/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Google: IIS twice as likely to serve malware as Apache

A new study by Google's Anti-Malware Team seems to confirm what many people have believed for years: Web sites running Microsoft's IIS are twice as likely to host malware than those running Apache.  —  Last month, Google studied about 70,000 malware-distributing domains.

Ars Technica Nate Anderson

Context & Ripple Effects

This lands one day after Google's own Online Security Blog breakdown of which web servers are behind the world's malware, based on a scan of roughly 70,000 malware-distributing domains. The headline finding — IIS sites twice as likely to host malware as Apache sites — is sharpened by a subtler number underneath it: compromised servers split evenly between IIS 6 and Apache at 49% each, despite Apache leading IIS 6 by some 40 points in deployments.

The study also feeds an argument already running the same week: Windows-Now.com's call for Microsoft to change its patch policy treats IIS's security record as evidence that Microsoft's update cadence, not just its code, is part of the problem.

First-order effects

  • Microsoft faces renewed pressure on its patching and hardening practices for IIS, with administrators of IIS-hosted sites now carrying data-backed questions about their platform choice.
  • Apache operators get a concrete security talking point against IIS in enterprise and hosting procurement debates, backed by Google-scale data rather than anecdote.

Second-order effects

  • Hosting providers and IT buyers weighing server stacks can now price security reputation into platform selection, shifting competitive weight toward Apache in shared-hosting environments where compromise rates matter most.
  • Google's Anti-Malware Team emerges as a de facto arbiter of web-security statistics, meaning future Microsoft or Apache claims about malware will be measured against Google's crawl-derived numbers.

Third-order effects

  • If large search operators keep publishing malware telemetry, server-market share battles will increasingly be fought over per-deployment compromise rates rather than raw install counts — a metric where market leaders look worse.
  • Security-by-statistics from platforms with crawler visibility points toward search companies becoming structural players in web hygiene, with their findings shaping vendor credibility across the industry.

The trend: Web-server competition is shifting from feature and performance comparisons toward measurable security outcomes, with search-engine telemetry becoming the yardstick both Microsoft and the Apache community get judged by.