Bonum Certa Men Certa

Over 23 New Microsoft Vulnerabilities and Microsoft Could Not Patch the One Actively Under Attack

Unlocked



Summary: Another massive patch Tuesday is due, but Microsoft customers are still left vulnerable

ACCORDING to a flood of reports, Microsoft claims to have just patched 23 vulnerabilities (the real number is a lot bigger and always a mystery). Quite a few of them are "critical".

It's a busy month for Windows administrators, as Microsoft has released eight security bulletins addressing more than 20 vulnerabilities. Five of the bulletins are rated 'critical'.


But here is the important bit:

Missing from the list is relief for a zero-day vulnerability in PowerPoint, actively targeted by hackers since last month.


This most likely means that for at least another month, all Microsoft Office users will be left exposed to attacks which have already begun, with Microsoft confirming this. Later on, people wonder why Conficker is able to propagate quite so rapidly. Here is the latest report about Conficker.

People have been speculating, waiting and prognosticating, but until now the extremely cleverly programmed Conficker worm has limited itself to mainly defensive measures, such as opening various communications channels (Conficker.C can set up peer-to-peer networks with other infected systems) in order to transform itself with downloaded code, and to actively combating anti-virus software and security analysis tools. Even on 1 April, the known date on which Conficker.C would be looking for updates, virtually nothing happened. Now however, money is involved: computers infected with the Conficker worm are downloading the scareware program "SpywareProtect2009".


Despite the latest lie from a Microsoft executive (circulating in the press this week), Windows Vista is just as insecure as its predecessors.

With so many of the world's Windows PCs already enlisted to join a botnet, it is no wonder that -- even according to Microsoft's latest report -- 97% of E-mail is SPAM. We have already shown why this is Microsoft's fault, at least in part. The catastrophic damage is not just one of productivity; according to this new report, there is also a severe environmental cost.

That's what McAfee says in its "Carbon Footprint of Spam" report released Wednesday, which states climate-change researchers from the firm ICF and McAfee's security staff calculated that the amount of energy needed to transmit, process and filter spam globally is equal to 33 billion kilowatt-hours each year. They say that can also be expressed as the equivalent to the electricity used in 2.4 million homes annually or the same green-house gas emissions from 3.1 million passenger cars using 2 billion gallons of gas.


The Inquirer, as usual, sensationalised it a bit.

Spam is killing the planet



[...]

Apparently, dealing with spam burns 33 billion kilowatt hours (one KW is about what a single bar electric heater will use) every year, enough to power 2.4 million homes.


There may be simple solutions to this.

Comments

Recent Techrights' Posts

Loads of People Exit IBM Tomorrow
Way to slam the door on on those who march or walk on
 
