuesday, September 15, 2026
Microsoft Layoffs in September 2026 Are Silent, Hidden
Expect the same next month ahead of the fake results
Links 15/09/2026: 'Smartphone', Android TV Box, Stockholm Syndrome of [Slop Plagiarism] Acceptance
Links for the day
Carmen-Lisandrette Maris Prepares Audiobook to Explain Software Freedom/Digital Rights to Adolescents, Needs Help From Volunteers
needs help with narrating
Links 15/09/2026: Putin-Connected Money for The Insurrectionist Jr. and Turkey's Crackdown on Activists
Links for the day
publicdomainpictures.net Seems to Have Become Fed Up With Slop Contaminating Its Database (Wasting Storage, Bandwidth), Now It's Suitably Flagged, Should Be Demoted/Delisted
The site was redone, suffered some hours of downtime, then 'relaunched' with a new interface this week
Gemini Links 15/09/2026: Hiking in Munții Făgăraș, Scams, and Slop Plagiarism Considered Unethical
Links for the day
Linux Kernel Becoming a Slopfest - Part 1 - At the Beginning (Torvalds Knew It Was Trouble)
We still wonder if we should make and actively maintain a shame list (developer/employer) for the people who contaminate Linux the most with slop plagiarism
EPO Staff is Preparing to Take Up a Notch the Strikes and Other Industrial Actions Ahead of October's Meeting (It Can Help Oust the Corrupt Leadership)
mobilising perhaps thousands of workers at a critical time in the history of the Office
unixcop.com is the Latest "Linux" Site to Have Become a Slopfarm After 2 Years of Death (Inactivity)
Not a way to stage a comeback
Allegedly Many PIP Layoffs in Nepal, IBM Does This Before a Known Death Toll in Avalanche (Caused by China-, Europe-, and US-Induced Global Warming)
Fresh wounds, before the bodies are even recovered (thousands still missing)
"Wail" by Alexandre Oliva
This work is licensed under the Creative Commons License BY-SA (Attribution ShareAlike) 4.0 International
This Morning The Register MS Published a Page With "AI" 83 Times in it. The Register MS Got Paid to Do This.
The Register MS is not a serious publisher and a lot of the stuff about "AI" on the Web isn't journalism but paid-for SPAM
While GAFAM/Microsoft Disguise Financial Crisis as "Investment in AI" the Slop Giants Make Up a Narrative of Wilful Slowdown
A BS artist is good at the art of BS when the artist's failures or weaknesses get twisted as moral or professional leadership
SLAPP Censorship - Part 184 Out of 200: A Tiny Law Firm That Knows Nothing But Microsoft (But Merely Pretends to Understand "IT")
They've managed to trick some mainstream media into thinking they're "Tech" experts or "Social [Control] Media" gurus; nothing could be further from the truth
Links 15/09/2026: Sweden’s Far Right Perishing and "Iceland Just Got Played"
Links for the day
It's Not About How Developers Vote
This isn't about politics, it's about users being in control of their own computers and computing
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, September 14, 2026
IRC logs for Monday, September 14, 2026
Gemini Links 15/09/2026: Poetry, Enshittification of Ebay, and Mecha System
Links for the day