Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

WARNING: A New Zero-Day Threat is On the Loose

WARNING: A New Zero-Day Threat is On the Loose

Zero-day threats are some of the most dangerous ones out there. What we mean by “zero day” threats are those that have been discovered by hackers before an official patch has been released by the developers, giving them exactly zero days before they are actively exploited in the wild. One of the more dangerous zero-day threats out there at the moment is one that takes advantage of Internet Explorer.

Before we start making Internet Explorer jokes, we want to mention that there is nothing funny about online threats--particularly those that haven’t been addressed yet by the developers. This newly discovered zero-day threat is called the “Double Kill” Internet Explorer vulnerability. Unfortunately, the Chinese developers who discovered this vulnerability--a computer security company called Qihoo--have been quiet about the details regarding the double-kill IE bug. It’s also difficult to tell if your organization is under threat, as they aren’t revealing any of the warning signs of such an attack.

The only thing known for sure about this threat is that it takes root by using Word documents. It’s likely that this is done through email attachments as well, as email is a major method of transporting threats of all kinds. When the document is opened up, Internet Explorer is opened in the background via some kind of shellcode that downloads an executable file. The vulnerability does all this without showing anything of note to the user, making it a difficult threat to identify, but the effects are well-known. Apparently, the downloaded executable file installs a Trojan horse malware on the user’s device which creates a backdoor into the system.

There are a lot more unknowns than anything else with this vulnerability, though. In particular, professionals aren’t sure if all Word documents are affected by this vulnerability, or if the threat even needs Microsoft Office in order to function as intended. It’s not even known what role Internet Explorer plays in the attack, or if the documents that can trigger this attack are identifiable. All we can tell you is that you need to keep security best practices in mind to keep these kinds of zero-day threats from becoming a problem for your organization.

To start, you should never download an unexpected file from an unexpected sender. This can come in the form of a resume, receipt, or other online document. You can never know for sure what you’re actually downloading, as criminals have been able to spoof email addresses to a dangerous degree in recent years. Just be cautious about everything you can, and augment caution with powerful security tools that can identify potential risks before they become major problems.

To get started with network security, reach out to Voyage Technology at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Friday, 31 October 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Hackers Cloud Network Security Hardware User Tips Efficiency Internet Malware IT Support Privacy Google Workplace Tips Computer Phishing Email IT Services Collaboration Hosted Solutions Users Workplace Strategy Ransomware Mobile Device Microsoft Small Business Quick Tips Passwords Backup Cybersecurity Saving Money Communication Data Backup Managed Service Productivity Smartphone Android Upgrade VoIP Smartphones Business Management Mobile Devices communications Data Recovery Windows Disaster Recovery Social Media AI Browser Microsoft Office Managed IT Services Current Events Network Remote Tech Term Internet of Things Automation Artificial Intelligence Facebook Information Miscellaneous Gadgets Cloud Computing Holiday Training Covid-19 Remote Work Server Managed Service Provider Outsourced IT Employee/Employer Relationship Encryption Spam Compliance IT Support Office Windows 10 Government Data Management Business Continuity Wi-Fi Business Technology Windows 10 Blockchain Bandwidth Virtualization Data Security Apps Two-factor Authentication Mobile Office Vendor App Employer-Employee Relationship BYOD Managed Services Voice over Internet Protocol Mobile Device Management Tip of the week Chrome Gmail Budget Apple Networking How To Applications BDR Computing Hacker Conferencing Information Technology Avoiding Downtime Marketing Access Control Office 365 WiFi HIPAA 2FA Help Desk Operating System Computers Virtual Private Network Risk Management Healthcare Website Health Office Tips Analytics Augmented Reality Retail Storage Password Bring Your Own Device Router Managed IT Services Big Data Social Windows 11 Going Green Patch Management Save Money Remote Monitoring Monitoring Vulnerability End of Support Vendor Management Customer Service Cybercrime Excel Physical Security Remote Workers Display Printer Telephone Paperless Office Infrastructure Cooperation Free Resource Project Management Windows 7 Firewall Document Management Microsoft 365 Solutions The Internet of Things Scam Data loss User Tip Modem Mobile Security Processor Robot Holidays Customer Relationship Management Settings Data Storage Supply Chain Smart Technology Printing Wireless Content Filtering Video Conferencing Hacking IT Management Managed Services Provider Virtual Machines Professional Services Presentation VPN YouTube Meetings Saving Time Cryptocurrency Managed IT Service Wireless Technology Computer Repair Downloads iPhone Virtual Desktop Licensing Data storage LiFi Vulnerabilities Word Entertainment Data Privacy Outlook Machine Learning Money Images 101 Humor Mobility Telephone System Multi-Factor Authentication Cost Management Maintenance Safety Antivirus Sports Mouse Employees Integration Administration Application Best Practice Alert Username Amazon Managing Costs Black Friday SSID Managed IT Buisness File Sharing Dark Data eCommerce How To Surveillance Database Outsource IT Virtual Assistant IBM Legal IT solutions Business Growth Notifications Environment IT Technicians Virtual Machine Media Cyber Monday Medical IT Travel Reviews Proxy Server Cookies Cortana Development Tactics Small Businesses Hotspot Transportation Techology Google Maps Alt Codes Displays Mirgation Hypervisor PowerPoint Competition Downtime Unified Threat Management Shopping Nanotechnology Optimization Addiction Outsourcing Language Employer/Employee Relationships Unified Threat Management Hosted Solution Typing PCI DSS Management Chatbots Navigation Screen Reader Workplace Distributed Denial of Service Gig Economy Network Congestion Knowledge Internet Service Provider Service Level Agreement Hiring/Firing Computing Infrastructure Teamwork Google Drive User Error User Paperless Evernote Regulations Compliance Identity Memes Smart Tech Co-managed IT Point of Sale Bookmark 5G Experience Net Neutrality Download Technology Care Alerts SQL Server IP Address Google Docs Unified Communications Business Communications Bitcoin Network Management Running Cable Tech Support Financial Data History IT Connectivity Scams Break Fix Google Wallet Smartwatch Browsers Monitors Procurement Upload Hybrid Work Azure Recovery Human Resources Multi-Factor Security Tech Hard Drives Windows 8 Laptop Websites Telework Social Network Cyber security Communitications IoT Cables Dark Web Domains Drones CES Electronic Medical Records Supply Chain Management Trends SharePoint Google Apps Google Calendar Term Refrigeration Halloween FinTech Customer Resource management Regulations IT Assessment Star Wars IT Maintenance Microsoft Excel Public Speaking Lenovo Data Analysis Writing Virtual Reality Flexibility Gamification Business Intelligence Staff Value Lithium-ion battery Shortcuts Legislation Hacks Server Management Entrepreneur Scary Stories Private Cloud Organization Social Networking Fun Smart Devices Ransmoware Superfish Identity Theft Digital Security Cameras Fileless Malware Deep Learning Twitter Remote Working Content Vendors Wearable Technology Memory Be Proactive Comparison Google Play Undo Error Health IT Motherboard Data Breach Social Engineering Electronic Health Records Assessment Workforce Permissions Education Videos Directions Remote Computing Threats Wasting Time Workplace Strategies Specifications Security Cameras Mobile Computing Trend Micro Search Software as a Service Internet Exlporer Meta Fraud Tablet Microchip

Blog Archive