Eye on Microsoft: Ransomware, Botnets, Critical Flaws, and Insecure Microsoft File Types
- Dr. Roy Schestowitz
- 2009-07-28 07:18:43 UTC
- Modified: 2009-07-28 07:18:43 UTC
●
Smut page ransomware Trojan ransacks browsers
Russian cybercrooks have come up with a variant of ransomware scams, which works by displaying an invasive advert for online smut in users' browsers that victims are extorted to pay to remove.
●
The Business of Botnets
Kaspersky Lab released some interesting statistics recently in a technical whitepaper. As part of its research into the cyber-underground, the company took a look at how botmasters are pricing the networks under their control.
●
Microsoft to fix critical hole in IE
In a rare move, Microsoft on Friday said it would be releasing security updates on Tuesday--outside of its monthly patch cycle--for a critical vulnerability in Internet Explorer and a moderate vulnerability in Visual Studio.
●
Microsoft to Issue Emergency Patches Next Week
The advance notification advisory that Microsoft released about these upcoming patches doesn't say so explicitly, but a spokesperson for the company confirmed that the updates will address a critical security flaw in collection of code that Microsoft uses in a number of places in Windows. Having a vulnerability in this so-called "code library" is especially dangerous because Microsoft also provides this library to third-party software makers to help them build programs that can leverage certain built-in features of Windows.
●
Insecure by design: MS Office formats
You see, when you're opening an Office document today, you're not just opening static words, images, or numbers. You're actually starting a program that uses Microsoft Office as its interpreter. And, no matter whether you're using Word 2,0 formats or the 2008's 7,000+ pages mis-mash of 'standard' ECMA-376 Office Open XML file formats, there is no built-in network security layer. Instead, there is a mis-mash of fixes for one problem or the other.
Also see:
Emergency, Botnets, and No Remedy
Recent Techrights' Posts
- There Are Also Loads of Microsoft LinkedIn Layoffs Today (Keep Track of the Subsidiaries They Keep Out of Headlines)
- Perhaps lost in the smokescreen
- There Are Bigger Rounds of Microsoft Layoffs Coming, a Cull of 10% Implemented in Waves (the "3%" Figure is Misleading, Face-Saving)
- Last night we said they might do the layoffs in three or at least two waves
- Unless a Third of All Microsoft Layoffs Worldwide Are in Redmond (Washington) Alone, Microsoft Has Just Lied to Everyone Via Jordan Novet in CNBC (i.e. the Usual Any Time There's Mass Layoffs and Novet Weighs in With False Numbers)
- Maybe when Microsoft said 3% it meant ~6,000 or more in the US alone
- As Expected, Microsoft Uses Media Operative (Jordan Novet) to Downplay the Scale of Mass Layoffs
- here we go
-
- Canonical Will Give You Money Only If You Work for Microsoft!
- Only if you are servicing (being a slave to) proprietary forges that Microsoft and the NSA control while violating the GPL will Canonical give you money
- If Microsoft Staff That Strangles Woman Pays You to Write Lies, It Will Not End Well
- The past couple of years were our most productive ever
- Gemini Links 14/05/2025: "Writing My Story with Inspiration from Notable Lives" and People Start Shovelling Up LLM Slop Onto Geminispace,
- Links for the day
- Microsoft is Very Highly Stressed About Adoption of GNU/Linux at Windows' Expense (on Former "Vista 10" PCs)
- What does this tell us?
- Slopwatch: BetaNoise (BetaNews), LinuxSecurity, and Slopfarms Still Promoted by Google News
- The primary goal is to demonstrate the problem persists
- Links 14/05/2025: Google Agrees to $1.3 Billion Settlement After Spying, China Tariffs Don't Work
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Tuesday, May 13, 2025
- IRC logs for Tuesday, May 13, 2025
- Gemini Links 13/05/2025: Apocalyptic Future and More
- Links for the day
- McKinsey (McK) is Killing IBM, It's All About Killing This Goose, "National Sales Team 80% on PIP Now" (Preceding Layoffs Without Severance)
- PIPs are not based on performance
- Links 13/05/2025: Microsoft Breaks Windows Very Badly Again, Mass Layoffs Reported (But False Figures, It's a Lot Higher)
- Links for the day
- 2025 Will be a Big Year For GNU/Linux on Desktops/Laptops
- with an economy like this, people who don't live in rich countries won't turn to Apple
- Signs of Trouble: Microsoft Job Openings for Jobs That Do Not Exist!
- Keeping up appearances?
- "Special Place in Hell" for Women Who Help Violent Microsofters From Another Continent Attack Local Women Who Did Nothing Wrong, They Just Got Bullied and Deserve Sympathy or Compensation
- Nothing says "Brat" like men who attack women, right?
- The Numbers Game: 50,000-60,000 Microsoft Workers Laid Off in 2.5 Years? And Debt Still Tripled Under Nadella.
- under Nadella Microsoft's debt trebled
- The Slow Death of Windows Will Mean the Inevitable Demise of Microsoft
- Once people stop using Windows, it'll be hard for Microsoft to sell anything to them
- Last Week's Public Talk by Richard Stallman Well Attended and Covered in Technical News Sites
- and we're looking at about 60,000 Microsoft layoffs in 3 years
- Gemini Links 13/05/2025: Shopping is an Exasperating Nightmare and Making Phones Minimal
- Links for the day
- 23,000 More Microsoft Layoffs by the End of June If the Estimates Are Correct (In Addition to About 6,000 Layoffs So Far This Year)
- There's no questions about many layoffs happening this month. It got leaked already. The only question is when (and also how many).
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Monday, May 12, 2025
- IRC logs for Monday, May 12, 2025
- Major Microsoft Layoffs This Week (Discussed Online)
- later we can expect a lot of spin, even misinformation
- What Happened to the Open Source Initiative (OSI) Elections: Missed Deadline
- they helped expose a number of other scandals
- Links 12/05/2025: Measles Rising and Taliban Outlaws Chess in Afghanistan
- Links for the day
- Gemini Links 12/05/2025: Advice, Iorist Ethics, and Touchscreens
- Links for the day
- The Finances of GAFAM Aren't as They Seem
- MICROSOFT FINANCIAL PYRAMID revisited
- Links 12/05/2025: US Brain Drain and Reminder That "Microsoft's Lobbying Efforts Eclipsed Enron" (Fraud Coverup)
- Links for the day
- The Enshittification of Royal Mail (Post Office/Postal Services) Continues
- Enshittification is a thing, not only in the digital realm
- Red Hat's Owner is Called "America's Worst Tech Company" (IBM) and Microsoft's Liabilities Grow
- Microsoft has about a quarter of a trillion (yes, trillion with a "T") in liabilities
- If the Gossip is True, Today Microsoft Has "Large M1 Meetings" to Discuss Almost 30,000 More Microsoft Layoffs in 2025
- the claim is that Microsoft is preparing to lay off 10% of its staff
- Microsoft Has a Long and Proven History of Funding Meritless Lawsuits Against Rivals and Critics (It Always Backfires)
- It also looks like the solicitor used by two Microsofters to SLAPP us is being urgently replaced
- Links 12/05/2025: Gardens and Kitchens
- Links for the day
- Links 12/05/2025: Media Being Attacked (New Forms of Attack on the Press), Many Data Breaches
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, May 11, 2025
- IRC logs for Sunday, May 11, 2025