Get a Pentest and security assessment of your IT network.

Cyber Security

Microsoft explains how ActiveX in Office is abused by attackers

Microsoft engineer Chengyun discusses the default behaviour of ActiveX controls embedded in Office documents. The software giant also provides information on how can an attacker abuse ActiveX and how Office users can change the behavior of the controls. The engineer also provides step-by-step instructions on configuring Office 2007 for users concerned about Safe-for-Initialization ActiveX control being instantiated by Office without prompt. Attackers have discovered ActiveX support in Office applications and have been using it to more effectively lure victims to web-based malware.

Source: https://threatpost.com/microsoft-explains-how-activex-office-abused-attackers-030409/72366/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security