Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

WARNING: A New Zero-Day Threat is On the Loose

WARNING: A New Zero-Day Threat is On the Loose

Zero-day threats are some of the most dangerous ones out there. What we mean by “zero day” threats are those that have been discovered by hackers before an official patch has been released by the developers, giving them exactly zero days before they are actively exploited in the wild. One of the more dangerous zero-day threats out there at the moment is one that takes advantage of Internet Explorer.

Before we start making Internet Explorer jokes, we want to mention that there is nothing funny about online threats--particularly those that haven’t been addressed yet by the developers. This newly discovered zero-day threat is called the “Double Kill” Internet Explorer vulnerability. Unfortunately, the Chinese developers who discovered this vulnerability--a computer security company called Qihoo--have been quiet about the details regarding the double-kill IE bug. It’s also difficult to tell if your organization is under threat, as they aren’t revealing any of the warning signs of such an attack.

The only thing known for sure about this threat is that it takes root by using Word documents. It’s likely that this is done through email attachments as well, as email is a major method of transporting threats of all kinds. When the document is opened up, Internet Explorer is opened in the background via some kind of shellcode that downloads an executable file. The vulnerability does all this without showing anything of note to the user, making it a difficult threat to identify, but the effects are well-known. Apparently, the downloaded executable file installs a Trojan horse malware on the user’s device which creates a backdoor into the system.

There are a lot more unknowns than anything else with this vulnerability, though. In particular, professionals aren’t sure if all Word documents are affected by this vulnerability, or if the threat even needs Microsoft Office in order to function as intended. It’s not even known what role Internet Explorer plays in the attack, or if the documents that can trigger this attack are identifiable. All we can tell you is that you need to keep security best practices in mind to keep these kinds of zero-day threats from becoming a problem for your organization.

To start, you should never download an unexpected file from an unexpected sender. This can come in the form of a resume, receipt, or other online document. You can never know for sure what you’re actually downloading, as criminals have been able to spoof email addresses to a dangerous degree in recent years. Just be cautious about everything you can, and augment caution with powerful security tools that can identify potential risks before they become major problems.

To get started with network security, reach out to Voyage Technology at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Saturday, 21 December 2024

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security Hardware Internet IT Support Efficiency User Tips Malware Privacy Email Phishing Google Workplace Tips Computer Collaboration IT Services Users Hosted Solutions Mobile Device Ransomware Quick Tips Cybersecurity Small Business Microsoft Workplace Strategy Data Backup Communication Smartphone Saving Money Business Management VoIP Smartphones Android Mobile Devices communications Backup Data Recovery Passwords Managed IT Services Managed Service Upgrade Browser Social Media Microsoft Office Disaster Recovery Tech Term Network Internet of Things Remote Artificial Intelligence Automation Facebook Cloud Computing Covid-19 Miscellaneous Gadgets Server Remote Work Managed Service Provider Windows Outsourced IT Current Events Productivity Information Encryption Spam Employee/Employer Relationship Windows 10 AI Holiday Data Management Business Continuity Compliance Government Office Business Technology Windows 10 Virtualization Blockchain Wi-Fi Training Bandwidth Apps Data Security Two-factor Authentication Mobile Office Mobile Device Management Chrome Gmail Budget Managed Services Voice over Internet Protocol Apple Networking App Employer-Employee Relationship Vendor Access Control Tip of the week Conferencing WiFi How To BDR Computing Hacker Information Technology BYOD Avoiding Downtime Applications Office 365 Analytics Office Tips Health Augmented Reality Help Desk Storage Password Bring Your Own Device Retail Healthcare Big Data Managed IT Services Operating System Computers Risk Management HIPAA Router Website Virtual Private Network Marketing Paperless Office Windows 11 Infrastructure IT Support Firewall 2FA Monitoring Excel Document Management The Internet of Things Remote Workers Telephone Scam Social Data loss Going Green Cooperation Free Resource Project Management Windows 7 Customer Service Patch Management Save Money Microsoft 365 Cybercrime Remote Monitoring End of Support Vulnerability Vendor Management Solutions Display Printer Outlook Holidays Data Storage Money Humor Smart Technology Supply Chain Video Conferencing Machine Learning Managed Services Provider Saving Time Safety Virtual Machines Professional Services Sports Mouse Managed IT Service Maintenance Administration Downloads Antivirus iPhone Licensing Entertainment Vulnerabilities Data Privacy Customer Relationship Management Images 101 Settings Wireless Printing Multi-Factor Authentication Robot Mobility Content Filtering Telephone System Cost Management Hacking YouTube Presentation Cryptocurrency IT Management Wireless Technology VPN Employees Meetings Physical Security Integration Virtual Desktop User Tip Data storage Modem LiFi Processor Computer Repair Mobile Security Word Proxy Server Reviews Cookies Monitors Cyber Monday Medical IT Tactics Development Refrigeration Hotspot Transportation Small Businesses Halloween Websites Mirgation Hypervisor Displays Public Speaking Shopping Lithium-ion battery Nanotechnology Optimization PowerPoint SharePoint Addiction Hacks Electronic Medical Records Language Employer/Employee Relationships Outsourcing Entrepreneur Scary Stories Chatbots Navigation Fun Management PCI DSS Lenovo Gig Economy Screen Reader Deep Learning Writing Distributed Denial of Service Workplace Service Level Agreement Internet Service Provider Undo Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Private Cloud Identity Education Evernote Paperless Server Management Regulations Compliance Superfish Bookmark Identity Theft Smart Tech Memes Co-managed IT Download Net Neutrality Mobile Computing Twitter Alerts SQL Server Technology Care Error History Business Communications Search Financial Data Browsers Smartwatch Connectivity IT Application Best Practice Social Engineering Break Fix Scams Buisness Upload Procurement Remote Computing Azure Hybrid Work IBM Legal Cyber security IT solutions Multi-Factor Security Tech Human Resources Social Network Telework CES Tablet IoT Communitications Business Growth Dark Web Cables Trends Supply Chain Management Alert File Sharing Regulations Dark Data Google Calendar Term Google Apps Cortana Managed IT Customer Resource management FinTech Data Analysis Star Wars IT Assessment Alt Codes How To Microsoft Excel IT Maintenance Downtime Gamification Flexibility Competition Notifications Staff Value Business Intelligence Travel Social Networking Hosted Solution Legislation Shortcuts Organization Techology Fileless Malware Digital Security Cameras Google Maps Smart Devices Typing Ransmoware Content Remote Working Wearable Technology Memory Vendors Google Drive Unified Threat Management Motherboard Data Breach User Comparison Google Play Be Proactive Knowledge Health IT Unified Threat Management Directions Videos Assessment Electronic Health Records Permissions Workforce 5G Wasting Time Threats IP Address Google Docs Trend Micro Unified Communications Network Congestion Specifications Security Cameras Workplace Strategies Experience User Error Microchip Internet Exlporer Software as a Service Bitcoin Fraud Meta Running Cable Managing Costs Amazon Username Google Wallet Point of Sale eCommerce Recovery Black Friday SSID Database Surveillance Hard Drives Windows 8 Virtual Assistant Outsource IT Laptop Tech Support IT Technicians Virtual Machine Environment Media Network Management Domains Drones

Blog Archive