Eye on Microsoft: Emergency, Botnets, and No Remedy
- Dr. Roy Schestowitz
- 2009-07-26 08:50:30 UTC
- Modified: 2009-07-26 08:50:30 UTC
Summary: Self-explanatory news about Microsoft and security
●
Microsoft to issue emergency patches next week
Microsoft plans to issue two emergency patches next week that fix vulnerabilities in the Internet Explorer browser and Visual Studio developer suite that allow attackers to remotely execute malware.
●
Software Crackdown
Cyber attacks seem to be getting more sophisticated by the hour. A few weeks ago malware known as Zero Day was found to have exploited a vulnerability in Microsoft's Windows operating system that could allow online criminals to take control of a computer from anywhere in the world without being detected. The operation involved what is known as "drive by" attacks, in which visitors to legitimate Web sites are redirected to a page that secretly downloads the malicious software.
●
Microsoft admits it can't stop Office file format hacks
Microsoft's plan to "sandbox" Office documents in the next version of its application suite is an admission that the company can't keep hackers from exploiting file format bugs, a security analyst said today.
Recent Techrights' Posts
- Slopwatch: Brian Fagioli, Google News, and Other LLM Slopfarms
- Why does Google News keep promoting these fake articles?
- Links 29/10/2025: Amazon Kept "Data Center Water Use Secret", "Abuse of Power" Against Media
- Links for the day
- Gemini Links 29/10/2025: "My Hardware Specs" and "Goodbye Debian…"
- Links for the day
- EPO Cocainegate: Feedback and Clarifications
- Part III will come out soon
- Links 29/10/2025: "US Military Is Destroying the Planet Beyond Imagination" and Boat Strikes Deemed Unlawful
- Links for the day
- Quality Comes First (Techrights Search)
- It's generally working already, but we wish to polish it some more
- Techrights Party Countdown
- Late next week we'll be holding a party near our home
- European Parliament and Council Directive on Privacy is Vanishing
- "edited / censored some time more recently"
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Tuesday, October 28, 2025
- IRC logs for Tuesday, October 28, 2025
- Slopwatch: The March of Slopfarms, From UbuntuPIT to Linux Journal and to Various Fake Sites Still Promoted by Google News
- It's so worrying to see what the Web has become
- Links 29/10/2025: CISA, Ukraine, and Amazon Problems
- Links for the day
- [Teaser] The EPO's Spokesperson, a Cocaine User, Fancies Young Women
- How's that for "optics" in the EU and Europe's second-largest institution?
- How Will António Campinos Respond to the EPO's 'Cocainegate'?
- That's the same thing we saw and still see when the press deals with enablers and partners of Jeffrey Epstein
- Join Us Now and Share the News - Part IV: There Cannot be Free Software Without Free Press and Free Information
- One day, one can hope, more people will recognise that for Software Freedom we need free press and free thinkers
- Join Us Now and Share the News - Part III: Principled Stance Is Never Cheap
- Protecting the truth and insisting that the general public is made aware of things that really happened isn't cheap
- Join Us Now and Share the News - Part II: Because Scarcity of Accurate Information Breeds Collective Ignorance
- we too will strive to share information that's aggressively suppressed
- Gemini Links 28/10/2025: More New Arrivals at Geminispace, xkcd on "Document Forgery"
- Links for the day
- Join Us Now and Share the News - Part I: Defence of the Truth
- This year we make a very strong, firm statement for truth, even if that means explaining our work to the top media judge in the country
- Links 28/10/2025: Meta and Fentanylware (CheeTok) Age-Restricted Down Under, "Britain Needs China’s Money"
- Links for the day
- Links 28/10/2025: Mass Layoffs at Amazon and Charter to Cut 1,200 Jobs
- Links for the day
- The Cocaine Patent Office - Part II: The Person Who Planted Paid-for Fake News for the European Patent Office (EPO) is a Cocaine User, Friend of António Campinos, Now on Record as Having Been Arrested
- Background: High-level manager at the European Patent Office caught in public with cocaine, arrested
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Monday, October 27, 2025
- IRC logs for Monday, October 27, 2025
- Google News Drowning in Slop (and Slopfarms That Hijack About Half the Results)
- Google News seems to be drowning in this stuff
- Gemini Links 28/10/2025: "How to Maximize Your Positive Impact" and ASCII Art and Artist Attribution
- Links for the day
- PETA and Activism
- Being staff or volunteer in PETA isn't easy
- Big Blue, Huge Debt
- debt will soar again
- Links 27/10/2025: Mass Surveillance Sold as "AI", People Reluctant to Lose Physical Media
- Links for the day
- Parties and Milestones Again
- we've begun putting up about 40 balloons
- Techrights' 19th Anniversary: Bronze
- Time to go back to preparing for this anniversary
- Our Latest European Patent Office (EPO) Series Will Last Several Weeks, Will Ask the EPO Management and the European Union (EU) Very Difficult Questions
- If nobody loses a job (or jobs) over this, then the EU basically became no better than Colombia or Nicaragua
- Slopwatch: LinuxSecurity, UbuntuPIT, Brian Fagioli, and Google News
- We focus on stories that are fake or LLM slop that disguises itself as "news" about Linux
- Links 27/10/2025: Wikipedia Vandalism, Bruce Perens Opens up on Childhood
- Links for the day
- This Site Could Not be Done by LLMs Even If It Wanted to (Because It's Not a Parrot of What Other Sites Say)
- LLMs have no knowledge or deep understanding
- Microsoft is Disloyal Towards Its Most Loyal Employees
- Against its most faithful enablers
- 19 Years, No Censorship
- No factual information is ever going to be removed, more so if it is in the public interest
- We Are Not a Conventional Site, That's Why They Hate (or Love) Us
- Throughout the week this week we'll be focusing on the EPO
- Following the Line of Cocaine All the Way to the Top
- Even a million denials and spin-doctoring won't distract from the core issue
- The Cocaine Patent Office - Part I: António Campinos Brought Corruption and Nepotism to the EPO, Then Came the Cocaine
- High-level manager at the European Patent Office (EPO) caught in public with cocaine, the Office has some answering to do
- Purchasing/Possessing Computers Isn't the Same as Controlling Computers
- Let's strive to put computers back under the control of their users, no matter who purchased these (usually the users)
- Gemini Links 27/10/2025: Alhena 5.4.3 and Fixing Bash
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, October 26, 2025
- IRC logs for Sunday, October 26, 2025
- Thankfully We've Made Copies of More Interesting Data From statCounter
- If statCounter (the Web site or the 'webapp') vanished overnight, we'd still have something left of it
- More Silent Layoffs at IBM/Red Hat
- when the media counts such layoffs or presents tallies the numbers are very incomplete
Comments
David Gerard
2009-07-26 19:01:17
Roy Schestowitz
2009-07-26 19:28:25
Forget about malicious programs. When we have binary formats we also deal with malicious file formats and files that become malicious when merely interpreted, not executed.
David Gerard
2009-07-26 20:33:59
(a) in the '90s, Microsoft made a lot of their file formats dumps of C structs, for performance reasons;
(b) when this became incredibly hazardous with the Internet, and computers were powerful enough to check for malicious input ... they just kept on using the old code.
Then their master stroke of putting a complete programming language inside Office, thus inventing the macro virus.
Then their other master stroke of programs that execute any random instructions they happen to find in EMAIL MESSAGES.
INNOVATION!