Microsoft's decision to block macros originating from the Internet by default has led to threat actors resorting to disk image and archive-based attacks, the global security firm Sophos claims.
GUEST RESEARCH: Venafi investigation of 35 million dark web URLs shows macro-enabled ransomware is widely available at bargain prices.
The Australian Cyber Security Centre (ACSC) is encouraging organisations "to urgently adopt an enhanced cyber security position. Organisations should act now and follow ACSC’s advice to improve their cyber security resilience in light of the heightened threat environment."
A Microsoft announcement that the company would be disabling macros as a default feature in Excel 4.0 has been greeted as a step that "would really help defenders".
The threat actor TA505 has started to distribute a new Windows backdoor named ServHelper, according to email security firm Proofpoint. The company claims there are two variants, one directed at remote desktop functions and the second which is primarily a downloader for a remote access trojan known as FlawedGrace.
Windows Script File (WSF) attacks are on the rise as one of the most popular attack vectors for the spread of ransomware and malware, but they could be easily prevented.