Microsoft pinky swears that THIS TIME they’ll make security a priority
One June 20, I'm live onstage in LOS ANGELES for a recording of the GO FACT YOURSELF podcast. On June 21, I'm doing an ONLINE READING for the LOCUS AWARDS at 16hPT. On June 22, I'll be in OAKLAND, CA for a panel and a keynote at the LOCUS AWARDS.
As the old saying goes, "When someone tells you who they are and you get fooled again, shame on you." That goes double for Microsoft, especially when it comes to security promises.
Microsoft is, was, always has been, and always will be a rotten company. At every turn, throughout their history, they have learned the wrong lessons, over and over again.
That starts from the very earliest days, when the company was still called "Micro-Soft." Young Bill Gates was given a sweetheart deal to supply the operating system for IBM's PC, thanks to his mother's connection. The nepo-baby enlisted his pal, Paul Allen (whom he'd later rip off for billions) and together, they bought someone else's OS (and took credit for creating it – AKA, the "Musk gambit").
Microsoft then proceeded to make a fortune by monopolizing the OS market through illegal, collusive arrangements with the PC clone industry – an industry that only existed because they could source third-party PC ROMs from Phoenix:
Bill Gates didn't become one of the richest people on earth simply by emerging from a lucky orifice; he also owed his success to vigorous antitrust enforcement. The IBM PC was the company's first major initiative after it was targeted by the DOJ for a 12-year antitrust enforcement action. IBM tapped its vast monopoly profits to fight the DOJ, spending more on outside counsel to fight the DOJ antitrust division than the DOJ spent on all its antitrust lawyers, every year, for 12 years.
IBM's delaying tactic paid off. When Reagan took the White House, he let IBM off the hook. But the company was still seriously scarred by its ordeal, and when the PC project kicked off, the company kept the OS separate from the hardware (one of the DOJ's major issues with IBM's previous behavior was its vertical monopoly on hardware and software). IBM didn't hire Gates and Allen to provide it with DOS because it was incapable of writing a PC operating system: they did it to keep the DOJ from kicking down their door again.
The post-antitrust, gunshy IBM kept delivering dividends for Microsoft. When IBM turned a blind eye to the cloned PC-ROM and allowed companies like Compaq, Dell and Gateway to compete directly with Big Blue, this produced a whole cohort of customers for Microsoft – customers Microsoft could play off on each other, ensuring that every PC sold generated income for Microsoft, creating a wide moat around the OS business that kept other OS vendors out of the market. Why invest in making an OS when every hardware company already had an exclusive arrangement with Microsoft?
The IBM PC story teaches us two things: stronger antitrust enforcement spurs innovation and opens markets for scrappy startups to grow to big, important firms; as do weaker IP protections.
Microsoft learned the opposite: monopolies are wildly profitable; expansive IP protects monopolies; you can violate antitrust laws so long as you have enough monopoly profits rolling in to outspend the government until a Republican bootlicker takes the White House (Microsoft's antitrust ordeal ended after GW Bush stole the 2000 election and dropped the charges against them). Microsoft embodies the idea that you either die a rebel hero or live long enough to become the evil emperor you dethroned.
From the first, Microsoft has pursued three goals:
Get too big to fail;
Get too big to jail;
Get too big to care.
It has succeeded on all three counts. Much of Microsoft's enduring power comes from succeeded IBM as the company that mediocre IT managers can safely buy from without being blamed for the poor quality of Microsoft's products: "Nobody ever got fired for buying Microsoft" is 2024's answer to "Nobody ever got fired for buying IBM."
Microsoft's secret sauce is impunity. The PC companies that bundle Windows with their hardware are held blameless for the glaring defects in Windows. The IT managers who buy company-wide Windows licenses are likewise insulated from the rage of the workers who have to use Windows and other Microsoft products.
Microsoft doesn't have to care if you hate it because, for the most part, it's not selling to you. It's selling to a few decision-makers who can be wined and dined and flattered. And since we all have to use its products, developers have to target its platform if they want to sell us their software.
