Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

WARNING: A New Zero-Day Threat is On the Loose

WARNING: A New Zero-Day Threat is On the Loose

Zero-day threats are some of the most dangerous ones out there. What we mean by “zero day” threats are those that have been discovered by hackers before an official patch has been released by the developers, giving them exactly zero days before they are actively exploited in the wild. One of the more dangerous zero-day threats out there at the moment is one that takes advantage of Internet Explorer.

Before we start making Internet Explorer jokes, we want to mention that there is nothing funny about online threats--particularly those that haven’t been addressed yet by the developers. This newly discovered zero-day threat is called the “Double Kill” Internet Explorer vulnerability. Unfortunately, the Chinese developers who discovered this vulnerability--a computer security company called Qihoo--have been quiet about the details regarding the double-kill IE bug. It’s also difficult to tell if your organization is under threat, as they aren’t revealing any of the warning signs of such an attack.

The only thing known for sure about this threat is that it takes root by using Word documents. It’s likely that this is done through email attachments as well, as email is a major method of transporting threats of all kinds. When the document is opened up, Internet Explorer is opened in the background via some kind of shellcode that downloads an executable file. The vulnerability does all this without showing anything of note to the user, making it a difficult threat to identify, but the effects are well-known. Apparently, the downloaded executable file installs a Trojan horse malware on the user’s device which creates a backdoor into the system.

There are a lot more unknowns than anything else with this vulnerability, though. In particular, professionals aren’t sure if all Word documents are affected by this vulnerability, or if the threat even needs Microsoft Office in order to function as intended. It’s not even known what role Internet Explorer plays in the attack, or if the documents that can trigger this attack are identifiable. All we can tell you is that you need to keep security best practices in mind to keep these kinds of zero-day threats from becoming a problem for your organization.

To start, you should never download an unexpected file from an unexpected sender. This can come in the form of a resume, receipt, or other online document. You can never know for sure what you’re actually downloading, as criminals have been able to spoof email addresses to a dangerous degree in recent years. Just be cautious about everything you can, and augment caution with powerful security tools that can identify potential risks before they become major problems.

To get started with network security, reach out to Voyage Technology at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Tuesday, 01 April 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security User Tips Hardware Internet Efficiency IT Support Malware Privacy Google Email Phishing Workplace Tips Computer Collaboration IT Services Hosted Solutions Users Mobile Device Ransomware Quick Tips Small Business Cybersecurity Workplace Strategy Microsoft Communication Data Backup Passwords Smartphone Backup Saving Money VoIP Business Management Smartphones Android Upgrade Mobile Devices communications Disaster Recovery Data Recovery Browser Managed Service Social Media Managed IT Services Microsoft Office Windows Tech Term Network Remote Internet of Things Facebook Current Events Productivity Automation Artificial Intelligence Cloud Computing Covid-19 Miscellaneous Gadgets Remote Work Server Managed Service Provider Outsourced IT Information Holiday Encryption AI Spam Employee/Employer Relationship Windows 10 Business Continuity Data Management Compliance Government Training Office Bandwidth Windows 10 Virtualization Blockchain Wi-Fi Business Technology Data Security Apps Two-factor Authentication Mobile Office Managed Services Mobile Device Management Budget Voice over Internet Protocol Gmail Apple Networking App Employer-Employee Relationship Vendor Chrome Conferencing How To WiFi BDR BYOD Computing Applications Information Technology Hacker Access Control Avoiding Downtime Office 365 Tip of the week Marketing Retail Storage Password Healthcare Bring Your Own Device Managed IT Services Big Data Operating System HIPAA Router Virtual Private Network Risk Management Computers Health Help Desk Analytics Website Office Tips IT Support Augmented Reality Remote Workers Firewall Telephone Scam Data loss The Internet of Things Cooperation Free Resource Project Management Windows 7 Going Green Patch Management Social Save Money Microsoft 365 Remote Monitoring Vulnerability End of Support Vendor Management Solutions Cybercrime Customer Service Display Printer Windows 11 Paperless Office Infrastructure 2FA Monitoring Excel Document Management Managed IT Service Maintenance Antivirus Downloads Sports Mouse iPhone Licensing Safety Entertainment Vulnerabilities Administration Data Privacy Images 101 Multi-Factor Authentication Mobility Robot Telephone System Cost Management Settings Printing Wireless Content Filtering IT Management Customer Relationship Management Employees VPN YouTube Meetings Physical Security Integration Cryptocurrency User Tip Modem Hacking Presentation Computer Repair Processor Mobile Security Holidays Virtual Desktop LiFi Wireless Technology Data storage Data Storage Smart Technology Supply Chain Video Conferencing Outlook Managed Services Provider Machine Learning Saving Time Virtual Machines Money Professional Services Word Humor Identity Hacks Server Management Evernote Paperless Scary Stories Private Cloud Regulations Compliance Fun Bookmark Smart Tech Memes Superfish Co-managed IT Identity Theft Refrigeration Deep Learning Public Speaking Twitter Download Net Neutrality Alerts SQL Server Technology Care History Business Communications Lithium-ion battery Error Financial Data Social Engineering Browsers Smartwatch Entrepreneur Connectivity IT Break Fix Scams Education Remote Computing Upload Procurement Azure Hybrid Work Cyber security Mobile Computing Multi-Factor Security Tech Human Resources Social Network Telework Search CES IoT Communitications Dark Web Cables Tablet Undo Best Practice Alert Trends Supply Chain Management Regulations Managed IT Google Calendar Term Google Apps Buisness File Sharing Dark Data Customer Resource management FinTech How To Data Analysis Star Wars IT Assessment Legal Microsoft Excel IT Maintenance IT solutions Business Growth Notifications Gamification Flexibility Staff Value Business Intelligence Social Networking Legislation Shortcuts Travel Application Organization Cortana Fileless Malware Digital Security Cameras Smart Devices Techology Ransmoware Google Maps Alt Codes IBM Content Remote Working Wearable Technology Memory Vendors Motherboard Data Breach Comparison Google Play Be Proactive Downtime Unified Threat Management Health IT Directions Videos Assessment Electronic Health Records Unified Threat Management Permissions Workforce Hosted Solution Typing Wasting Time Threats Trend Micro Specifications Security Cameras Workplace Strategies Network Congestion Competition Knowledge Microchip Internet Exlporer Software as a Service Google Drive User Error Fraud Meta Managing Costs Amazon Username eCommerce Black Friday SSID Point of Sale 5G Unified Communications Experience Database Surveillance Google Docs Virtual Assistant Outsource IT IT Technicians Virtual Machine Environment Bitcoin Network Management Media Running Cable Tech Support User Monitors Proxy Server Reviews Cookies Google Wallet Cyber Monday Medical IT Tactics Development Hotspot Transportation Small Businesses Mirgation Hypervisor Displays Windows 8 IP Address Laptop Websites Shopping Nanotechnology Optimization Drones PowerPoint Electronic Medical Records Addiction SharePoint Language Employer/Employee Relationships Outsourcing Chatbots Navigation Halloween Recovery Management PCI DSS Writing Gig Economy Screen Reader Lenovo Distributed Denial of Service Workplace Hard Drives Domains Virtual Reality Service Level Agreement Internet Service Provider Computing Infrastructure Teamwork Hiring/Firing

Blog Archive