Bonum Certa Men Certa

Vista 7 Zero-Day Followed by Internet Explorer 7 Zero-Day

Nine O Nine



Summary: Vista 7 as exposed as the naked emperor; Internet Explorer received similar treatment as users are under attack and no remedy is available

OVER the past week and a half we wrote several posts about the illusion of security in Vista 7. Among those posts:

  1. Vista 7 Exploit is Out (Zero-Day Vulnerability)
  2. If Microsoft Cannot be Sued Over Liability, Can it be Sued for Negligence?
  3. Microsoft Won't Secure Firefox/Chrome Users, Shows More Negligence


Reports about this subject continued to come and only an advisory (not a patch) came from Microsoft. Regarding another serious crack that led to security issues in vista 7, reports suggest that it "comes as no surprise," proving yet again that Microsoft does not give a damn about security.

There is now the following serious incident which leads to invaluable harm. No report seems to say which platform is to blame, but the University of East Anglia is not necessarily a docile Windows shop, not based on its Web site anyway. It actually abandoned Solaris for GNU/Linux when Sun began roaming the streets looking for love. Does anyone know what mail systems are used at the University of East Anglia?

A 61MB ZIP file was posted on a Russian FTP server late last night, local time. It contains over a thousand emails, and around three thousand other items including source code and data files. Emails are peppered with disparaging remarks and a crude cartoon of sceptical scientists is also included in the archive - suggesting the hacker roamed wide across the University's servers.


More at The Guardian.

A spokesperson for the University of East Anglia said: "We are aware that information from a server used for research information in one area of the university has been made available on public websites. Because of the volume of this information we cannot currently confirm that all this material is genuine. This information has been obtained and published without our permission and we took immediate action to remove the server in question from operation. We are undertaking a thorough internal investigation and have involved the police in this inquiry."


Regardless of what this "server in question" actually runs, Microsoft is taking a weird approach to security, suggesting/recommending a different architecture (not platform) as a cure for executables that exploit Windows by design, not just by compilation.

Meanwhile we find that users of Internet Explorer 7 (version 6 also) are under attack due to a zero-day flaw. [hat tip: Tony Manco]

According to Symantec, which has quickly tested the exploit code that appeared on the Bugtraq list at insecure.org, the code as it stands is not 100% reliable but the security researchers expect that a “fully-functional reliable exploit will be available in the near future”. And that means exploit code that will enable websites to be infected, and any IE6 and 7 users with JavaScript enabled to be compromised.


More information at IDG:

The code was posted Friday to the Bugtraq mailing list by an unidentified hacker. According to security vendor Symantec, the code does not always work properly, but it could be used to install unauthorized software on a victim's computer.


No fix is available yet, except a download that's called Firefox or Fedora. But Microsoft does not want people to say the "F" word, so it will probably deliver a patch very soon.

To Free software's credit, it rarely waits for attacks to occur before addressing security vulnerabilities.

More on Vista 7 insecurity:



Recent Techrights' Posts

Salaries Are Counted in Money, Not in Participation in the Employer's Scheme
articles greatly exaggerating GAFAM salaries
Even Linux Cannot Cope With Slop
Bots on the Web are truly obnoxious
GNU/Linux Has Become More Mainstream in the United Kingdom
It's a long weekend here and we guess some people dabble in GNU/Linux migrations, at least at home
 
