Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

WARNING: A New Zero-Day Threat is On the Loose

WARNING: A New Zero-Day Threat is On the Loose

Zero-day threats are some of the most dangerous ones out there. What we mean by “zero day” threats are those that have been discovered by hackers before an official patch has been released by the developers, giving them exactly zero days before they are actively exploited in the wild. One of the more dangerous zero-day threats out there at the moment is one that takes advantage of Internet Explorer.

Before we start making Internet Explorer jokes, we want to mention that there is nothing funny about online threats--particularly those that haven’t been addressed yet by the developers. This newly discovered zero-day threat is called the “Double Kill” Internet Explorer vulnerability. Unfortunately, the Chinese developers who discovered this vulnerability--a computer security company called Qihoo--have been quiet about the details regarding the double-kill IE bug. It’s also difficult to tell if your organization is under threat, as they aren’t revealing any of the warning signs of such an attack.

The only thing known for sure about this threat is that it takes root by using Word documents. It’s likely that this is done through email attachments as well, as email is a major method of transporting threats of all kinds. When the document is opened up, Internet Explorer is opened in the background via some kind of shellcode that downloads an executable file. The vulnerability does all this without showing anything of note to the user, making it a difficult threat to identify, but the effects are well-known. Apparently, the downloaded executable file installs a Trojan horse malware on the user’s device which creates a backdoor into the system.

There are a lot more unknowns than anything else with this vulnerability, though. In particular, professionals aren’t sure if all Word documents are affected by this vulnerability, or if the threat even needs Microsoft Office in order to function as intended. It’s not even known what role Internet Explorer plays in the attack, or if the documents that can trigger this attack are identifiable. All we can tell you is that you need to keep security best practices in mind to keep these kinds of zero-day threats from becoming a problem for your organization.

To start, you should never download an unexpected file from an unexpected sender. This can come in the form of a resume, receipt, or other online document. You can never know for sure what you’re actually downloading, as criminals have been able to spoof email addresses to a dangerous degree in recent years. Just be cautious about everything you can, and augment caution with powerful security tools that can identify potential risks before they become major problems.

To get started with network security, reach out to Voyage Technology at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Saturday, 02 August 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security User Tips Efficiency Hardware Internet Malware IT Support Privacy Google Computer Email Workplace Tips Phishing Hosted Solutions IT Services Users Collaboration Mobile Device Workplace Strategy Ransomware Quick Tips Small Business Cybersecurity Microsoft Backup Passwords Communication Data Backup Saving Money Smartphone Android Managed Service Smartphones VoIP Business Management Mobile Devices communications Upgrade Disaster Recovery Data Recovery Social Media Productivity Browser Windows Microsoft Office Managed IT Services AI Current Events Network Remote Tech Term Internet of Things Automation Artificial Intelligence Facebook Gadgets Cloud Computing Holiday Covid-19 Miscellaneous Training Information Remote Work Server Managed Service Provider Outsourced IT Compliance Encryption Spam Employee/Employer Relationship Office Windows 10 Government Business Continuity Data Management Wi-Fi Blockchain Business Technology IT Support Bandwidth Windows 10 Virtualization Apps Two-factor Authentication Vendor Mobile Office Data Security Employer-Employee Relationship BYOD Chrome Mobile Device Management Budget Gmail Managed Services Apple Networking Voice over Internet Protocol App Computing Information Technology Hacker HIPAA Access Control Avoiding Downtime Applications Office 365 Marketing Tip of the week Conferencing How To WiFi BDR Operating System Virtual Private Network Risk Management Computers Router Health Analytics Website Office Tips Augmented Reality Retail Help Desk Storage Password Bring Your Own Device Managed IT Services Healthcare Big Data Going Green Patch Management Social Save Money Cooperation Free Resource Remote Monitoring Project Management Vulnerability End of Support Windows 7 Vendor Management Cybercrime Microsoft 365 Physical Security Customer Service Display Printer Solutions Paperless Office Infrastructure Windows 11 Document Management 2FA Monitoring Firewall Excel Scam Data loss Remote Workers The Internet of Things Telephone Robot Entertainment Vulnerabilities Settings Data Privacy Printing Wireless Images 101 Content Filtering IT Management Customer Relationship Management Multi-Factor Authentication VPN Mobility YouTube Meetings Telephone System Cost Management Cryptocurrency Hacking Presentation Computer Repair Virtual Desktop Employees Data storage Integration LiFi Wireless Technology Modem User Tip Processor Outlook Mobile Security Machine Learning Holidays Money Word Humor Data Storage Smart Technology Supply Chain Video Conferencing Maintenance Antivirus Sports Managed Services Provider Virtual Machines Mouse Professional Services Saving Time Safety Managed IT Service Administration Downloads iPhone Licensing Cyber security Multi-Factor Security Tech Human Resources Travel Application Social Network Telework CES IoT Communitications Techology Dark Web Cables Google Maps Cortana Trends Supply Chain Management Alt Codes IBM Regulations Google Calendar Term Google Apps Downtime Unified Threat Management Customer Resource management FinTech Data Analysis Star Wars IT Assessment Unified Threat Management Microsoft Excel IT Maintenance Hosted Solution Gamification Flexibility Staff Value Business Intelligence Typing Social Networking Legislation Shortcuts Network Congestion Organization Fileless Malware Digital Security Cameras Smart Devices Google Drive User Error Ransmoware Competition Knowledge Content Remote Working Wearable Technology Memory Vendors Motherboard Data Breach Comparison Google Play Be Proactive Point of Sale 5G Health IT Directions Videos Assessment Electronic Health Records Google Docs Permissions Workforce Unified Communications Experience Running Cable Tech Support User Wasting Time Threats Bitcoin Network Management Trend Micro Google Wallet Specifications Security Cameras Workplace Strategies Monitors Microchip Internet Exlporer Software as a Service Fraud Meta IP Address Laptop Websites Username Managing Costs Amazon Windows 8 eCommerce Drones Black Friday SSID Database Surveillance SharePoint Virtual Assistant Outsource IT Electronic Medical Records Media Halloween Recovery IT Technicians Virtual Machine Environment Cookies Lenovo Cyber Monday Medical IT Hard Drives Writing Proxy Server Reviews Tactics Development Hotspot Transportation Small Businesses Domains Virtual Reality Hacks Server Management Scary Stories Private Cloud Mirgation Hypervisor Displays Nanotechnology Optimization Superfish PowerPoint Identity Theft Refrigeration Fun Shopping Twitter Addiction Language Employer/Employee Relationships Outsourcing Deep Learning Public Speaking Lithium-ion battery Navigation Error Management PCI DSS Chatbots Screen Reader Distributed Denial of Service Workplace Education Social Engineering Entrepreneur Gig Economy Remote Computing Service Level Agreement Internet Service Provider Computing Infrastructure Teamwork Hiring/Firing Mobile Computing Evernote Paperless Regulations Compliance Identity Smart Tech Memes Co-managed IT Tablet Undo Search Bookmark Alert Download Net Neutrality Alerts SQL Server Technology Care Best Practice Managed IT Business Communications Buisness File Sharing Dark Data Financial Data History Connectivity IT Legal Break Fix Scams IT solutions How To Browsers Smartwatch Notifications Upload Procurement Azure Hybrid Work Business Growth

Blog Archive