Links 04/12/2025: "People Hooked on [Slop] Far Are More Likely to Experience Mental Distress", Monopolies in Europe, and "Blogging Makes Me Feel Like A Worse Writer"
Links for the day
Dr. Andy Farnell: Can we regain control (of technology)?
"Technology as spiralling mass hysteria has the unsettling potential to draw even rational sceptics like myself into disaffection"
Links 04/12/2025: "Hey Hi" Implosion and Half of Europeans See Cheeto Trump as Enemy of Europe
Links for the day
Communication Needs Open Standards and Open Data
Standards are imperative
The "Hey Hi" House of Cards
The "Hey Hi" bubble is living on borrowed time (days or weeks) and it can implode any time now
Supporting the Free Software Foundation (FSF) Also Supports GNU Development
The FSF is mostly raising money to pay salaries
IBM's "AK Sez" Campaign
In today's media, to be characterised as important and smart one needn't be important and smart
Microsoft's Vista 11 Not Gaining, Just Plateauing or Even Going Down (Over Time)
"Desktop Windows version Market Share Worldwide"
Bubbles Popping, "Hey Hi" (AI) a Passing Fad
"Microsoft slides amid report it's cutting software sales quotas tied to AI"
At The Register MS, "Exclusive Webinar" Means Sponsored Video Ad Disguised as an Article
Why would one choose to watch these?
IBM Forces Staff to Sign an NDA If They Want Severance Package, in Effect Bribing Them or Denying Them Money They're Entitled to If They 'Disparage' IBM
We wrote about the legality or illegality of this in relation to Microsoft two years ago
IBM and Red Hat Not Done With 2025 Layoffs ("RAs") Yet
IBM isn't quite done laying off people this year, with only 3 weeks till Christmas
Gemini Links 04/12/2025: Christmas Looms, Devuan, and Programming
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, December 03, 2025
IRC logs for Wednesday, December 03, 2025
Slopwatch: It's Blowing, Jim (Gym), the Bubble is Blowing Up
Let's race to "zero GPT"
At IBM, "Last Day" Can be Same as Layoffs ("RAs"), Might be Euphemism Advanced by PR/HR Under NDA-Tied Conditions
They try to act all happy cheerful (in public) about becoming unemployed
Links 03/12/2025: "Disastrous Hey Hi (AI)", Breaches of Confidentiality, and "Global Democratic Recession"
Links for the day
Fake Security and 'Free' Certificates as a Trap of Planned Obsolescence and Top-Down Centralisation
The boiling frogs
Links 03/12/2025: UK Budget Leak and Criticism of Peace Posturing Over Ukraine
Links for the day
So Far Rust in Ubuntu Has Turned Out to be an Expensive Mistake
it is certainly seeming or feeling like the wrong people are in charge and they make bad decisions based on false reasoning
Gemini Links 03/12/2025: Obsession, Ubuntu, and Programming With Scheme
Links for the day
The Next Stages of EPO Coverage (and Why That Matters)
What's at stake here?
Wayland Rejection Is Not Racist
We need to collectively reject that
Reflections on a Month of Techrights Search
it looks like we've survived nearly a month without the search functionality being leveraged to stage DDoS attacks
New Year's Resolutions 4 Weeks Ahead of 2026
the main New Year's Resolution was... sleep
IBM Layoffs: It's Like They Read From a Script, Like They've Signed a Non-Disparagement Agreement/Clause
Some new departures
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, December 02, 2025
IRC logs for Tuesday, December 02, 2025
Keep the Pressure Up at Europe's Second-Largest Institution, the EPO
Some of the information concerns corruption, not just "money issues"
"The News" is Sponsored and It Lies (for Money), It Even Makes Up Phony Rankings
Many people exit IBM this month
Links 02/12/2025: Microsoft SharePoint Exploited, Openwashing Still a Thing, Europe Want a Seat at the Table With Russia Negotiations
Links for the day
Gemini Links 02/12/2025: Kentucky, Resilience, Raspberry Pi Pico, and Efficient Route Metrics
Links for the day
Steam Survey Signals Steep GNU/Linux Growth
the new (and latest) figures from Steam Survey affirm a trend of steady GNU/Linux growth
Short Survey of Past Media Coverage About Campinos, EUIPO, and a Call for Action on EPO Press Coverage
Of course Campinos got a sniff or a taste of lawlessness and impunity in Spain. Then he exported that to Germany.
Links 02/12/2025: "Around 500 million PCs are holding off upgrading to Windows 11" and "LLMs are a failure"
Links for the day
IBM's CEO Now on a Buzzwords Propaganda Tour
truly ridiculous
Attempts to Censor People Are a Sign That Arguments Were Lost, Gagging the Opposition Attempted Instead
no matter how supposedly "prestigious" an institution may be, it can still be corrupt and intolerant of criticism
"The Mafia" at the EPO Now Attacks Staff That Points Out Misconduct at the EPO
portraying the criticism as the real problem rather than the behaviour being criticised
Tomi Ahonen's Site is Gone, Memory-holed by Typepad's Shutdown
They had people assigned to do books to rewrite history and pretend that this sabotage never happened
Many IBM Layoffs Revealed This Week, Probably to Peak ("Last Day") December 4th
"In recent years, Executives and Upper management is hired from business schools, these people have no technical background. Technical people became slide makers and meetings organizers, thus, mediocrity became the rule. IBM is at the end of the road, slow death and embarrassment."
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, December 01, 2025
IRC logs for Monday, December 01, 2025