Anniversaries Next Month
The month should be otherwise quiet and uneventful for us
Coding is Not Obsolete
we drown ourselves in chaff to meet "LOC" objectives while ignoring everything else
Microsoft Layoffs Perpetual But Silent, People Pushed Out Using Pressure or Incentive Schemes
Earlier this month we named some of the programs
Links 30/08/2026: Apple Rant and LLM (Slop) Scrapers Target Gemini Protocol and Gopher
Links for the day
Walls in Free Software
mind your own business and move on
What a Summer!
Tomorrow is the last day of this month
Links 30/08/2026: Soldiers in Niger Attack Presidential Palace and Airport, Nepali City Struggles to Handle the Many Dead Bodies
Links for the day
Clownflare Sees GNU/Linux Rising to 11% This Past Week
Is it the year of "Linux in China"?
Links 30/08/2026: Russian Strike on a Ukrainian Warehouse and Rhetoric Escalations
Links for the day
Gemini Links 30/08/2026: Photography, Paper Books, Linux Kernel and the Debian Projects Permitting Slop Plagiarism
Links for the day
Imagine a World Where Nobody Fights for Software (and Computing) Freedom
The community keeps fighting back, so some of these ambitions are delayed or watered down
FSF Has Grown (More Staff) After a Year of Financial Growth
On October 4 the FSF turns 41
SLAPP Censorship - Part 166 Out of 200: Garrett Wasn't Found Innocent Per Se, the Court Wanted More Evidence of Who Was Behind Particular Accounts Using Tor
It's complicated
Criminals Don't Obey Laws, California Does Not Enhance Online Safety
It has been a while since we last mentioned so-called 'age-verification' laws
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, August 29, 2026
IRC logs for Saturday, August 29, 2026
Links 29/08/2026: Stop the Hate, Goldfish Myths, and xmpp.nz
Links for the day
Links 29/08/2026: Wave of Social Control Media Bans, Suno Data Breach Class Actions
Links for the day
Links 29/08/2026: Microsoft GitHub Outage (Again), "Displaying Ads Directly on Your Monitor", and "Election Deniers Could Soon Control Elections"
Links for the day
IBM is "Taking the PIP" (Piss), People 'Retire' 'Voluntarily' to "Focus on Family"
IBM has a billion bucks for 'the butcher', but not a million dollars for critical projects and initiatives in Free software
It Should be Uncontroversial to Say That Social Control Media is a Weapon
Democracy is not compatible with the likes of Kapo-Berg and MElon controlling public discourse of billions
Misuse of Bots (Now Sold as "Agents", "Hey Hi", "Automation", and "Efficiency")
They even try to rebrand robotics as "hey hi" and try to sell slop as "work"
Debian: Plagiarism OK, Just be "Responsible" About It
The result isn't the worst, but it's not good either
Don't Let Them Kill Activism
Are the oligarchs shutting the lid on activism and whistleblowers?
SLAPP Censorship - Part 165 Out of 200: Two Years Since My Wife and I Sued
In early September 2024 we hit back
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, August 28, 2026
IRC logs for Friday, August 28, 2026
Gemini Links 29/08/2026: Death Notice, Systems Biology, and Gopher
Links for the day
Links 28/08/2026: Chatbot Pushers Admit They're Used Heavily for Social Engineering Scams, Strong Backlash Against "Smart Glasses" (CCTV on Legs)
Links for the day
Michael Catanzaro's Latest Blog Post Affirms Rumours of Red Hat Changes and RAs/PIPs at IBM
reading between the lines, IBM is "spitting out" Red Hat staff
If Linux Was Written in Rust, 80% or More of Linux Developers Would Not Understand It (Same If It's Composed by LLM Slop)
The licence (GPL) is not enough when there are ways to bypass it
Gemini Links 28/08/2026: Absurd Tomodachi Summer, Screen Piggery, and Jugulans 1.0.3 Released
Links for the day
Links 28/08/2026: "UK Power Grid Has a Phantom Data Center Problem" and "Growth at All Costs is Cancer"
Links for the day
SLAPP Censorship - Part 164 Out of 200: Patent Troll SLAPPs, Defamation Trolls, and Stranglers From America
You start to wonder if the core issue is insecurity
Rumours of More PIPs and Layoffs at Confluent Just Months After IBM Bought It
It is meanwhile apparent IBM will have mass layoffs next week (September)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, August 27, 2026
IRC logs for Thursday, August 27, 2026
After Many Waves of PIPs (Silent Layoffs) IBM Makes Non-Silent Layoffs, Effective Next Week (September)
What we heard is turning out to be true