Bonum Certa Men Certa

VENOM€® is Not a Serious Bug, It's Just a Marketing Campaign From CrowdStrike

Bugs
Image courtesy of Red Hat, demonstrating lack of correlation between severity and logos/brands



Summary: Many journalists bamboozled into becoming couriers of CrowdStrike, an insecurity firm which tries to market itself using a name and logo for a very old bug

THERE is a disproportionate level of coverage not of Free software but of bugs in Free software. We last wrote about it only days ago



A firm called CrowdStrike (who? Exactly!) is trying to emulate the 'success' of previous FUD campaigns. Now is the time to check who's a real journalist (fact-checking) and who's just serving PR campaigns like "VENOM", a shameless FUD campaign from CrowdStrike.

The whole "VENOM" nonsense was covered in a good article titled "VENOM hype and pre-planned marketing campaign panned by experts". To quote: "On Wednesday, CrowdStrike released details on CVE-2015-3456, also known as Venom. Venom is a vulnerability in the floppy drive emulation code used by many virtualization platforms.

"However, while it’s possible that a large number of systems are impacted by this flaw, it isn’t something that can be passively exploited.

"Several security experts discussed the flaw online, focusing on the marketing and the media attention that it generated – including some over-hyped headlines. Most media organizations were briefed ahead of time about the discovery and gagged by embargo until the Venom website launched, so they had plenty of time to write.

"Many media articles compared Venom to Heartbleed, which is an apples to oranges comparison. If anything, the only commonality is the fact that both flaws had a pre-planned marketing campaign."

Here comes the "Heartbleed" brand. Yet again. They're using names that are scary (even all caps, like "GHOST") because it's so much easier to sell than "CVE-2015-3456". Journalists rarely have the technical knowledge to analyse a bug or a flaw, so they assume bugs and logos are indicative of severity.

This patch Tuesday Microsoft revealed 40+ vulnerabilities. Not a single one had a brand name, logo, etc. Here is how IDG covered 46 flaws publicly disclosed by Microsoft just for this Tuesday (Microsoft hides even more flaws). So many flaws were collectively covered in one article and yet there are no logos; none has any branding.

"VENOM" has become the latest example of what we call bugs with branding. This has got to stop because it corrupts journalism and makes the field of computer security almost synonymous with marketing or advertising. CrowdStrike used ALL CAPS (for emphasis rather than acronym) and connotation with poison to market itself, an insecurity firm, after finding a floppy drive bug from over a decade ago. There is a logo too (the first example we found of it), not just branding for this bug, dubbed "VENOM".

Bug branding (turning number into branding-friendly FUD) seems to have adopted the ALL CAPS convention from "GHOST", only for extra scare. This FUD has surfaced even in Linux-centric sites, which played along with the marketing campaign. Red Hat [1] and SJVN [2], even Phoronix [3] and Softpedia [4], have covered it by now, despite no focus on security news there.

Branding for bugs leads to stupid headlines that are more poetic than factual and are very light on facts. There is little substance there. This whole recipe (bug+brand name+logo=lots of publicity without much merit) has been repeatedly exploited to give a bad name to FOSS security. A lot of headlines try to connect this to the "Heartbleed" brand. Headlines that we have found so far (links below) include "New Venom bug hits data centers, but it's hardly Heartbleed", "Venom bug could allow hackers to take over cloud servers - and experts say it could be worse than Heartbleed", "New Venom flaw may be worse than Heartbleed, researchers warn", and "Venom vulnerability more dangerous than Heartbleed, targets most virtual machines".

Zack Whittaker (former Microsoft staff) covered it like this in the CBS-owned tech tabloid, ZDNet: "Bigger than Heartbleed, 'Venom' security vulnerability threatens most datacenters"

Here is that "Heartbleed" brand again. "Please Stop Comparing Every Security Flaw to Heartbleed," said one good headline from Gizmodo (that's just how they covered this marketing campaign).

