/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Time for Microsoft to Change Its Patch Policy?

A very interesting post on the Google Online Security Blog analyzes which web servers are responsible for the world's malware.  —  Microsoft IIS 6 tied with Apache at 49% for compromised servers, even though Apache has a 40% lead in deployments.

Windows-Now.com Robert McLaws

Context & Ripple Effects

This follows Google's Online Security Blog analysis from June 5, 2007, which normalized malware infections against install base and found Microsoft IIS 6 tied with Apache at 49% of compromised servers — on an Apache lead of roughly 40 points in deployments that makes IIS 6 disproportionately hit. Ars Technica picked the finding up the next day, and Windows-Now uses it to ask whether Microsoft's patch policy itself is the problem.

The framing matters because it shifts the argument from 'which server is hacked more' (raw counts favor whichever has more installs) to 'which is hacked more per install' — a metric that puts Microsoft's patch release cadence and admin uptake under direct scrutiny rather than just market share.

First-order effects

  • Microsoft faces renewed pressure to defend its Patch Tuesday cadence for IIS, since Google's data implies unpatched IIS 6 installs are being compromised at a far higher rate than their share of the web justifies.
  • Administrators running IIS 6 now have a widely cited, per-install normalized statistic showing their servers carry outsized compromise risk, changing the calculus for leaving patches deferred.

Second-order effects

  • Hosting providers and enterprise buyers choosing between IIS and Apache gain a data-backed risk differential to price into decisions, forcing Microsoft to compete on security posture rather than familiarity.
  • Security bloggers and researchers are handed a reusable methodology — compromise rate per deployment — that can be turned on any vendor's product line, raising the cost of slow patch pipelines across the industry.

Third-order effects

  • If per-install compromise rates become the standard yardstick, vendor security comparisons move from anecdote to measurable ratios, making patch policy a competitive differentiator rather than an IT backwater.
  • Sustained gaps in patched-vs-unpatched exploitation push the industry toward faster, more automatic update mechanisms for server software, since manual admin patching demonstrably lags attacker activity.

The trend: Web-server security assessment is shifting from raw malware counts to per-deployment compromise rates, turning vendors' patch release policies into a public, comparable metric.