Stirpes  

Go Back   Stirpes > Technology > Technology, Computer Science & Robotics > Computers & Internet Security and Privacy

Computers & Internet Security and Privacy Computer machines and components.
News and updates on latest security related advisories, threads, software, open source, etc.

Reply
 
Thread Tools Display Modes
  #1 (permalink)     Quote this post in a PM
Old Tuesday, April 24th, 2007
Erasmus's Avatar
Alien
 
Last Online: 2 Days Ago 15:57
Join Date: Aug 2006
Location: Moisheville
Posts: 1,267
Erasmus is a sage.Erasmus is a sage.Erasmus is a sage.Erasmus is a sage.Erasmus is a sage.Erasmus is a sage.Erasmus is a sage.Erasmus is a sage.
Send a message via ICQ to Erasmus Send a message via MSN to Erasmus Send a message via Yahoo to Erasmus
Exclamation Cyberspies exploit Microsoft Office

Cyberspies exploit Microsoft Office

By Byron Acohido, USA TODAY

SEATTLE — Cyberspies have a new secret weapon: tainted Microsoft Office files.
A rising number of cyberattacks are taking aim at specific individuals at critical government agencies and corporations — enticing them to unwittingly open a corrupted Word, Excel or PowerPoint file sent as an e-mail attachment.
Clicking on the file relinquishes control of the PC without the user's knowledge. The attacker then uses the compromised PC as a base from which to roam the organization's internal network.
Federal agencies and defense and nuclear contractors are under assault. Security firm MessageLabs says it has been intercepting a series of attacks from PCs in Taiwan and China since November.
"The bad guys know which organizations have data worth stealing and are picking them out one by one," says Alex Shipp, senior technologist at MessageLabs.
In early 2006, security experts detected one or two such attacks a week. Last month, MessageLabs intercepted 716 e-mails carrying corrupted Office files aimed at 216 different agencies and companies.
FIND MORE STORIES IN: Microsoft | Security | Microsoft Office | Word | Powerpoint | Alan Paller | Messagelabs
Assaults are coming from China and perhaps other countries in the hunt for military, trade and infrastructure intelligence, says Alan Paller, research director at The SANS Institute, a security think tank. The goal: strategic advantage over the USA. "The attacks are working," says Paller. "Penetrations are deep and broad."
Some attacks could be "on-demand," at the behest of companies that hire cybergangs to pilfer data from rivals, says Righard Zwienenberg, chief researcher at Norman Data Defense Systems.
At a congressional hearing last week on cybersecurity, Donald Reid, a senior State Department official, described how an employee in May clicked on a Word document corrupted via a security hole for which Microsoft had no patch. A fix wasn't available until eight weeks later. Microsoft has issued 10 patches for security holes in Office programs since January 2006, including a handful delivered only after crooks began using newly discovered flaws in their attacks. The best protection: keeping Office security patches updated.
The Office file attacks are "very targeted and very limited," says Mark Miller, Microsoft's director of security response, who called on workers "to absolutely extend extreme caution" when opening Office files in e-mail.
Microsoft has been slow to patch security holes in Office programs, says Zwienenberg. "But the cybercriminals are getting smarter and smarter."



Cyberspies exploit Microsoft Office - USATODAY.com
Reply With Quote
Reply

Bookmarks

Tags
None


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
microsoft unveils revolutionary device Strengthandhonour Technology, Computer Science & Robotics 2 Wednesday, May 30th, 2007 22:58
German Population Plunge “Irreversible,” Federal Stats Office Admits Aptrgangr Ethnopolitics 1 Thursday, November 16th, 2006 21:04
More Microsoft browser vulnerabilities reported Nerthus Computers & Internet Security and Privacy 0 Tuesday, March 28th, 2006 11:12
Gone to Google: Microsoft sues over exec's defection Ebusitanus Economics 0 Wednesday, July 20th, 2005 10:11

Locations of visitors to this page

Stirpes Stats

All times are GMT. The time now is 03:51.

Page generated in 0.2167690 seconds with 15 queries.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0