The word/brand "Heartbleed" was made up by a Microsoft-connected firm. Watch coverage from Microsoft-friendly sites and you will find headlines like: "Heartbleed, eat your heart out: VENOM vuln poisons countless VMs"

Dan Goodin, a foe of FOSS (from a security angle), brings in the NSA and Bitcoin to add FUD amid this branded bug/buzz. He wrote about the latest branded bug not once but twice (see links below). He is squeezing the most FOSS FUD out of it (opportunism). Kim Komando chose the headline "New bug taking over the Internet". No sensationalism here? One press release said "Better Business Bureau Says Most Don't Need to Worry" [about the branded bug], so there is some objectivity out there too, or an effort to calm people down.

Watch carefully how the bug is marketed in the media: Logo with SVG-like transparency; for a bug! Looks like it was prepared by graphics/marketing professionals. Are insecurity firms now liaising with marketing firms to professionally draw SVG logos for bugs? More logos for simple bugs (we found several, but one main logo) are circulating, usually with photos of snakes. See the complete list [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36] as of this morning. How much more of this FUD is going to circulate before journalists realise that they make a mountain out of a molehill?

Related/contextual items from the news:


  1. VENOM, don’t get bitten.
    CVE-2015-3456 (aka VENOM) is a security flaw in the QEMU’s Floppy Disk Controller (FDC) emulation. It can be exploited by a malicious guest user with access to the FDC I/O ports by issuing specially crafted FDC commands to the controller. It can result in guest controlled execution of arbitrary code in, and with privileges of, the corresponding QEMU process on the host. Worst case scenario this can be guest to host exit with the root privileges.


  2. For Venom security flaw, the fix is in: Patch your VM today
    The QEMU fix itself is now available in source code. Red Hat has been working on the fix since last week.


  3. VENOM Bug In QEMU Escapes VM Security


  4. 11-Year-Old Bug in Virtual Floppy Drive Code Allows Escape from Virtual Machines
    Popular virtualization platforms relying on the virtual Floppy Disk Controller code from QEMU (Quick Emulator) are susceptible to a vulnerability that allows executing code outside the guest machine.




Recent Techrights' Posts

European Patent Office (EPO) Series: Legal Concerns and Suspicions of Irregularities
complaints submitted to OLAF
GAFAM and IBM Dying in Massive Debt, Hence the Mass Layoffs (Increasingly Silent Layoffs That the Media Fails to Mention)
the integrity of this economy is only as good as its leaders or those who govern the market
SLAPP Censorship - Part 134 Out of 200: What "Majority Rules" Tell Us About the Litigant
we press on with this series
Overshoot Day Sites That Contribute to the Problem
Some of these are not even accessible (at all) without JavaScript
As Expected, Facebook Collapses, Microsoft Hides Massive Debt
GAFAM is a giant mountain of debt
Staff of EPO Cautions Against Unlawful Weaponisation of PIPs Against Industrial Actions That Protest Corruption
PIP-like sanctions against anybody who does not toe the line of Cocaine King?
 
