Bonum Certa Men Certa

Nothing New Under the Microsoft

Cracker



Microsoft's handling of security is a cyclic routine that goes like this:

  1. Many flaws get reported, accumulated, and then mostly ignored
  2. Attacks on the unpatched flaws begin, so Microsoft 'kindly' bothers to work on patches in a rush
  3. Patch Tuesday arrives and Microsoft delivers a slew of patches (occasionally delivering nothing critical for bragging rights in the press, only to deliver a massive number of critical patches the following month, i.e. deferral)
  4. Patches arrive too late, after many servers and desktop have already been hijacked
  5. A number of zero-day flaws emerge, some of which exploiting vulnerabilities Microsoft has been aware of for a long time
  6. Patches turn out to be dysfunctional and consequently many computers are left out of services
  7. Microsoft reworks the patches and then delivers a patch to the broken patches
  8. Repeat (1)


This month was no exception. Microsoft delivered half a dozen "critical" patches (usually meaning that the vulnerability they patch enables crackers to seize full control of a to-be-compromised machine).

Appended below are reports from the past couple of days alone. The lies need to end because everyone suffers.

____ [1] Another Microsoft Bug Revealed on Huge Patch Day

Along with its biggest patch release in five years, Microsoft warned on Tuesday of another potentially dangerous vulnerability in its software.

The problem lies within the WordPad Text Converter for Word 97 files, Microsoft said in an advisory.

The systems affected include Windows 2000 Service Pack 4, Windows XP Service Pack 2, Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2, Microsoft said. XP Service Pack 3 and the Vista operating systems are not affected.


[2] Two new zero-day exploits dent Microsoft's Patch Tuesday

Microsoft's Patch Day delivered eight updates, but has been overshadowed by newly discovered zero day holes, which are apparently not closed by the new updates.


[3] New Web Attack Exploits Unpatched IE Flaw

As Microsoft readies its latest set of security updates, online attackers have begun exploiting a new flaw in the company's Internet Explorer (IE) browser.


[4] Third Zero Day exploit appears

Microsoft has confirmed it is investigating another zero day exploit.


[5] Security vulnerability found in MS SQL Server 2000

SEC Consult say Microsoft has been aware of the problem since April this year. Despite the promise of a patch by September, a release date for the patch remains uncertain.


Comments

Recent Techrights' Posts

GNU/Linux up to 5% in Ireland, Not Counting Chromebooks
statCounter is an Irish
The War on Free Software Reporters - Part III - Doxing and LARPing
LARPing is an issue I've had to deal with for nearly 20 years
The Media Finally Admits (on a Regular Basis) That LLMs Suck
They could not replace medical doctors, teachers, lawyers etc.
 
