Why do people continue to run vulnerable, ancient OS software?

Those who are still running unsupported software please have a look at this Vulnerability Summary from CISA. Specifically the areas regarding Microsoft and old versions of Windows 10 and Server. These are the very reasons why corporations and private entities are allowing malware and ransomware to propagate. The sheer volume of different vendors listed each time a new summary comes out is astonishing. It shows one specific thing about the developer world and corporate culture. Serious incompetence.

As a follow on, Windows 7 / 8 users are going to find that Digital Rights services for Silverlight and Windows Media player on those old OS are no longer supported. Although, they will still function.

I have always wondered about this also.

For myself I do as much as I possibly can at home to update operating system, security software and third party programs. I know that much of the time it is just features and not security vulnerabilities that I am upgrading but it gives me piece of mind to know that I have updated.

There is no excuse (lack of personnel ?) for large corporations to run outdated software and expose their clients to security breaches. Should be easier for professionals to update as opposed to home users.

Indeed, great observation. I can personally attest to being in a managerial position where, the unnamed company I worked for. Wasted weeks on end discussing how a simple IT integration would take place. It was top heavy in attendance, the whining was deafening. Companies waste more valuable time over a weekend where these things could be done yet don’t. Meetings to plan the next meeting, and so on. Nothing ever gets done. Just more coffee and doughnuts for the heavy hitters.

SA

Here is another where China gets into an old and unmanaged AIX server for a global engineering company.

This is how old it actually is and the versions that are not and are still supported.

Bottom line!! This company, alike many others, are as arrogant and ignorant as it comes. Nothing more than a national security risk to manufacturing pipelines and further. What comes when something does get triggered? America is beyond ignorant with its lameness toward OPSEC. Period!! Money is the most important thing. And our government is too afraid to bust it off where it hurts most with these companies.

SA

For average users who are not tech savvy, they usually don’t pay attention to this matter. If everything works fine, they will simply ignore it.