{"id":314508,"date":"2017-04-27T16:38:42","date_gmt":"2017-04-27T16:38:42","guid":{"rendered":"http:\/\/citifmonline.com\/?p=314508"},"modified":"2017-04-27T16:38:42","modified_gmt":"2017-04-27T16:38:42","slug":"hackers-used-microsoft-word-bug-for-months","status":"publish","type":"post","link":"https:\/\/citifmonline.com\/?p=314508","title":{"rendered":"Hackers used Microsoft Word bug &#8216;for months&#8217;"},"content":{"rendered":"<p>A bug in Microsoft Word was exploited by hackers for months before it was eventually fixed, according to security researchers.<\/p>\n<p>The flaw allowed attackers to take control of a computer via malicious document files.<\/p>\n<p>The zero-day, or previously undetected, vulnerability was patched earlier this month.<\/p>\n<p>However, it has since emerged that Microsoft was told about it in October, nearly six months ago.<\/p>\n<p>A report from the Reuters news agency notes that security researcher Ryan Hanson at Optiv first discovered the problem in July 2016.<\/p>\n<p>Microsoft could have notified customers to make a change to settings in Word that would have prevented the vulnerability from being exploited &#8211; but that would also have alerted hackers to its existence.<\/p>\n<p>The decision to wait for a patch seems to have allowed a window of opportunity for hackers to discover the flaw on their own.<\/p>\n<p><strong>Hackathon<\/strong><br \/>\nIn March, cyber-security company FireEye noticed financial hacking software that was being distributed with the Microsoft bug.<\/p>\n<p>And another company, McAfee, found attacks that were exploiting it, too.<\/p>\n<p>McAfee faced some criticism, however, for publishing a blog post about the vulnerability &#8211; with details hackers may have found useful &#8211; two days before it was fixed.<\/p>\n<p>Yet another company, Proofpoint, found that the vulnerability was being targeted by scammers trying to distribute Dridex malware &#8211; which infects a victim&#8217;s computer before snooping on banking logins.<\/p>\n<p>There were even reports of hacking after the patch was made available.<\/p>\n<p>Cyber-security outlet Morphisec said that employees at Ben-Gurion University in Israel had had their email accounts compromised by attackers who had then sent infected documents to medical professionals and contacts at technology companies.<\/p>\n<p>&#8220;Prior to public disclosure, our engineers were aware of a small number of attempts to use this vulnerability through targeted spam designed to convince users to open a malicious attachment,&#8221; a Microsoft spokesman said.<\/p>\n<p>Customers who applied the 11 April security update were already protected, he added.<br \/>\n&#8220;In an ideal world, it would have been fixed sooner,&#8221; said cyber-security expert Graham Cluley.<\/p>\n<p>However, he pointed out that patching software run on millions of computers around the world was not an easy process.<\/p>\n<p>&#8220;There&#8217;s always this huge challenge because companies want to patch their software, but they want to do it properly &#8211; they want to make sure they&#8217;ve been comprehensive with the fix,&#8221; he told the BBC.<\/p>\n<p>&#8211;<\/p>\n<p>Source: BBC<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A bug in Microsoft Word was exploited by hackers for months before it was eventually fixed, according to security researchers. The flaw allowed attackers to take control of a computer via malicious document files. The zero-day, or previously undetected, vulnerability was patched earlier this month. However, it has since emerged that Microsoft was told about [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jnews-multi-image_gallery":[],"jnews_single_post":[],"jnews_primary_category":[],"jnews_social_meta":[],"jnews_override_counter":[],"footnotes":""},"categories":[106],"tags":[1492,727],"class_list":["post-314508","post","type-post","status-publish","format-standard","hentry","category-technology","tag-citi-trends","tag-microsoft"],"_links":{"self":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts\/314508","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=314508"}],"version-history":[{"count":0,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts\/314508\/revisions"}],"wp:attachment":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=314508"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=314508"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=314508"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}