Eye on Microsoft: Ransomware, Botnets, Critical Flaws, and Insecure Microsoft File Types
- Dr. Roy Schestowitz
- 2009-07-28 07:18:43 UTC
- Modified: 2009-07-28 07:18:43 UTC
●
Smut page ransomware Trojan ransacks browsers
Russian cybercrooks have come up with a variant of ransomware scams, which works by displaying an invasive advert for online smut in users' browsers that victims are extorted to pay to remove.
●
The Business of Botnets
Kaspersky Lab released some interesting statistics recently in a technical whitepaper. As part of its research into the cyber-underground, the company took a look at how botmasters are pricing the networks under their control.
●
Microsoft to fix critical hole in IE
In a rare move, Microsoft on Friday said it would be releasing security updates on Tuesday--outside of its monthly patch cycle--for a critical vulnerability in Internet Explorer and a moderate vulnerability in Visual Studio.
●
Microsoft to Issue Emergency Patches Next Week
The advance notification advisory that Microsoft released about these upcoming patches doesn't say so explicitly, but a spokesperson for the company confirmed that the updates will address a critical security flaw in collection of code that Microsoft uses in a number of places in Windows. Having a vulnerability in this so-called "code library" is especially dangerous because Microsoft also provides this library to third-party software makers to help them build programs that can leverage certain built-in features of Windows.
●
Insecure by design: MS Office formats
You see, when you're opening an Office document today, you're not just opening static words, images, or numbers. You're actually starting a program that uses Microsoft Office as its interpreter. And, no matter whether you're using Word 2,0 formats or the 2008's 7,000+ pages mis-mash of 'standard' ECMA-376 Office Open XML file formats, there is no built-in network security layer. Instead, there is a mis-mash of fixes for one problem or the other.
Also see:
Emergency, Botnets, and No Remedy
Recent Techrights' Posts
- 2025 Will be Fought and Fraught With LLM Slop or Fake 'Articles' (Former Media/News Sites Turning to Marketing Spam)
- The elephant in the room?
- Brittany Day Can Rest and Let Microsoft/Chatbots Write Fake 'Articles' About "Linux" This Christmas
- Who said people don't work on Christmas? Chatbots or plagiarism-as-a-service work 24/7, every day of the year except during Microsoft downtimes
-
- Microsoft Openwashing Stunts Initiative (OSI) is A Vulture in "Open" Clothing
- it's quite telling that the OSI isn't protecting the Open Source Definition
- Gemini Links 25/12/2024: Reality Bites and Gopher Thanks
- Links for the day
- Links 26/12/2024: Japan-China Mitigations and Mozambique Prison Escape (1,500 Prisoners)
- Links for the day
- Links 26/12/2024: Ukraine's Energy Supplies Bombed on Christmas Day, Energy Lines Cut/Disrupted in the Baltic Sea Again
- Links for the day
- Gemini Links 26/12/2024: Rot Economy, Self-hosted Tinylogs
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Wednesday, December 25, 2024
- IRC logs for Wednesday, December 25, 2024
- [Meme] Time to Also Investigate Bill Gaetz
- Investigation overdue
- IBM Has Almost Obliterated or Killed the Entire Fedora Community (Not IBM Staff)
- Remaining Fedora insiders are well aware of this, but bringing this up (an "accusation" against IBM) might be a CoC violation
- Links 25/12/2024: Fentanylware (TikTok) Scams and "Zelle Scams Lead to $870M Loss"
- Links for the day
- Links 25/12/2024: Windows TCO Brought to SSH, Terence Eden 'Retires'
- Links for the day
- Links 25/12/2024: Latest Report Front Microsoft Splinter Group, War Updates
- Links for the day
- Links 25/12/2024: Hong Kong Attacks Activists During Holidays, Xerox to Buy Lexmark
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Tuesday, December 24, 2024
- IRC logs for Tuesday, December 24, 2024
- Gemini Links 25/12/2024: Open Source Social and No Search
- Links for the day
- Brittany Day Connects Windows Ransomware to "Linux" Using Microsoft LLMs (FUD Galore, Zero Effort, No Accountability)
- FUD and misinformation made by Microsoft LLMs again?
- Links 24/12/2024: Labour Strikes and TikTok Scrambling to Prop Up Radical Politicians That Would Protect TikTok
- Links for the day
- Where the Population is Controlled by Skinnerboxes Inside People's Pockets (or Purses)
- A very small fraction of mobile users practise or exercise freedom/control over the skinnerbox
- [Meme] Coin-Operated Publishers (Gaming the Message, Buying the Narrative)
- Advertise (sponsor) to 'play'
- Advertisers and Their Covert Impact on Publications' Output (or Writers' Topics of Choice, as Assigned or Approved by Editors)
- It cannot be trivially denied that sponsorship in the form of "advertising" impacts where publishers go (or don't go, won't go)
- Terrible Year for Microsoft Windows in Cyprus
- down from 86% to 72% since January
- [Meme] How to Kill Unions (Staff on Shoestring Budget Cannot Afford Lawyers)
- What next for the EPO? "Gig economy"?
- The EPO's Staff Union (SUEPO) Takes Legal Action to Rectify the Decrease in Wages (Lessening of Purchasing Power)
- here is what the union published
- Gemini Links 24/12/2024: Deedum Gemini Client Gets Colour Support, Advent of Code 2024
- Links for the day
- Microsoft Windows Slides to New Lows in Colombia
- Now Windows is at an all-time low
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Monday, December 23, 2024
- IRC logs for Monday, December 23, 2024