Eye on Microsoft: Windows (In)Security in the News
- Dr. Roy Schestowitz
- 2009-04-24 10:24:19 UTC
- Modified: 2009-04-24 10:24:19 UTC
●
Windows Trojan That Infected Over 3.6 Million PCs Evolves with Worm Behavior
One of the top families of malicious code targeting the Windows platform has evolved with the addition of worm behavior, Microsoft warns. According to data made public via the Microsoft Security Intelligence Report, the Win32/Vundo Trojan infected over 3.6 million computers in the second half of 2008, and occupies the third position in a malware ranking behind Renos and Zlob. Vundo is a family of malware with various components that are designed to serve victims 'out of context' pop-up advertisements following infection. Microsoft warns that the Vundo family of malicious software can also
be used to download and execute arbitrary files.
●
One bot-infected PC = 600,000 spam messages a day
TRACElabs concluded that Rustock and Xarvester, the latter perhaps linked to the down-and-out Srizbi botnet, are the most efficient spam spewers of the nine bots. Each is capable of sending up to 25,000 messages per hour, or 600,000 per day, and 4.2 million per week.
●
Updated research of the largest base of real-world vulnerability data
4. Exploitation - Eighty percent of vulnerability exploits are now available within single digit days after the vulnerability’s public release. In 2008, Qualys Labs logged 56 vulnerabilities with zero-day exploits, including the RPC vulnerability that produced Conficker. In 2009, the first vulnerability released by Microsoft, MS09-001 had an exploit available within seven days. Microsoft’s April Patch Tuesday included known exploits for over 47 percent of the published vulnerabilities. This law had the most drastic change from the Laws 1.0 in 2004, which provided a comfortable 60 days as guidance.
Recent Techrights' Posts
- A Week After a Worldwide Windows Outage Microsoft is 'Bricking' Windows All On Its Own, Cannot Blame Others Anymore
- A look back at a week of lousy press coverage, Microsoft deceit, and lessons to be learned
-
- Links 26/07/2024: Hamburgerization of Sushi and GNU/Linux Primer
- Links for the day
- Links 26/07/2024: Tesco Cutbacks and Fake Patent Courts
- Links for the day
- Links 26/07/2024: Grimy Residue of the 'AI' Bubble and Tensions Around Alaska
- Links for the day
- Gemini Links 26/07/2024: More Computers and Tilde Hosting
- Links for the day
- Links 26/07/2024: "AI" Hype Debunked and Elon Musk's "X" Already Spreads Political Disinformation
- Links for the day
- "Why you boss is insatiably horny for firing you and replacing you with software."
- Ask McDonalds how this "AI" nonsense with IBM worked out for them
- No Olympics
- We really need to focus on real news
- Nobody Holds the GNOME Foundation Accountable (Not Even IRS), It's Governed by Lawyers, Not Geeks, and Headed by a Shaman Crank
- GNOME is a deeply oppressive institutions that eats its own
- [Meme] The 'Modern' Web and 'Linux' Foundation Reinforcing Monopolies and Cementing centralisation
- They don't care about the users and issuing a few bytes with random characters costs them next to nothing. It gives them control over billions of human beings.
- 'Boiling the Frog' or How Online Certificate Status Protocol (OCSP) is Being Abandoned at Short Notice by Let's Encrypt
- This isn't a lack of foresight but planned obsolescence
- When the LLM Bubble Implodes Completely Microsoft Will be 'Finished'
- Excuses like, "it's not ready yet" or "we'll fix it" won't pass muster
- "An escalator can never break: it can only become stairs"
- The lesson of this story is, if you do evil things, bad things will come your way. So don't do evil things.
- When Wikileaks Was Still Primarily a Wiki
- less than 14 years ago the international media based its war journalism on what Wikileaks had published
- The Free Software Foundation Speaks Out Against Microsoft
- the problem is bigger than Microsoft and in the long run - seeing Microsoft's demise - we'll need to emphasise Software Freedom
- IRC Proceedings: Thursday, July 25, 2024
- IRC logs for Thursday, July 25, 2024
- Over at Tux Machines...
- GNU/Linux news for the past day
- Links 26/07/2024: E-mail on OpenBSD and Emacs Fun
- Links for the day
- Links 25/07/2024: Talks of Increased Pension Age and Biden Explains Dropping Out
- Links for the day
- Links 25/07/2024: Paul Watson, Kernel Bug, and Taskwarrior
- Links for the day
- [Meme] Microsoft's "Dinobabies" Not Amused
- a slur that comes from Microsoft's friends at IBM
- Flashback: Microsoft Enslaves Black People (Modern Slavery) for Profit, or Even for Losses (Still Sinking in Debt Due to LLMs' Failure)
- "Paid Kenyan Workers Less Than $2 Per Hour"
- From Lion to Lamb: Microsoft Fell From 100% to 13% in Somalia (Lowest Since 2017)
- If even one media outlet told you in 2010 that Microsoft would fall from 100% (of Web requests) to about 1 in 8 Web requests, you'd probably struggle to believe it
- Microsoft Windows Became Rare in Antarctica
- Antarctica's Web stats still near 0% for Windows
- Links 25/07/2024: YouTube's Financial Problem (Even After Mass Layoffs), Journalists Bemoan Bogus YouTube Takedown Demands
- Links for the day
- Gemini Now 70 Capsules Short of 4,000 and Let's Encrypt Sinks Below 100 (Capsules) as Self-Signed Leaps to 91%
- The "gopher with encryption" protocol is getting more widely used and more independent from GAFAM
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Wednesday, July 24, 2024
- IRC logs for Wednesday, July 24, 2024
- Techrights Statement on YouTube
- YouTube is a dying platform
- [Video] Julian Assange on the Right to Know
- Publishing facts is spun as "espionage" by the US government and "treason" by the Russian government, to give two notable examples
- Links 25/07/2024: Tesla's 45% Profit Drop, Humble Games Employees All Laid Off
- Links for the day
- Gemini Links 25/07/2024: Losing Grip and collapseOS
- Links for the day