Attackers Use Microsoft Security Hole Against Energy, Defense, Financial Targets

Advertisement
By Nicole Perlroth, The New York Times | Updated: 7 May 2014 15:44 IST
By the time Microsoft warned customers of a nasty security hole in its Web browser Saturday, a sophisticated group of attackers were already using the vulnerability against defense and energy companies, according to FireEye, the security company.

Things went from bad to worse over the weekend. FireEye's researchers watched as the attackers shared their exploit with a separate attack group, which began using the vulnerability to target companies in the financial services industry, according to Darien Kindlund, the director of threat intelligence at FireEye.

Even after Microsoft issued its advisory Saturday, Kindlund said, "There was a notable increase in proliferation."

Soon, the attackers were using the vulnerability for so-called watering hole attacks, in which hackers infect a popular website with malware, then wait for victims to click to the site and infect their computers.

Advertisement

Kindlund said FireEye believed the two attack groups were nation-state sponsored. While he said the company did not yet have conclusive evidence, based on the groups' previous campaigns it was believed they were operating from China.

Advertisement

The vulnerability affected all versions of Microsoft's Internet Explorer Web browser. Only those who had configured their browsers to run in enhanced protection mode were protected.

The situation took on added urgency because Microsoft stopped supporting its Windows XP operating system last month, meaning that any devices running Windows XP would be permanently vulnerable to attack.

Advertisement

Typically in its regular upgrade cycle, Microsoft waits to issue security fixes on the first Tuesday of every month - what system administrators call "Patch Tuesday." But given the gravity of the hole, Microsoft raced to issue a patch Thursday and decided to update Windows XP systems as well.

(Also see: Microsoft Rescues Windows XP Users With Critical Internet Explorer Fix)

"The security of our products is something we take incredibly seriously," Adrienne Hall, the general manager of Microsoft's Trustworthy Computing project, said in a statement Thursday. "When we saw the first reports about this vulnerability we decided to fix it, fix it fast, and fix it for all customers."

Advertisement

The timing of FireEye's discovery was fortuitous for the company, whose stock has tumbled 40 percent since a finding last month by NSS Labs, an independent research company, that FireEye's breach-detection systems underperformed similar offerings by Cisco Systems, Trend Micro and General Dynamics. NSS Labs actually issued a grade of "caution" to customers using FireEye's web and email malware protection systems.

The findings set off an unusual back-and-forth online between NSS Labs and FireEye. Responding to the report in a blog post, Manish Gupta, FireEye's senior vice president for products, said NSS Labs' test environment did not match the real threat landscape. NSS Labs' researchers responded in a blog post of their own - titled "Don't Shoot the Messenger."

FireEye's stock, which had been trading at $65 before the NSS Labs report was released, has been tumbling and closed near $40 Thursday.

Kindlund, of FireEye, said this week's discovery of the security hole in Internet Explorer was proof that isolated tests did not reflect real-world threats. A separate finding by NSS Labs released in March had found that Internet Explorer was more secure than Google's Chrome and Apple's Safari browser.

"Look, we're focused on protecting and defending against real-world attacks," Kindlund said. "It's hard to model and test for that in any controlled way. Clearly, there's a disconnect between what's happening in the real world and what's currently being tested."

© 2014 New York Times News Service

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the Samsung Galaxy Z TriFold May Cost in India
  2. Nubia Fold With 8-Inch OLED Display Launched Alongside Nubia Flip 3
  3. Ray-Ban Meta Gen 2 Glassses Are Now Available in India
  4. YouTube Recap 2025 Rolled Out With Personalised Cards, Viewing Insights
  5. iPhone 16 Price Drops Under Rs. 63,000 on Croma With Bank Discounts
  6. Oppo A6x 5G With 6,500mAh Battery Launched in India at This Price
  7. Red Dead Redemption Comes to Android and iOS via Netflix Games
  8. Redmi 15C 5G Camera Details Confirmed a Day Ahead of Launch in India
  9. Vivo X300 Pro Review: Flagship Mobile Photography. Redefined.
  10. Vivo X300 Launched in India With MediaTek Dimensity 9500 SoC at This Price
  1. Poco C85 5G India Launch Date Announced; Key Specifications, Features Confirmed
  2. Redmi Note 15 5G Series Price, Specifications Tipped Ahead of Global Launch
  3. Apple Might Launch Only Three iPhone Models in 2026, IDC Data Suggests
  4. Samsung Teases Exynos 2600 Chip Expected to Debut on Flagship Samsung Galaxy S26 Series
  5. Nubia Fold With 6,560mAh Battery, 8-Inch OLED Display Launched Alongside Nubia Flip 3: Price, Features
  6. iPhone 16 Price Drops Under Rs. 63,000 on Croma With Bank Discounts: Specifications, Features
  7. Samsung Galaxy Z TriFold Pricing Revealed; Here's How Much It Might Cost in India and Other Markets
  8. YouTube Recap 2025 Rolled Out With Personalised Cards, Video Viewing Insights
  9. Apple to Reportedly Resist Government’s Directive to Preload Sanchar Saathi App: 5 Things to Know
  10. Red Dead Redemption and Undead Nightmare DLC Now Available on Android and iOS
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.