This rarified position has afforded Microsoft enormous freedom to roll out harebrained "features" that made things briefly attractive for some group of developers it was hoping to tempt into its sticky-trap. Remember when it put a Turing-complete scripting environment into Microsoft Office and unleashed a plague of macro viruses that wiped out years worth of work for entire businesses?
It wasn't just Office; Microsoft's operating systems have harbored festering swamps of godawful defects that were weaponized by trolls, script kiddies, and nation-states:
https://en.wikipedia.org/wiki/EternalBlue
Microsoft blamed everyone except themselves for these defects, claiming that their poor code quality was no worse than others, insisting that the bulging arsenal of Windows-specific malware was the result of being the juiciest target and thus the subject of the most malicious attention.
Even if you take them at their word here, that's still no excuse. Microsoft didn't slip and accidentally become an operating system monopolist. They relentlessly, deliberately, illegally pursued the goal of extinguishing every OS except their own. It's completely foreseeable that this dominance would make their products the subject of continuous attacks.
There's an implicit bargain that every monopolist makes: allow me to dominate my market and I will be a benevolent dictator who spends his windfall profits on maintaining product quality and security. Indeed, if we permit "wasteful competition" to erode the margins of operating system vendors, who will have a surplus sufficient to meet the security investment demands of the digital world?
But monopolists always violate this bargain. When faced with the decision to either invest in quality and security, or hand billions of dollars to their shareholders, they'll always take the latter. Why wouldn't they? Once they have a monopoly, they don't have to worry about losing customers to a competitor, so why invest in customer satisfaction? That's how Google can piss away $80b on a stock buyback and fire 12,000 technical employees at the same time as its flagship search product (with a 90% market-share) is turning into an unusable pile of shit:
Microsoft reneged on this bargain from day one, and they never stopped. When the company moved Office to the cloud, it added an "analytics" suite that lets bosses spy on and stack-rank their employees ("Sorry, fella, Office365 says you're the slowest typist in the company, so you're fired"). Microsoft will also sell you internal data on the Office365 usage of your industry competitors (they'll sell your data to your competitors, too, natch). But most of all, Microsoft harvest, analyzes and sells this data for its own purposes:
Leave aside how creepy, gross and exploitative this is – it's also incredibly reckless. Microsoft is creating a two-way conduit into the majority of the world's businesses that insider threats, security services and hackers can exploit to spy on and wreck Microsoft's customers' business. You don't get more "too big to care" than this.
Or at least, not until now. Microsoft recently announced a product called "Recall" that would record every keystroke, click and screen element, nominally in the name of helping you figure out what you've done and either do it again, or go back and fix it. The problem here is that anyone who gains access to your system – your boss, a spy, a cop, a Microsoft insider, a stalker, an abusive partner or a hacker – now has access to everything, on a platter. Naturally, this system – which Microsoft billed as ultra-secure – was wildly insecure and after a series of blockbuster exploits, the company was forced to hit pause on the rollout:
For years, Microsoft waged a war on the single most important security practice in software development: transparency. This is the company that branded the GPL Free Software license a "virus" and called open source "a cancer." The company argued that allowing public scrutiny of code would be a disaster because bad guys would spot and weaponize defects.
This is "security through obscurity" and it's an idea that was discredited nearly 500 years ago with the advent of the scientific method. The crux of that method: we are so good at bullshiting ourselves into thinking that our experiment was successful that the only way to make sure we know anything is to tell our enemies what we think we've proved so they can try to tear us down.
Or, as Bruce Schneier puts it: "Anyone can design a security system that you yourself can't think of a way of breaking. That doesn't mean it works, it just means that it works against people stupider than you."
And yet, Microsoft – whose made more widely and consequentially exploited software than anyone else in the history of the human race – claimed that free and open code was insecure, and spent millions on deceptive PR campaigns intended to discredit the scientific method in favor of a kind of software alchemy, in which every coder toils in secret, assuring themselves that drinking mercury is the secret to eternal life.
Access to source code isn't sufficient to make software secure – nothing about access to code guarantees that anyone will review that code and repair its defects. Indeed, there've been some high profile examples of "supply chain attacks" in the free/open source software world:
But there's no good argument that this code would have been more secure if it had been harder for the good guys to spot its bugs. When it comes to secure code, transparency is an essential, but it's not a sufficency.
The architects of that campaign are genuinely awful people, and yet they're revered as heroes by Microsoft's current leadership. There's Steve "Linux Is Cancer" Ballmer, star of Propublica's IRS Files, where he is shown to be the king of "tax loss harvesting":
Microsoft may give lip service to open source these days (mostly through buying, stripmining and enclosing Github) but Ballmer's legacy lives on within the company, through its wildly illegal tax-evasion tactics:
But Ballmer is an angel compared to his boss, Bill Gates, last seen some paragraphs above, stealing the credit for MS DOS from Tim Paterson and billions of dollars from his co-founder Paul Allen. Gates is an odious creep who made billions through corrupt tech industry practices, then used them to wield influence over the world's politics and policy. The Gates Foundation (and Gates personally) invented vaccine apartheid, helped kill access to AIDS vaccines in Sub-Saharan Africa, then repeated the trick to keep covid vaccines out of reach of the Global South:
The Gates Foundation wants us to think of it as malaria-fighting heroes, but they're also the leaders of the war against public education, and have been key to the replacement of public schools with charter schools, where the poorest kids in America serve as experimental subjects for the failed pet theories of billionaire dilettantes:
The management culture of Microsoft started rotten and never improved. It's a company with corruption and monopoly in its blood, a firm that would always rather build market power to insulate itself from the consequences of making defective products than actually make good products. This is true of every division, from cloud computing:
No one should ever trust Microsoft to do anything that benefits anyone except Microsoft. One of the low points in the otherwise wonderful surge of tech worker labor organizing was when the Communications Workers of America endorsed Microsoft's acquisition of Activision because Microsoft promised not to union-bust Activision employees. They lied:
Why wouldn't they lie? They've never faced any consequences for lying in the past. Remember: the secret to Microsoft's billions is impunity.
Which brings me to Solarwinds. Solarwinds is an enterprise management tool that allows IT managers to see, patch and control the computers they oversee. Foreign spies hacked Solarwinds and accessed a variety of US federal agencies, including National Nuclear Security Administration (who oversee nuclear weapons stockpiles), the NIH, and the Treasury Department.
When the Solarwinds story broke, Microsoft strenuously denied that the Solarwinds hack relied on exploiting defects in Microsoft software. They said this to everyone: the press, the Pentagon, and Congress.
This was a lie. As Renee Dudley and Doris Burke reported for Propublica, the Solarwinds attack relied on defects in the SAML authentication system that Microsoft's own senior security staff had identified and repeatedly warned management about. Microsoft's leadership ignored these warnings, buried the research, prohibited anyone from warning Microsoft customers, and sidelined Andrew Harris, the researcher who discovered the defect:
The single most consequential cyberattack on the US government was only possible because Microsoft decided not to fix a profound and dangerous bug in its code, and declined to warn anyone who relied on this defective software.
Yesterday, Microsoft president Brad Smith testified about this to Congress, and promised that the company would henceforth prioritize security over gimmicks like AI:
Despite all the reasons to mistrust this promise, the company is hoping Congress will believe it. More importantly, it's hoping that the Pentagon will believe it, because the Pentagon is about to award billions in free no-bid military contract profits to Microsoft:
You know what? I bet they'll sell this lie. It won't be the first time they've convinced Serious People in charge of billions of dollars and/or lives to ignore that all-important maxim, "When someone tells you who they are and you get fooled again, shame on you."
If you'd like an essay-formatted version of this post to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:
Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
✓ Live Streaming✓ Interactive Chat✓ Private Shows✓ HD Quality✓ Free Actions
Free to watch • No registration required • HD streaming
There has been a definite shift in what I report upon since starting this series in September. Some of that is due to my own experience level in doing the research; I have a better grasp on the ebb and flow of digital patterns now. When I started this job, I figured I would be reporting on the different types and families of malware more often, giving out warnings for what’s out there lurking in the dark corners of the internet for the unwary. But that’s not really what I do at all. Mostly, I report on vulnerabilities, and the exploitation thereof. And boy are there a lot of them these days.
Patch Tuesday has become a marker in my schedule for expecting to hear news that ranges from the ridiculous (how are we still seeing elevated privilege oversights?) to the terrifying (patching remote access in kernel spaces) to the exasperating (DNS outages that were repaired by reverting to a previous version). Microsoft products have become so pervasive and widely used that practically every corporation, small business, educational facility, hospital, airline, and personal computer is subject to this day. Indeed, my own computer restarted itself after updating this morning. What was once a time to prepare for rebooting all the systems in a network has turned into a ‘what will go wrong now?’ scenario. And there are so many little things being updated, upgraded or fixed that it’s nearly impossible to keep up with them all, especially in a short form report like mine. What takes priority? Which one do I think I’ll be seeing later this week as having been exploited?
Two years ago – when Patch Tuesday unofficially turned 20 years old – CrowdStrike published an article on the changes and exponential growth leading to the need for this day. The article included a graph of the number of vulnerabilities patched by year, dating back to 1999. That graph is a steady upward curve, peaking in 2020 with roughly 1300 patches and fixes. And while the following years were considerably lower than that, never once has the need for patching dropped back to levels predating 2013, the tech boom year that Microsoft released both Windows 8.1 and the Xbox One, along with many other tech companies releasing new versions of products, or entirely new ones. In the subsequent years since the article was written, not much has changed save one aspect.
The move to more remote work has increased both the demand for secure software able to deliver the tools necessary for it and the vectors by which it can be attacked. If the internet is a highway, then vulnerabilities are the cracks and potholes. Anyone who’s ever driven down an interstate can tell you that the work to repair the road surface is never ending. The running joke where I live is that there are two seasons: winter and construction. And the more traffic there is, the faster that surface degrades from constant use. The analogy isn’t quite 1:1 in digital space, but it’s comparable. Greater web traffic means that the vulnerabilities that exist are more likely to become problematic simply because of the sheer volume and variations of use. Keeping up with that is Sisyphean in scope, a repetitive task carried on infinitely.
But the real issue is versions of products and software being released with those vulnerabilities unaccounted for in the first place. CrowdStrike’s article talked about how the onus has been put on the consumer to be aware of risks rather than on the vendor to release a product without flaws. Some of this is a volume issue again, this time stemming from the wide variety of technology, software, applications, cloud offerings and more that is the hallmark of industry growth and innovation. Microsoft as an entity is inescapable, even in other operating systems. Those ‘risks’ are deemed acceptable because there isn’t really an alternative. (There’s a term for that...)
Today is ‘Exploit Wednesday’, the informal designation for what follows all the patches publicly released the previous day. The rest of my week will be waiting to see what happens, hence the somewhat less technical nature of today’s report. Yesterday’s patches included 3 zero-day fixes and 57 flaws, which is down from November and October. A good way to end the year, one might say.
Yesterday was patch day, and so today I will be doing my monthly coverage of it. The first thing I noticed this morning was that my own computer did not restart until nearly 2 am, but upon checking my news feed I see why. This was a large set of patches. A record-breaking 507 flaws, according to Bleeping Computer’s breakdown.
Included in this month’s patching are 254 Elevation of Privilege Vulnerabilities, 17 Security Feature Bypass Vulnerabilities, 145 Remote Code Execution Vulnerabilities, 102 Information Disclosure Vulnerabilities, 35 Denial of Service Vulnerabilities, and 16 Spoofing Vulnerabilities. 59 of these are considered critical, 48 of which are remote code execution, 9 are elevation of privilege, 1 is a security bypass, and 1 is a spoofing. This amount of flaws reflects only what Microsoft has patched as part of the monthly update, but there have been numerous other fixes released out of band this month. Additionally, a massive 468 Microsoft Edge/Chromium flaws were fixed by Google earlier this month, as well as 360 flaws that were discovered and later ported to Microsoft Edge after June’s Patch Tuesday.
If this amount seems particularly high, there’s a reason for it. Last week Microsoft announced that this month’s patches would be larger, as they’ve started using an AI-powered security scanning tool called multi-model agentic scanning harness (MDASH). It uses a twofold process, scanning critical Windows binaries for vulnerabilities and then validating the findings using multiple AI models. Vulnerability candidates are then passed through a second Windows-specific validation pipeline designed to eliminate false positives before engineers investigate the issues. This tool is also helping Microsoft engineers understand update failures, as those have been happening with more regularity, as well as suggesting possible bug fixes, and identifying similar bugs elsewhere in the Windows source code with human oversight still being the final arbiter for review and judgment.
As is typical, Patch Tuesday isn’t solely a Microsoft routine. Other enterprises have also fixed a slew of issues, with specifics linked to their own announcements in the article.
Adobe recently patched seven max-severity ColdFusion and Campaign flaws, including the ColdFusion flaw CVE-2026-48282, which was later exploited in attacks.
BeyondTrust released security updates for two critical authentication bypass flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software.
Cisco released security updates for numerous products, including Cisco Identity Services Engine, Catalyst Center, and ClamAV. Cisco also confirmed that CVE-2026-20230, fixed in June, was actively exploited in attacks.
Fortinet released security updates for numerous flaws in FortiOS, FortiSandbox, FortiPam, FortiSandbox, FortiSASE, and FortiProxy.
Gitea released a security update for a critical auth bypass in the Gitea Docker image.
Ivanti released security updates for two vulnerabilities in Ivanti Xtraction.
Linux kernel maintainers released a patch for the Januscape vulnerability, a flaw that allows attackers to escape a virtual machine and execute arbitrary code on the host.
NVIDIA released security updates for NVIDIA Triton Inference Server and NVIDIA TensorRT-LLM.
Progress Software released security updates for a high-severity path traversal zero-day vulnerability that led to the emergency shutdown of ShareFile Storage Zone Controllers last week.
Ubiquiti released security updates for vulnerabilities in UniFi OS, including a maximum-severity flaw that can be exploited in command injection attacks.
U-Boot maintainers introduced patches to fix new flaws that could enable stealthy firmware attacks.
SAP released the July security updates, which include fixes for four critical flaws in NetWeaver, Commerce Cloud, and AppRouter.
VMware released security updates for VMware Avi Load Balancer, which include authentication bypasses and remote code execution flaws.
Zimbra released security updates for a critical XSS vulnerability affecting the Classic Web Client in the Zimbra Collaboration suite.
Bleeping Computer has compiled a list of each flaw and vulnerability patched this month, as always. It is extensive and long, as a warning to anyone wishing to read it for themselves. Should any of these experience the failure to update that’s been recurrent of late, or other issues pop up (this being informally designated Exploit Wednesday), I’ll be sure to let you know.
Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
✓ Live Streaming✓ Interactive Chat✓ Private Shows✓ HD Quality✓ Free Actions
Free to watch • No registration required • HD streaming
PlayStation Goes Call Of Duty Crazy
This week on the show, we get into the new MacOS Beta. Will Apple have a touchscreen Mac?...
https://thetechnologygeek.org/playstation-goes-call-of-duty-crazy/
It’s becoming something of a habit. Patch Tuesday rolls around, installing updates and fixes for various vulnerabilities and zero days, and then there’s the follow up patch to fix what went wrong with the update. This month’s is no different. Alongside the 206 vulnerabilities and 3 publicly disclosed zero days is a warning that certain builds will fail to update. Again. Bleeping Computer and Qualys have both published breakdowns of this month’s patches, with Bleeping Computer also publishing an article on the failure to update in certain machines.