More Fake News From (and for) IBM, Nobody Ever Held Accountable for Fraud
Companies that turn a blind eye to their own corruption end up recruiting more corrupt people and sacking those who object to the corruption
Links 30/07/2026: Smol Document Server and More PalmOS-ing
Links for the day
Links 30/07/2026: Microsoft Refuting Its Own Slop Hype and "Amazon Is Gutting Its Hey Hi (AI) Division" (GAFAM Bubble)
Links for the day
Today The Register MS Published "AI" Spam and Fake Article by "Senior Technical Marketing Engineer"
unethical practices
Cult inquiry parliament leak fallout
Reprinted with permission from Daniel Pocock
Techrights Will Always Protect Sources
Our #1 priority is sources
The Era of Silence
So stay silent, remain hidden
TheLayoff.com Deletes Comment That Called IBM's Previous CEO, Ginni Rometty, "Gin 'n Tonic"
It is hard to believe the comment was deleted for being a duplicate (in another thread)
The Mainstream Media Continues to Overlook or Intentionally Ignore Hundreds of Billions in Hidden/Secret Microsoft Debt
the issue is that Microsoft's crisis is a lot greater and broader than this
Microsoft May Have Gotten Rid of 8% of Its Workforce This Month
It's hard to know what's really going on because there's no transparency due to NDAs
Links 30/07/2026: "Age of Irrationality", Google Losing Money, and "House of Ellison is on the Brink"
Links for the day
Gemini Links 30/07/2026: Homeworlds Notes and Manuscript Submitted
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, July 29, 2026
IRC logs for Wednesday, July 29, 2026
At The Register MS "PARTNER CONTENT" Means Company Writing Fake Articles About Itself and Its Own Products
At The Register MS, content-farming has become a thing
IBM, Running Out of Things It Can Sell, is Selling Software Patents
IBM is not just pathetic; it's actively harmful because it lobbies for software patents and spreads software patents around
Gemini Links 29/07/2026: Star Trek, Retirement, and ODEs in GNU Octave
Links for the day
Links 29/07/2026: "BuzzFeed Lays Off 33 Percent of Remaining Staff" (Trying LLM Slop Some More), Scam Altman Mocked by the Media
Links for the day
GNOME Curated and Censored by IBM (Under the Guise of "Code of Conduct")
Felipe Borges (IBM) has just posted a follow-up
Digital Mass Surveillance as a Hallmark of Failed Societies
"small leap forward in tech ethics"
I Found a Typo, Don't Vote!
Social control media isn't good at adding any meaningful signal
Jeremy Sands Explained the Harms of Codes of Conduct
next week the 500th show milestone [is reached]
Tonight's Earnings Report From Microsoft and Facebook ('Meta') Will be Faked Because They Hide Almost a Trillion Dollars in Debt
The US economic system is only as honest as the people who govern it
The Vacuum Syndrome
Parables help
The Only Old People Who Can Survive IBM Are the CEO and His Circle of Enablers
very similar to what's happening at the EPO
The 'Church' of Moglen/Stallman
'reunion' with Eben Moglen
Microsoft Layoffs Aren't Done Ahead of the Need to Tell Shareholders About "Efficiency" (Tonight)
Microsoft layoffs won't be "Done" until what's left of Microsoft is "None"
Microsoft Lacks Growth. Ahead of 'Results' The UK's Competition and Markets Authority (CMA) Finds Merit in Allegations Slop is Microsoft's Excuse for Price Hikes (Piggybacking Vendor Lock-in).
At this stage it's not hard to see why many nations gravitate away from Microsoft
Parliament leaks confidential cult inquiry witness contact list (COFG Victoria)
Reprinted with permission from Daniel Pocock
Troll-Feeding is Time-Wasting
in social control media
WordPress is Technical Debt
There are a number of technical tasks underway and maybe some testing (this coming weekend or later)
Will Red Hat Still Exist in 2027 or Just Become a "Brand" at IBM?
Whistleblowers told us IBM was laying off about 500 Red Hat engineers earlier this year
Call for IBM Whistleblowers
If you work for IBM and have something material (like balance sheets) to prove financial misconduct, please try to 'touch base' and establish a secure communication channel we can both use
EPO Series on EU and Pan-European Corruption, Vote-Rigging, Extending Beyond the EPO Itself
By Saturday it will be August already, so we'll start preparing for Rianne's birthday
SLAPP Censorship - Part 133 Out of 200: Lies by Omission
As usual, the other side wants people to ignore how much they lost
European Patent Office (EPO) Series: Streamlining the Decision-Making Process
Negrão was one of 17 applicants for the position but he somehow managed to end up as the sole candidate on the shortlist prepared by the Management Board in June 2020
