U.S. Cyber Command Issues Warning About Microsoft Outlook Vulnerability

Robinson+Cole Data Privacy + Security Insider
Contact

Hackers are targeting U.S. government networks, according to U.S. Cyber Command, which says there is a vulnerability of CVE-2017-1174, which is a two year old flaw in Microsoft Outlook that is being used by attackers to install remote access Trojans and other malware.

U.S. Cyber Command recommends that the vulnerability be patched to prevent exploitation. The known flaw can be exploited by allowing an intruder access to credentials, which is usually accomplished through phishing attacks. Once the attacker has successfully obtained Outlook credentials, the attacker can change the user’s home page to a page the attackers have infected with malicious code that activates when Outlook is opened.

Security researchers believe the attacks are being launched by Iran-backed group APT33, and are in response to the political tensions with Iran. According to the security researchers, APT33 has been using brute force attacks with commonly used passwords.

The cyber tensions between the U.S. and Iran are continuing and do not look like they will stop in the near future. U.S. businesses are being attacked and are caught in the cross-fire, so awareness of the warnings provided by U.S. Cyber Command and U.S.-CERT (Computer Emergency Readiness Team) is important to stay abreast of new threats and vulnerabilities. Since these latest attacks are being launched through brute force attacks, educating employees on these threats, and reinforcing strong passphrases is an obvious first response.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide