Malware targeting Windows 8

Microsoft has been putting a lot of effort into making their software more secure, and it’s paying off: Kaspersky’s IT Threat Evolution: Q3 2012 report includes no Microsoft software in its Top Ten Vulnerabilities List.

The anti-malware software bundled with Windows 8 is Microsoft’s strongest offering in any version to date. But as long as Windows is widely deployed, it will remain a popular target for malware developers, as is demonstrated by the recent discovery by Symantec that a new Trojan variant, detected as Backdoor.Makadocs, includes code specific to the new O/S.

Windows 8 sales well below Microsoft’s expectations

Apparently Microsoft was expecting Windows 8 sales to be much higher than they have been to date. No doubt this is at least partly because of doubts related to the new user interface, and partly due to general satisfaction with Windows 7, acknowledged to be the basis for Windows 8.

Update: Ars Technica looks at the available numbers and says it’s too soon to declare Windows 8 a disaster.

Update 2: The Verge reports that Microsoft is claiming they have sold 40 million Windows 8 upgrades in its first month.

Internet Explorer 10 for Windows 7

At one point it looked like Microsoft might not produce a version of Internet Explorer 10 that would run on any version of Windows earlier than Windows 8. Thankfully, for those of you still using Microsoft’s web browser, a Windows 7 compatible version of IE10 is now available. Please note that this version is categorized as a ‘Release Preview’, so it is probably somewhat buggy.

You can find more information regarding this development at Ars Technica and The Verge.

Bringing Google tools to Windows 8

Anyone accustomed to using Google’s Chrome browser, seeing Google search in their browser and having other Google tools handy in previous versions of Windows will notice their absence in Windows 8. Google noticed as well, and has instructions for bringing Chrome and Google search tools to the new O/S.

Google’s aptly-titled Get Your Google Back page provides users with a simple wizard-based process for returning the missing features.

Patch Tuesday for November 2012

Another month, another Patch Tuesday. As discussed in the advance warning post, this month’s crop consists of six patches with nineteen fixes for Windows (including Windows 8), Office, Internet Explorer and .NET:

Windows users are encouraged to install the critical updates as soon as possible via Microsoft Update.

More details at the Microsoft Security Response Center.

DirectX 11 only for Windows 8

Microsoft has traditionally been pro-consumer in terms of backward compatibility. They expended a lot of resources to make sure that new versions of Windows would be compatible with older hardware, for instance.

A rare exception to this was Microsoft’s failure to make DirectX 10 compatible with Windows XP. Given the huge number of Windows XP systems still out there when DirectX 10 was introduced in 2006 (and even now), this move almost certainly hurt everyone involved, including Microsoft, game developers and consumers. As a Windows XP gamer, I occasionally encounter games that require DirectX 10, at which point I put the box back on the shelf.

Despite claims to the contrary, it’s clear that a big part of Microsoft’s DirectX 10 decision was that they wanted people to upgrade to Windows Vista. I’m sure a few gamers upgraded Windows because of this, but to the vast majority it was just another stupid roadblock and a reason to be angry at Microsoft.

Game developers were left with a difficult decision. They could continue developing for DirectX 9, but in doing so they would not be able to use the new features of DirectX 10. They could develop two versions of their games, one requiring DirectX 10 and the other, compatible with DirectX 9, but this would add a lot of work and complexity to the process. Or they could stop developing for DirectX 9, but this would eliminate a huge potential market: Windows XP gamers. None of these choices are ideal. For the most part, DirectX 10-only game titles are still relatively rare.

Unfortunately, Microsoft has made a similar decision for DirectX 11: it will only be available on Windows 8. Once again, this decision is likely to do more damage than anything else.

Advance warning for November 2012 Patch Tuesday

It’s that time of the month again. Microsoft has issued its advance warning for this month’s Patch Tuesday. The patches themselves will become available, as usual, on the second Tuesday of the month. That’s November 13, 2012, at approximately 10 a.m. PST.

The patches this month affect Windows, Internet Explorer, Office and the .NET Framework. There are six planned bulletins, with 19 total issues being addressed. Four of the bulletins are rated Critical. For all the details, see the related Technet security bulletin.

As always, Windows users should install these patches as soon as possible on or after November 13.

‘Ransomware’ prevalence increasing in North America

A new white paper from Symantec discusses the increase of ‘ransomware’ in North America. Ransomware is malware that – once installed on a user’s computer – prevents normal operation and presents the user with warnings that appear to be from regional law enforcement organizations. The warnings threaten further legal action if the user fails to pay a fine. The warnings look sufficiently legitimate to fool many users, who then pay the ‘fine’.

If you start seeing one of these warnings on your computer, do not pay the ‘fine’. Instead, have the malware removed from your computer by a knowledgeable technician.

More details from ARS Technica.

‘Impervious’ Adobe Reader X/XI is actually vulnerable

A working exploit for the latest versions of Adobe’s PDF Reader software (X and XI) is being made available to malicious hackers for $50,000 via underground forums.

Starting with Version X, Adobe’s Reader software has employed a ‘sandbox’ that supposedly insulates the operating system from attacks originating in Reader content. The exploit code reportedly gets around the sandbox.

Adobe is investigating, but no patches are available yet. Since this threat is active, anyone using Adobe Reader X or XI should exercise extreme caution when opening PDF documents or clicking links to PDF documents from unknown sources. Another option is to uninstall the Adobe software and use an alternative like Foxit Reader.

More details from KrebsOnSecurity.

Vulnerabilities in Sophos anti-malware products

Security researcher Tavis Ormandy has discovered several security vulnerabilities in Sophos security products. The holes were patched within a few weeks of the initial reports, but Ormandy maintains that Sophos’ response was too slow. The vulnerabilities, if unpatched, can allow attackers to gain full control of computers running affected Sophos software.

Regardless of whether you agree with Ormandy’s conclusions about Sophos, it’s clear that if you run Sophos security products, you should make sure they are fully patched.

Rants and musings on topics of interest. Sometimes about Windows, Linux, security and cool software.