Eye on Microsoft: Ransomware, Botnets, Critical Flaws, and Insecure Microsoft File Types
- Dr. Roy Schestowitz
- 2009-07-28 07:18:43 UTC
- Modified: 2009-07-28 07:18:43 UTC
●
Smut page ransomware Trojan ransacks browsers
Russian cybercrooks have come up with a variant of ransomware scams, which works by displaying an invasive advert for online smut in users' browsers that victims are extorted to pay to remove.
●
The Business of Botnets
Kaspersky Lab released some interesting statistics recently in a technical whitepaper. As part of its research into the cyber-underground, the company took a look at how botmasters are pricing the networks under their control.
●
Microsoft to fix critical hole in IE
In a rare move, Microsoft on Friday said it would be releasing security updates on Tuesday--outside of its monthly patch cycle--for a critical vulnerability in Internet Explorer and a moderate vulnerability in Visual Studio.
●
Microsoft to Issue Emergency Patches Next Week
The advance notification advisory that Microsoft released about these upcoming patches doesn't say so explicitly, but a spokesperson for the company confirmed that the updates will address a critical security flaw in collection of code that Microsoft uses in a number of places in Windows. Having a vulnerability in this so-called "code library" is especially dangerous because Microsoft also provides this library to third-party software makers to help them build programs that can leverage certain built-in features of Windows.
●
Insecure by design: MS Office formats
You see, when you're opening an Office document today, you're not just opening static words, images, or numbers. You're actually starting a program that uses Microsoft Office as its interpreter. And, no matter whether you're using Word 2,0 formats or the 2008's 7,000+ pages mis-mash of 'standard' ECMA-376 Office Open XML file formats, there is no built-in network security layer. Instead, there is a mis-mash of fixes for one problem or the other.
Also see:
Emergency, Botnets, and No Remedy
Recent Techrights' Posts
- Oligarchs and States Always Attempted to Obstruct Efforts to Expose Their Corruption
- We commend the administrator who consistently and adamantly defend the freedom of speech
- GNU/Linux Exceeding 5% in Guadeloupe According to statCounter
- GNU/Linux "share" estimates in Guadeloupe
- EPO People Power - Part XXXII - Little Hope That European Press Will Attempt to Expose Drug Abuse in Europe's Second-Largest Organisation
- What does this tell us about the press in Europe?
- IBM SkillsBuild as Microsoft Training, Microsoft Vendor Lock-in, Microsoft Surveillance
- Microsoft benefits from IBM's "training"
-
- Links 12/01/2026: Brussels Plotting Exit From GAFAM (US), Carole Cadwalladr Explains "Peter Thiel's New Model Army"
- Links for the day
- Scheduled Maintenance Between 15th of January and Days to Follow, Free Software Foundation (FSF) Looking to Add 43 More Members by 16th of January
- People who value Software Freedom should consider joining to support the FSF
- Bracing for Microsoft Layoffs, Tired of Microsoft Lies, Microsoft Staff Wants Transparency, Not Face-Saving Coverup From Frank Shaw
- totally made up stock price
- GNU/Linux Estimated at Around 5% in Montserrat
- another country where the "share" of GNU/Linux is now measured at 5%
- Dr. Richard Stallman @ Georgia Tech Next Week
- More Than One Week From Now
- Three most controversial Australian authors linked to St Paul's, Coburg
- Reprinted with permission from Daniel Pocock
- Links 11/01/2026: Data Breaches and Recent (Early 2026) Political Developments
- Links for the day
- Gemini Links 12/01/2026: Insomniacs After School and Boycotting Amazon
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, January 11, 2026
- IRC logs for Sunday, January 11, 2026
- Brett Wilson LLP 'Dropping' the LLP, Is This Rebranding?
- It's not a coincidence or a glitch, there was a formal change somewhere in the system
- Can IBM Still Control the Narrative?
- We'll see what comes out through the grapevine later this week
- EPO People Power - Part XXXI - Almost No Crime is Possible Without Enablers and Complicit Colleagues
- By the middle of January 2026 we'll have taken things up another gear
- Aruba's GNU/Linux Adoption Seems to Have Reach All-Time High This Year
- ChromeOS rose by a lot too
- After the LLM Slop Frenzy...
- In every way, slop is no better than spam
- Links 11/01/2026: 'Nothing to Lose' in Iran and Kyiv Restores Electricity
- Links for the day
- Gemini Links 11/01/2026: "Late To The Party" and "Thinking About Software Licences"
- Links for the day
- Links 11/01/2026: Bob Weir and Stewart Cheifet Perish
- Links for the day
- Higher Adoption Rates of GNU/Linux in Cyprus in Recent Years
- there are some Cypriots who are championing Free software
- Microsoft's linkedin.com is Shrinking, Expect LinkedIn Layoffs to Carry on in 2026
- Expect the mass layoffs and office closures to carry on there, maybe as early as next week
- Gemini Links 11/01/2026: Scott Morgan and 'The Unix Way'
- Links for the day
- IBM to Be 'Reorganised'
- The rich look for ways to 'monetise' what's left IBM
- Dr. Andy Farnell Explains Why He'll Stop Sending E-mail to Microsoft and Gmail Users
- The article is long and well worth reading
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Saturday, January 10, 2026
- IRC logs for Saturday, January 10, 2026
- Monday, January 12, Red Hat Layoffs Allegedly Planned
- We'll update this post or follow up if or when we get more information
- Slop Still Becoming Rare as Another Week Ends
- Generally speaking, calm and quiet is desirable, it's what we hope for (an absence of slop, a lack of need to keep abreast of it, ultimately)
- Links 10/01/2026: Iran Offline, Venezuelans Decry Civilian Casualties
- Links for the day
- GAFAM Wants War
- Go war! Go bailouts! Go debt! Go Wall Street!
- GNOME Foundation's Microsoft Developer Account
- "Lately they're teaming up with Mozilla to eliminate middle click paste - something which I use continuously."
- GNU/Linux and Chromebooks Rose to Almost 10% in Haiti
- What's noteworthy is that this month GNU/Linux is measured at around 8% and ChromeOS at about 2%
- Links 10/01/2026: "Abolish ICE or GTFO", Calls to Ban X/Twitter From Apple/Google App Stores (or Implement National Blocks) Over MElon Turning It Into Non-consensual Deepfake Porn Site
- Links for the day
- EPO People Power - Part XXX - New Year Starts, Cocainegate Still Discussed a Lot, António Campinos Desperate for Distraction From It
- Why the sudden change or 'generosity'? [...] Actual cocaine addicts caused nervous breakdowns among sober people
- 2026 Might be the Year Microsoft Replaces Layoffs With Mass Firings (No Severance Payments to Dismissed Staff)
- It's hard to "see" PIPs unless insiders blow the whistle
- IBM and Microsoft Hiding Layoffs in Similar, Overlapping Ways
- Performance Improvement Plans aplenty
- IBM is a Cancer That Attaches Itself to Everything
- Red Hat should have remained an independent company
- Links 10/01/2026: STV Layoffs (Scottish TV), “CBS Evening News” in Chaos (Culls and Censorship by the US Regime)
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Friday, January 09, 2026
- IRC logs for Friday, January 09, 2026
- Gemini Links 10/01/2026: Blackout, E-Waste, and Secondary Smartphone
- Links for the day