back to article Researcher says Patch Tuesday fix should have been made earlier

Security researcher Kafeine says one of this week's Microsoft patches addresses a vulnerability it knew of since last year, and may only have pulled the patching trigger after a spate of banking trojan attacks. The attacks utilised the low-level flaw (CVE-2016-3351) for cloaking purposes among an arsenal of exploits. The …

  1. Robert Helpmann??
    Childcatcher

    Which way to jump?

    It has been a while since I was told this, so perhaps things have changed. My understanding is that Microsoft rates the severity of flaws and creates patches for them based on their risk and not the risk to their customers. Such an approach might be used to explain behavior of this sort given that any patch has risk associated with it and this particular flaw wasn't causing that much trouble in the wild, at least not to MS directly.

    1. a_yank_lurker

      Re: Which way to jump?

      Slurp has been engaging in security theater for a long time. They have gotten into shouting matches with Google over not bother to fix Winbloat bugs before because Slurp wanted to do it at their convenience not when users needed it done.

  2. paulf
    Pirate

    Ad networks

    FTA: "The bank trojans were being dropped until Kafeine and fellow researchers reported the attacks to advertising networks whose infrastructure was being abused."

    So the Ad networks were quite happily dishing out copies of the trojan software all over the place until they were notified by security researchers. Even a small amount of cursory scanning of files distributed over their Ad networks would have detected the booby trapped files. Oh, wait, that would have cost money. At the risk of generalising, I imagine that people who don't run Ad blockers are probably those least able to rectify all the problems introduced by such trojans.

    And these Ad networks still don't get why we use ad blockers?!

    1. Aitor 1

      Re: Ad networks

      Security is why I use adblockers.

      The ad networks are just stupid. They should have never allowed obnoxious ads and malware.

  3. Anonymous Coward
    Anonymous Coward

    Install Linux Mint and Adblock your Web browser

    Simple, safe and idiot proof. No learning curve to replace Windows.

  4. DerekCurrie
    Holmes

    The only sane updating system is ASAP updating

    Pandering to lazy IT personnel by supplying once-a-month security updates is NOT sane. End it. Tough if the lazy IT personnel don't like it. THEY can decide to let the updates pile up until the second Tuesday of the month, if they so choose/dare. Meanwhile, those of us who live in the real world require ASAP. It minimizes the infection period AND it keeps the malware rats on their toes as well. ASAP is the ideal.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like