Links 29/07/2026: "Hugging Face Has a Deepfake Nudes Problem" and "$1.5B Anthropic Copyright Infringement Ruling" (Plagiarism is Not "Training")
Links for the day
Comments on Today's Judgment
It hopefully helps clarify what actually happened
Microsoft Has Fallen to #3 in Singapore
There are many technically talented people in Singapore or overseas workers who lodge in Singapore
Thank You, Andy
Burnham and "Tech Rights"
Solicitors Regulation Authority (SRA) Inaction and Incompetence - Part II - 77 Messages Sent, Did Not Even Investigate or Examine Any of the Actual Evidence (British Taxpayers' Money Wasted)
SRA has become known (even notorious) for inaction
Inevitable Politics
In technology, provided the work you do has growing impact (we served almost 2 million requests yesterday), things will inevitably become more political - whether you like it or not does not matter
Not Only "Loonies Take on Farage"
pretending that the opposition to the right wing is "Loonies"
Brigading Against Women - Part I - Bypassing the Legal System by Threatening Companies in Another Continent
In the next part we'll begin to connect Lozza's online activities (and court activities) to those of Garrett
IBM is Trying to Turn Debt (Borrowed Money) Into Fake Growth and It'll Worsen Matters
they put in their balance sheets a fake "growth" in something that does not even exist
Microsoft Relies on Misleading Narrative of Studios Going 'Independent'; in Reality There Are Mass Layoffs in Them
This is not a good narrative for Microsoft
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, July 28, 2026
IRC logs for Tuesday, July 28, 2026
Gemini Links 29/07/2026: Arosa, Tired Tuesday, and Constellation Browser
Links for the day
In IBM, PIPs and RAs (Layoffs) Have Become Almost the Same Thing, Workers 'Expire' With Age (Seniority, Experience) and Empathy is Punishable by Termination
IBM does seem like a dead company
At Microsoft, PIPs Are Sometimes Known as "LITE" (a Silent Layoffs Legal Hack or a Shrewd Workaround to Skirt WARN Act)
Zero "layoffs" to report
Gemini Links 28/07/2026: “Strategies Against Algorithms” and DIYers
Links for the day
"Social Dialogue" With the Man Who Never Faced Real Competition at the European Patent Office (EPO), He Buys the Voters and Eliminates Rivals
Will the "Pretender" write back?
Digital Restrictions (DRM) and Microsoft: What Kills XBox Will Kill Windows Next
Microsoft wrongly and very arrogantly assumed that users would tolerate everything it throws their way
GNU/Linux in Afghanistan Reaches 7%
For many years it was stuck at less than 1%
Greenwashing Corruption With a "Chief Sustainability Officer", Who Infamously Defended Battisetelli's Crimes at the EPO and Petitioned for Him
She was rewarded for conspiring against EPO staff, as usual
What I Explained to Police About Blackmail and Death Threats via Burner Accounts (a Practice Which Generally Constitutes a Crime)
Today I've communicated several times with police
Links 28/07/2026: "People’s Claude Chats Are Publicly Accessible Online" and SpaceX Stock Crashes Like Its Products
Links for the day
UK tech sector missing from democratic process
Reprinted with permission from Daniel Pocock
How Not to Cover Elections (Democracy Relies on Reliable, Complete Information)
Misinformed voters are a recipe for disaster
Microsoft E.E.E. (and "Bait and Switch") Going Exactly According to Plan
That is what they are trying to tell us and the companies that employ us
IBM: An Old Company That Hates Old People
Remember that's coming to Red Hat workers in 2 months
Strict Policy on Violence and Violent Language
This matter is now being escalated to law firms
Avoiding Discrimination Against People With Disabilities
work underway to improve the system which runs the sites
Links 28/07/2026: XBox DRM Doomed Everyone (Cannot Play Anything), Slop (Ponzi Scheme) Being Pinkwashed Now
Links for the day
Gemini Links 28/07/2026: Ethics, GIMP Script-Fu, SMTP Versus Gemini, and Proposal for Better TOFU
Links for the day
To a Sociopath, Ethical People Are Bad People. Don't Fall for It.
If you put sociopaths on a pedestal, the pedestal will break
Improving the Static Site Generator
Our system has fixes triaged
Diversity in Debian
bringing up the topic is the real problem, diversity itself is a taboo subject
GNU/Linux in Brazil. The B in BRIC(S).
the "market share" is assessed to be around 5%
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, July 27, 2026
IRC logs for Monday, July 27, 2026