Get a Pentest and security assessment of your IT network.

Cyber Security

MS Office Built-in Feature Allows Malware Execution Without Macros Enabled

Security researchers at Cisco’s Talos threat research group have discovered one such attack campaign spreading malware-equipped Microsoft Word documents that perform code execution on the targeted device without requiring Macros enabled or memory corruption. The technique leverages a built-in feature of MS Office, called Dynamic Data Exchange (DDE) that allows two running applications to share the same data. Microsoft doesn’t consider this as a security issue, rather according to the company the DDE protocol is a feature that can not be removed but could be improved with better warning alerts.

Source: https://thehackernews.com/2017/10/ms-office-dde-malware.html

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security