Two Unofficial IE Patches Block Attacks
Pentrex writes "eWeek reports that two well-respected Internet security companies (eEye and Determina) have released unofficial patches to correct the vulnerability being exploited to load spyware, bots and Trojan downloaders on Windows machines. Microsoft isn't sanctioning the third-party patches, which include source code for review. As always, the advice is to weigh the risks before opting for an unofficial hotfix."
If by "lazy" you mean "they need to test every single change made to their software extensively, and don't have the luxury of being able to throw out third-party hacks with no long-term support requirements", then sure they're being lazy. You'll notice that they're fixing both these issues with their monthly updates on April 11th(I think?) if you look around.
But porting office to macos doesn't hurt their FUD about how anything that touches opensource is somehow corrupted by it.
Plus, I think they want to be seen as the only OS for commodity hardware. Eg, you *could* buy from apple, but you'll be paying twice as much for the hardware than it's worth, and it's an artist's workstation... not for "real work" (note to apple fanbois: I don't actually believe this, my problem with apple is the same problem i have with MS and it has nothing to do with quality)
Firefox is worse than IE. It's just safer. If it wasn't safer I would not even have it installed. Sad but true.