The patches themselves cover a range of issues, including 65 Elevation of Privilege Vulnerabilities,19 Security Feature Bypass Vulnerabilities, 55 Remote Code Execution Vulnerabilities, 30 Information Disclosure Vulnerabilities, 7 Denial of Service Vulnerabilities, and 27 Spoofing Vulnerabilities. 33 of these are ‘Critical’ vulnerabilities, 28 of which are remote code execution, 4 are elevation of privilege, and 1 is an information disclosure flaw. Earlier this month, Google also released a massive patch covering 360 Microsoft Edge/Chromium flaws that are not counted in the Patch Tuesday update, but are still noteworthy.
As for the failure to update, the specific builds affected by it are a small percentage of devices running Windows 10, versions 22H2 and 21H2, or Windows 11, version 23H2, that were then upgraded to Windows 11, version 24H2 or 25H2, according to Microsoft. Impacted systems will see 0x80073712 or 0x800f0993 errors while checking the update logs. There is a fix being rolled out, and should require nothing more from the user than a system restart. However, systems that were upgraded to Windows 11 version 24H2 or 25H2 (presumably from Windows 10) will need to do a little bit of extra work, as the affected code preventing successful updating will need to be removed. Further instructions are included in the link.
This is far from the first instance of installation failure with Windows updates. I’ve covered several of them over the past 10 months. The 0x80073712 error is responsible for those in April and May, which ended up requiring out of band patches. The build of my home system is one that falls under the category of upgraded from Windows 10 to Windows 11, now running version H25. But aside from April’s necessary patch, I haven’t experienced any issues myself.
Microsoft isn’t the only company that releases patches during the second week of the month. Adobe released security updates for Experience Manager, InDesign, InCopy, Substance 3D Sampler, Dreamweaver, Reader, ColdFusion, and more. Check Point released security updates for a Remote Access VPN and Mobile Access flaw that was exploited in Qilin ransomware attacks. Cisco released security updates for numerous products, including a Unified CM flaw with a PoC exploit and an SD-WAN zero-day exploited in attacks. Fortinet released security updates for numerous flaws in FortiOS, FortiSandbox, and FortiProxy. Google released Android's June security bulletin, fixing 124 flaws and one actively exploited vulnerability. The company also fixed a new Google Chrome zero-day that was exploited in attacks. Ivanti released security updates for vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) and Ivanti Sentry, with none exploited in the wild. Ubiquiti released security updates for three vulnerabilities with maximum severity ratings that could lead to remote code execution. SAP released the June security updates, which include fixes for four critical flaws. Veeam released security updates for a critical Backup & Replication security flaw that can be exploited to gain remote code execution (RCE) on domain-joined backup servers. And Acer released a warning regarding two maximum-severity unpatched flaws in Acer Wave 7 Routers that could be used to hijack routers.
To close on good news, among the fixes for June is a patch for the HTTP/2 flaw. This led to denial-of-service attacks earlier this month, dubbed the HTTP/2 Bomb, which I covered here. Microsoft has introduced a new ‘MaxHeadersCount’ registry setting to limit the number of headers in a request, along with a support bulletin on how to use it to prevent further abuse of the vulnerability.
Microsoft's June Patch Tuesday update was one of its largest ever, addressing 206 security vulnerabilities across Windows, Office, Azure, and other products. Security researchers say the growing number of fixes reflects both the increasing complexity of modern software and the expanding attack surface that companies need to defend.
Some experts are also pointing to AI as a contributing factor. As developers use AI tools to generate and accelerate code, software is being produced faster than ever, which can make it harder to catch bugs and security flaws before release. More code doesn't automatically mean less secure code, but it does create more opportunities for vulnerabilities to appear.
The update included fixes for several high-severity issues, continuing a trend of steadily rising vulnerability counts in major software platforms. For security teams, the challenge is not just applying patches but keeping up with the volume of new disclosures arriving each month.
Comment:
There's something a little ironic about AI helping developers move faster while also potentially giving security teams more things to patch. Productivity gains are great, but nobody gets excited about the extra maintenance that comes with them.