Cyberspies Exploit Microsoft Office
Datalk.com Computer, Internet, Games Talk FAQ



  Datalk.com - Computers, Internet, Games > Software and Programming > Computer Security and Internet Security Talk and Alerts

Topic Cyberspies Exploit Microsoft Office


Reply
 
April 23rd, 2007   Post 1
Team Infidel
Kilobyte
 

Posts: 429
Country: United States
Microchips: 22
Gadgets

Post - Cyberspies Exploit Microsoft Office


USA Today
April 23, 2007
Pg. 1

Infected files infiltrate government agencies
By Byron Acohido, USA Today
SEATTLE — Cyberspies have a new secret weapon: tainted Microsoft Office files.
A rising number of cyberattacks are taking aim at specific individuals at critical government agencies and corporations — enticing them to unwittingly open a corrupted Word, Excel or PowerPoint file sent as an e-mail attachment.
Clicking on the file relinquishes control of the PC without the user's knowledge. The attacker then uses the compromised PC as a base from which to roam the organization's internal network.
Federal agencies and defense and nuclear contractors are under assault. Security firm MessageLabs says it has been intercepting a series of attacks from PCs in Taiwan and China since November.
"The bad guys know which organizations have data worth stealing and are picking them out one by one," says Alex Shipp, senior technologist at MessageLabs.
In early 2006, security experts detected one or two such attacks a week. Last month, MessageLabs intercepted 716 e-mails carrying corrupted Office files aimed at 216 different agencies and companies.
Assaults are coming from China and perhaps other countries in the hunt for military, trade and infrastructure intelligence, says Alan Paller, research director at The SANS Institute, a security think tank. The goal: strategic advantage over the USA. "The attacks are working," Paller says. "Penetrations are deep and broad."
Some attacks could be "on-demand," at the behest of companies that hire cybergangs to pilfer data from rivals, says Righard Zwienenberg, chief researcher at Norman Data Defense Systems.
At a congressional hearing last week on cybersecurity, Donald Reid, a senior State Department official, described how an employee in May clicked on a Word document corrupted via a security hole for which Microsoft had no patch. A fix wasn't available until eight weeks later. Microsoft has issued 10 patches for security holes in Office programs since January 2006, including a handful delivered only after crooks began using newly discovered flaws in their attacks. The best protection: keeping Office security patches updated.
The Office file attacks are "very targeted and very limited," says Mark Miller, Microsoft's director of security response, who called on workers "to absolutely extend extreme caution" when opening Office files in e-mail.
Microsoft has been slow to patch security holes in Office programs, Zwienenberg says. "The cybercriminals are getting smarter and smarter," he says.
 

Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft Offers Blogger Cash for Wikipedia Editing -HAL- Microsoft Talk 3 June 7th, 2007 07:31
Top 10 "highly useful" gadgets and gizmos for your office -HAL- Gadgets and Gizmos Talk 7 June 3rd, 2007 13:35
Vista UI Is a 'Step Back' for Microsoft bigcanada813 Latest Computer and Internet News 0 February 27th, 2007 16:54
Microsoft Opens Vista Kernel to Rivals Sunb! Microsoft Talk 1 December 29th, 2006 14:41




Content Relevant URLs by vBSEO


  Contact Us         Library