Bonum Certa Men Certa

Over 23 New Microsoft Vulnerabilities and Microsoft Could Not Patch the One Actively Under Attack

Unlocked



Summary: Another massive patch Tuesday is due, but Microsoft customers are still left vulnerable

ACCORDING to a flood of reports, Microsoft claims to have just patched 23 vulnerabilities (the real number is a lot bigger and always a mystery). Quite a few of them are "critical".

It's a busy month for Windows administrators, as Microsoft has released eight security bulletins addressing more than 20 vulnerabilities. Five of the bulletins are rated 'critical'.


But here is the important bit:

Missing from the list is relief for a zero-day vulnerability in PowerPoint, actively targeted by hackers since last month.


This most likely means that for at least another month, all Microsoft Office users will be left exposed to attacks which have already begun, with Microsoft confirming this. Later on, people wonder why Conficker is able to propagate quite so rapidly. Here is the latest report about Conficker.

People have been speculating, waiting and prognosticating, but until now the extremely cleverly programmed Conficker worm has limited itself to mainly defensive measures, such as opening various communications channels (Conficker.C can set up peer-to-peer networks with other infected systems) in order to transform itself with downloaded code, and to actively combating anti-virus software and security analysis tools. Even on 1 April, the known date on which Conficker.C would be looking for updates, virtually nothing happened. Now however, money is involved: computers infected with the Conficker worm are downloading the scareware program "SpywareProtect2009".


Despite the latest lie from a Microsoft executive (circulating in the press this week), Windows Vista is just as insecure as its predecessors.

With so many of the world's Windows PCs already enlisted to join a botnet, it is no wonder that -- even according to Microsoft's latest report -- 97% of E-mail is SPAM. We have already shown why this is Microsoft's fault, at least in part. The catastrophic damage is not just one of productivity; according to this new report, there is also a severe environmental cost.

That's what McAfee says in its "Carbon Footprint of Spam" report released Wednesday, which states climate-change researchers from the firm ICF and McAfee's security staff calculated that the amount of energy needed to transmit, process and filter spam globally is equal to 33 billion kilowatt-hours each year. They say that can also be expressed as the equivalent to the electricity used in 2.4 million homes annually or the same green-house gas emissions from 3.1 million passenger cars using 2 billion gallons of gas.


The Inquirer, as usual, sensationalised it a bit.

Spam is killing the planet



[...]

Apparently, dealing with spam burns 33 billion kilowatt hours (one KW is about what a single bar electric heater will use) every year, enough to power 2.4 million homes.


There may be simple solutions to this.

Comments

Recent Techrights' Posts

Sven Luther, Lucy Wayland & Debian's toxic culture
Reprinted with permission from disguised.work
 
Chris Rutter, ARM Ltd IPO, Winchester College & Debian
Reprinted with permission from disguised.work
[Video] Microsoft Got Its Systems Cracked (Breached) Again, This Time by Russia, and It Uses Its Moles in the Press and So-called 'Linux' Foundation to Change the Subject
If they control the narrative (or buy the narrative), they can do anything
Links 19/04/2024: Israel Fires Back at Iran and Many Layoffs in the US
Links for the day
Russell Coker & Debian: September 11 Islamist sympathy
Reprinted with permission from disguised.work
Sven Luther, Thomas Bushnell & Debian's September 11 discussion
Reprinted with permission from disguised.work
G.A.I./Hey Hi (AI) Bubble Bursting With More Mass Layoffs
it's happening already
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, April 18, 2024
IRC logs for Thursday, April 18, 2024
Coroner's Report: Lucy Wayland & Debian Abuse Culture
Reprinted with permission from disguised.work
Links 18/04/2024: Misuse of COVID Stimulus Money, Governments Buying Your Data
Links for the day
Gemini Links 18/04/2024: GemText Pain and Web 1.0
Links for the day
Gemini Links 18/04/2024: Google Layoffs Again, ByteDance Scandals Return
Links for the day
Gemini Links 18/04/2024: Trying OpenBSD and War on Links Continues
Links for the day
IRC Proceedings: Wednesday, April 17, 2024
IRC logs for Wednesday, April 17, 2024
Over at Tux Machines...
GNU/Linux news for the past day
North America, Home of Microsoft and of Windows, is Moving to GNU/Linux
Can it top 5% by year's end?
[Meme] The Heart of Staff Rep
Rowan heartily grateful
Management-Friendly Staff Representatives at the EPO Voted Out (or Simply Did Not Run Anymore)
The good news is that they're no longer in a position of authority
Microsofters in 'Linux Foundation' Clothing Continue to Shift Security Scrutiny to 'Linux'
Pay closer attention to the latest Microsoft breach and security catastrophes
Links 17/04/2024: Free-Market Policies Wane, China Marks Economic Recovery
Links for the day
Gemini Links 17/04/2024: "Failure Is An Option", Profectus Alpha 0.5 From a Microsofter Trying to Dethrone Gemini
Links for the day
How does unpaid Debian work impact our families?
Reprinted with permission from Daniel Pocock
Microsoft's Windows Falls to All-Time Low and Layoffs Reported by Managers in the Windows Division
One manager probably broke an NDA or two when he spoke about it in social control media
When you give money to Debian, where does it go?
Reprinted with permission from Daniel Pocock
How do teams work in Debian?
Reprinted with permission from Daniel Pocock
Joint Authors & Debian Family Legitimate Interests
Reprinted with permission from Daniel Pocock
Bad faith: Debian logo and theme use authorized
Reprinted with permission from Daniel Pocock
Links 17/04/2024: TikTok Killing Youth, More Layoff Rounds
Links for the day
Jack Wallen Has Been Assigned by ZDNet to Write Fake (Sponsored) 'Reviews'
Wallen is selling out. Shilling for the corporations, not the community.
Links 17/04/2024: SAP, Kwalee, and Take-Two Layoffs
Links for the day
IRC Proceedings: Tuesday, April 16, 2024
IRC logs for Tuesday, April 16, 2024
Over at Tux Machines...
GNU/Linux news for the past day