Microsoft ended support for the Internet Explorer 11 desktop application on 15 June 2022, on most editions of Windows 10, closing out a browser that had shipped with Microsoft Plus! for Windows 95 on 24 August 1995 and held something in the region of 95% of the market in 2002 and 2003. The retirement was announced a year in advance and executed without drama: users who launched the icon were redirected into Microsoft Edge. It was not a recall. The desktop application went out of support, and Edge kept an Internet Explorer mode for the enterprise web that had been built against nothing else. Nearly twenty-seven years of a browser that had won a war and then spent a decade as the thing everyone used once, to download something better.

The response that travelled furthest came from South Korea, and it was not sentimental so much as exhausted. For years, Korean banking portals and government services had been built around ActiveX controls that only Internet Explorer could run, which meant the browser stayed installed long after the rest of the world had moved on, and meant that Korean developers kept testing against it. A software engineer named Jung Ki-young spent 430,000 won — roughly $330 — on a granite headstone carved with the browser's logo and an English epitaph: "He was a good tool to download other browsers." He set it up at his brother's café in Gyeongju. The photograph went round the world within days, which is a strange kind of eulogy for a piece of software.

The security reading of that week is less comic. What went out of support on 15 June was an application, not a codebase. The Trident layout engine that rendered pages in Internet Explorer — the component Windows exposes as MSHTML — continued to ship inside Windows, because Edge's Internet Explorer mode needs it to render the intranet applications that large organisations never rewrote. Microsoft permanently disabled the standalone IE11 desktop application through a Microsoft Edge update on 14 February 2023, eight months after the retirement date. Disabling the front door is not the same as demolishing the house. The engine stayed reachable, and an engine designed in the 1990s remains an engine designed in the 1990s.

Which is how the story ends, and the ending is the point. In July 2024, Check Point researchers described a technique in which attackers built Windows internet shortcut files — ordinary .url files — carrying an mhtml prefix that forced Windows to open the attacker's page in the retired Internet Explorer rather than in Edge or Chrome, then hid an .hta payload behind what looked like a PDF. Check Point said the trick had been in use from January 2023 until May 2024. Microsoft patched it, as CVE-2024-38112, on 9 July 2024. Two years after the headstone, Internet Explorer was still a viable place to send a victim, precisely because it had been retired rather than removed.

Also that month · 5,067 machines

A record without an army

On 14 June Cloudflare published details of an HTTPS flood it had detected and mitigated the previous week, peaking at 26 million requests per second against a customer on its free plan — at the time the largest HTTPS denial-of-service attack on record, against a previous high of 15 million requests per second in April 2022. The interesting figure was the small one. The traffic came from 5,067 devices, each averaging roughly 5,200 requests per second at peak; in under thirty seconds they generated more than 212 million HTTPS requests across over 1,500 networks in 121 countries, with about 3% arriving through Tor. The sources were cloud providers rather than residential broadband — hijacked virtual machines and servers, not cameras and home routers. Cloudflare named the botnet Mantis on 14 July 2022, described it as a descendant of the MikroTik-based Meris, and said it had launched more than 3,000 HTTP attacks in the preceding month. Stolen compute had become cheaper than stolen devices, and considerably more effective.

Also that month · The patch, and who got there first

Follina closed, nine weeks on

The Word document that ran code without macros, covered in last month's edition, was finally patched on 14 June, in a Patch Tuesday of fifty-five fixes — nine weeks to the day after a researcher reported the behaviour and was told it was not a security issue. The interval between the 30 May advisory and the patch was not quiet. Proofpoint reported that TA413, which it assesses acts for the Chinese state, had begun using the flaw against the Tibetan community around 30 May, in campaigns impersonating the Women Empowerments Desk of the Central Tibetan Administration. Days later the same firm described an unattributed but state-aligned operation that sent close to a thousand messages to European government bodies and local US governments, using an RTF disguised as a salary increase. On 10 June Ukraine's CERT-UA warned that more than five hundred addresses at Ukrainian radio stations, newspapers and news agencies had received a document offering links to interactive maps, and attributed the campaign, tracked as UAC-0113, to Sandworm. Microsoft's eventual answer went further than the patch: in January 2023 it listed the Support Diagnostic Tool as deprecated and marked for removal.

India desk · June 2022

The month the VPNs took their servers home

CERT-In's cyber security directions of 28 April 2022 came into force on 27 June, and the clause that emptied a market was not the six-hour reporting rule but the one beneath it. Providers of VPN, cloud, virtual private server and data centre services had to record subscriber names, addresses, contact details and allotted IP addresses, and keep it all for five years after an account closed. For companies whose whole proposition was the absence of such records, there was no compliant configuration. ExpressVPN said on 2 June that it would remove its Indian servers rather than keep logs; Surfshark followed, arguing that concentrating that much identifying data in one jurisdiction would create breach exposure, not reduce it. NordVPN announced on 14 June that its India servers would go on 26 June, the day before the deadline. Proton VPN would follow in September.