In the Month of May 2024 the OSI's Blog Was Almost 100% Microsoft Lobbying, Microsoft Staff, Microsoft Proprietary Software, and Microsoft Events
Entryism complete. RIP, OSI.
An Important Goal Has Been Accomplished Already
Stubborn activists need to insist on a future where computer users actually control the computers they own
Gemini Links 02/06/2024: Delayed Disappointment
Links for the day
statCounter: GNU/Linux on More Than 1 in 5 Desktops/Laptops
Desktop Operating System Market Share Norway
Reminder: The First CEO of IBM (Owner of Red Hat) Was "Convicted on Extortion" (According to Edwin Black, Author of "IBM and the Holocaust")
Red Hat is not a liberal company
GNU/Linux Market Share in Turkey Now Exceeds 10%, According to StatCounter
StatCounter (or statCounter) shows considerable increases
GNU/Linux in Germany: The Seven Percent
The historical data shows that it wasn't always like this
Slovenia: Windows Becomes Minority Market Share This Month
It finally happened. Android is now measured as bigger than Windows.
statCounter: Bing Has Lost Market Share Since the Chatbot Hype, in Europe Yandex Nearly Exceeds Bing Now
Bing also had many layoffs (not that the media bothered covering that); we must debunk Microsoft's baseless claims and deliberate lies/hype
Microsoft Windows Falls Below 10% in Africa, Down to About 20% in Asia
The future isn't Windows
Taiwan Can Defend Its Autonomy Better by Avoiding Microsoft (Back Doors)
Maybe it's just a coincidence that GNU/Linux "took off" when Hong Kong lost its perceived independence from China
The War on Free Software Reporters - Part IV - Impersonation and Menacing Behaviour, Defamation Under One's Own Name
Such serial defamation (that went on for a very long time) is coordinated and relentless
Links 02/06/2024: Workers' Strikes and a Warming World
Links for the day
Microsoft Falls to All-Time Low of 25% in Operating Systems
If Android is counted, Windows is in trouble as it's down to all-time low of 25%
Steam Survey: GNU/Linux Up, But Canonical's Ubuntu Declining
big increases for GNU/Linux, Arch Linux gaining at Ubuntu's expense
Guardian Digital, Inc (linuxsecurity.com) Leveraging Microsoft Chatbots to SPAM for Microsoft (Googlebombing "Linux")?
Welcome to the Web in 2024. Search for "Linux" news, get Windows garbage.
Smallest Number of New Debian Developers in More Than 2 Years
Maybe Debian should recognise there's a problem instead of trying to censor - at humongous expense - those who speak about the problem
Slashdot's "Linux" Section is Reposting Press Releases for Red Hat
Is this being paid for?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, June 01, 2024
IRC logs for Saturday, June 01, 2024
Links 01/06/2024: Microsoft Chaffbot Broken Out of Control
Links for the day
Why We're Taking Things Up a Notch
Expect about 20 articles a day this year
Sites That Cover WSL Are Helping Microsoft's Attack on GNU/Linux
Calling out the typical culprits
Plans for June
We'll try to publish Daily Links every time we have enough of these
Links 01/06/2024: Ukraine Updates, MongoDB Collapses
Links for the day
Gemini Links 01/06/2024: MNT Pocket Reform, Gemini and Content Length
Links for the day
Links 01/06/2024: WeblogPoMo2024, Pentagon’s Increasing Reliance on (i.e. Bailouts to) Microsoft
Links for the day
Twitter is (in Many Ways) Already Dead
Put an 'X' on it
Posts About Free Software, BSD, and GNU/Linux
Focus shifts have occasionally been discussed here over the years
After Softpedia Pushed Out Its Linux News Editor - and Effectively Killed the Linux Section - it Killed the Whole News Section (Altogether)
So they've killed Linux coverage, then their whole "news" section died
Their Goal is Control, Not Security (and Their Staff Advocates Fake Security or Pricey Gimmicks That Disempower the Users)
Those companies just want control, or simply domination over users (and their computers)
[Meme] The Lowest Standards of Security
No need for any qualifications
IRC Proceedings: Friday, May 31, 2024
IRC logs for Friday, May 31, 2024
Over at Tux Machines...
GNU/Linux news for the past day
Cybersecurity is a structural not behavioural problem.
Reprinted with permission from Cyber|Show
Free Software is the Future, Open Source is Just Openwashing (Proprietary With a False Marketing Twist)
Also see postopen.org
Society Has Been Destabilised by Social Control Networks
Is it time to get rid of them, if not by sanctions/bans then simply by popular boycotts?
Gemini Turns 5 This Month
As long as Geminispace exists and is accessed by enough people, Gemini Protocol will continue to matter
Links 01/06/2024: More Crackdowns in Hong Kong, Street Named After Navalny
Links for the day
The War on Free Software Reporters - Part II - Antisocial Mobs
how various GNU/Linux bloggers got "canceled" over the years
Microsoft's Share of Physical Web Servers Fell From 9.14% to 9.04% in One Month
What's interesting to us is how Microsoft continues moving down in everything measured
Links 31/05/2024: Escalations in Ukraine and Russia, National Reporter's Shield Law in US
Links for the day
Links 31/05/2024: Generating and Using Identifiers, Why Unicode
Links for the day
A 3-Year Campaign to Coerce/Intimidate Us Into Censorship: In Summary
Some high-profile examples of defamation include Linus Torvalds, Richard Stallman...
[Meme] Never "Missing Out" in FOSS Conferences
The sexists who objectify women and bully women are going to FOSS events in pursuit of sex, according to themselves
Racism, Ageism, and Ableism at IBM/Red Hat and Kyndryl
IBM's Kyndryl is now accused of "racial, age, disability discrimination"
The War on Free Software Reporters - Part I - Why Techrights Cannot be Censored (and Won't be Censored)
Microsoft remains by far the biggest culprit
In Spite of Boot-locking (Trying to Make It Hard If Not Impossible to Install BSDs and GNU/Linux on New PCs) Microsoft's Grip is Rapidly Slipping
Escaping the Microsoft prison
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, May 30, 2024
IRC logs for Thursday, May 30, 2024
Microsoft's Problem in Puerto Rico
Notice how much Windows has fallen
Gemini Links 31/05/2024: MNT Pocket Reform and Benben v0.5.0
Links for the day
"I once preached peaceful coexistence with Windows. You may laugh at my expense -- I deserve it." -Be's CEO Jean-Louis Gassée
Execution of Red Hat: But I helped promote Azure and .NET
In Many Countries Vista 11's Market Share Goes Down, Not Up (Even Microsoft-Funded Mainstream Media Admits This)
More people are moving to GNU/Linux