Attackers use Microsoft security hole against energy, defense, - TopicsExpress



          

Attackers use Microsoft security hole against energy, defense, finance companies targets By the time Microsoft warned customers of a nasty security hole in its web browser, a sophisticated group of attackers were already using the vulnerability against defense and energy companies. Things went from bad to worse over the weekend. Security companies researchers watched as the attackers shared their exploit with a separate attack group, which began using the vulnerability to target companies in the financial services industry. Even after Microsoft issued its advisory last Saturday, There was a notable increase in proliferation. Soon, the attackers were using the vulnerability for so-called watering hole attacks, in which hackers infect a popular website with malware, then wait for victims to click to the site and infect their computers. It is believed the two attack groups were nation-state sponsored. While he said the company did not yet have conclusive evidence, based on the groups previous campaigns it was believed they were operating from China. The vulnerability affected all versions of Microsofts Internet Explorer web browser. Only those who had configured their browsers to run in enhanced protection mode were protected. The situation took on added urgency because Microsoft stopped supporting its Windows XP operating system last month, meaning that any devices running Windows XP would be permanently vulnerable to attack. Typically in its regular upgrade cycle, Microsoft waits to issue security fixes on the first Tuesday of every month - what system administrators call Patch Tuesday. But given the gravity of the hole, Microsoft raced to issue a patch Thursday and decided to update Windows XP systems as well. The security of our products is something we take incredibly seriously, Adrienne Hall, the general manager of Microsofts Trustworthy Computing project, said in a statement Thursday. When we saw the first reports about this vulnerability we decided to fix it, fix it fast, and fix it for all customers.
Posted on: Sat, 03 May 2014 08:26:11 +0000

Trending Topics



Recently Viewed Topics




© 2015