On 27 June, the day they took effect, CERT-In moved part of the line: micro, small and medium enterprises were given until 25 September 2022, and data centre, VPS, cloud and VPN providers the same date for the subscriber-validation requirement. The six-hour reporting duty and the 180-day log rule started on schedule. The junior IT minister, Rajeev Chandrasekhar, had already said publicly that providers unwilling to hold and produce logs would have to leave. What the industry did was neither. It moved the hardware out and kept the customers, selling Indian addresses from virtual servers hosted outside the country, so that a subscriber in Delhi still appeared to be there while any records that existed sat beyond Indian reach. Atlas VPN counted 348.7 million VPN app installs in India in the first half of 2021 alone — installs rather than people, but nobody disputed the scale.

AI Tech desk · June 2022

Ten dollars a month for autocomplete

GitHub took Copilot out of technical preview on 21 June 2022 and put a price on it: general availability at $10 a month or $100 a year, free for verified students and maintainers of popular open-source projects. More than 1.2 million developers had used the preview in its first year, and GitHub claimed that in files where the tool was switched on it was already writing nearly 40% of the code in popular languages. Two days later Amazon answered with a free preview of CodeWhisperer, a rival trained partly on its own codebase; the day in between belonged to Google Research, whose Parti paper scaled an autoregressive text-to-image model to twenty billion parameters without releasing it. The month's noisiest AI story — the engineer who declared LaMDA sentient, a claim Google rejected, carried in this edition's capsule — aged worse than the invoice. A ten-dollar subscription for machine-written code, five months before ChatGPT existed, turned out to be the template for how generative AI would be sold.

Digital Guard desk · June 2022

Defender steps outside Windows

Microsoft launched Defender for individuals on 16 June 2022 — an app for Windows, macOS, Android and iOS, offered at no extra charge to Microsoft 365 Personal and Family subscribers. It was less a new engine than a new surface: a dashboard pulling a household's phones and computers into a single view, extending protection beyond the Windows machine the Defender name had always shipped inside, and coexisting with whatever third-party product was already installed. After two decades of giving the baseline away as an operating-system feature, Microsoft had turned it into a reason to keep paying for a subscription — and the consumer vendors were now competing with the operating system itself. The industry gathered the same fortnight: RSA Conference returned to San Francisco's Moscone Center from 6 to 9 June, in person again after its pandemic postponement from February. The incumbents were already consolidating — NortonLifeLock and Avast completed their merger that September, taking the name Gen Digital before the year ended — while Defender accreted identity-theft monitoring and a VPN it would retire in 2025.

⏳ Time capsule — June 2022

  • The United Kingdom marked Queen Elizabeth II's Platinum Jubilee with four days of national celebration from 2 to 5 June, seventy years after her accession.
  • The Washington Post reported on 11 June that Google had placed the engineer Blake Lemoine on leave after he claimed its LaMDA language model was sentient; Google called the claim unfounded and dismissed him in July.
  • The Golden State Warriors beat the Boston Celtics four games to two on 16 June to win the NBA title, with Stephen Curry taking his first Finals MVP award.
  • The United States Supreme Court overturned Roe v. Wade on 24 June in Dobbs v. Jackson Women's Health Organization, returning abortion regulation to the states.
Where it stands today — 2026

Retirement is not removal

Four years on, the June 2022 headline that has aged best is the one that looked like nostalgia. Internet Explorer's desktop application is gone; the Trident engine behind it is still inside Windows, serving an Internet Explorer mode that Microsoft has committed to supporting through at least 2029. The CVE-2024-38112 campaign proved what that costs: attackers spent sixteen months deliberately routing victims into a browser the industry had already held a funeral for. The same shape governs the month's other Microsoft story. Follina's patch on 14 June closed one exploit, but the real remedy was withdrawing the Microsoft Support Diagnostic Tool altogether — a component nobody used on purpose, reachable from a document because that had once been convenient.

The rest resolved more plainly. Cloudflare's 26 million requests per second held its record for barely eight months, giving way to 71 million in February 2023 and to far larger figures during the HTTP/2 Rapid Reset campaign later that year, but the thesis survived: attackers now steal compute, not devices. Forescout's OT:ICEFALL disclosure on 20 June — fifty-six flaws across ten industrial vendors, many of them design decisions rather than mistakes — put insecure by design into a vocabulary regulators spent the next two years borrowing. India's directions never softened. They remain in force in 2026, the consumer VPN industry still serves the country from machines outside it, and the six-hour clock that started that June is the one against which every Indian disclosure in this archive is now measured.