Zero-day exploit targets European website
SECURITYBy BiztechAfrica - June 22, 2012, 10:02 a.m.
Sophos is advising computer users and administrators to exercise caution following the discovery of an as-yet unpatched security vulnerability in Microsoft software.
SophosLabs determined that the website of a European aeronautical parts supplier - which is currently not being named due to the sensitivity of the situation - had been hacked, and a malicious attack planted on the website which exploits a zero-day Microsoft security vulnerability.
Sophos was alerted to the security problem when a Sophos customer attempted to visit the affected website, and received a warning message that a file on the site was infected by code which attempts to exploit a vulnerability in Microsoft XML Core Services which could allow Remote Code Execution - a vulnerability known as CVE-2012-1889 - which has been linked to recent warnings from Google about 'state-sponsored attacks'.
"One way that hackers break into large companies and organisations is to target their supply chain. Rather than try to hack a company which may have robust security practices and security teams, they can instead attack a smaller supplier who is less likely to notice the security breach," says Brett Myroff, CEO of Sophos distributor, NetXactics.
Users running any flavour of currently-supported Windows are vulnerable, from XP, up to and including Windows 7. All supported editions of Microsoft Office 2003 and Microsoft Office 2007 are also vulnerable. At the time of writing there is not yet an official patch from Microsoft - but the company recommends that Internet Explorer and Microsoft Office users immediately install a Fix it solution, downloadable with instructions from Microsoft Knowledge Base Article 2719615, until the company issues an official fix.
"Users should not underestimate the seriousness of this vulnerability. It's being actively exploited in the wild, and there is currently no patch available for it.
“Sophos has raised its threat level rating to 'Critical'. Sophos does provide protection against the exploit - but the best solution of all would be to have a proper fix from Microsoft,” Myroff says.
MORE SECURITY NEWS
Benin’s internet cafés become headquarters for cybercrimeInternet cafés in the West African nation of Benin appear to be fast becoming ‘command centres’ for online scammers. Read More
Heartbleed a ‘severe vulnerability’Today will be a memorable one in cybersecurity history, thanks to the end of Windows XP support and the coming to light of the Heartbleed Open SSL vulnerability, says Lucas Zaichkowsky, Enterprise Defense Architect at AccessData. Read More
Kaspersky Lab Launches worldwide interactive cyberthreat mapKaspersky Lab has launched an interactive cyberthreat map that visualises cyber security incidents occurring worldwide in real time. Read More
Kaspersky Lab study: about one third of all phishing attacks aimed at stealing moneyCybercriminals are trying harder than ever to acquire confidential user information and steal money from bank accounts, says a new study by Kaspersky Lab. Read More
Uganda to host Banking Fraud and ICT Security ConferenceThe 3rd Annual East Africa Banking and ICT Security Summit will be held on April 25 in Kampala Uganda. Read More
Kenya’s cyber security strategy enters homestretchKenya is putting in place a cyber security strategy to protect the country’s online assets. Read More
Over the NSA surveillance hype? Here’s why you shouldn’t beA year after the Snowden revelations, the panic has died down and most companies and individuals are carrying on as they did before. But they shouldn’t be, says JJ Milner, MD of Global Micro. Read More
Three layers of security: crucial for businessBusinesses today need to focus equally on physical, personnel and cyber security in order to mitigate risk in the face of growing criminal focus on enterprise data, says UK-based security expert Chris Phillips. Read More
2014 Banking and ICT summits pegged for Uganda, Zambia and EthiopiaCyber Security Africa has announced that its 2014 Banking and ICT summits will be hosted in Uganda, Zambia and Ethiopia. Read More
FEATURED STORYKenyan shift to Green Economy would generate USD 45bn by 2030
Kenya’s transition to a green economy could produce major economic benefits equivalent to an estimated USD 45 billion by 2030, a new study shows.
BEST READ NEWS
IN DEPTHE-waste threatens Ghana’s beaches
Many beaches in Ghana, already stressed by pollution and poor maintenance, are now facing a new threat: e-waste.