Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

WARNING: A New Zero-Day Threat is On the Loose

WARNING: A New Zero-Day Threat is On the Loose

Zero-day threats are some of the most dangerous ones out there. What we mean by “zero day” threats are those that have been discovered by hackers before an official patch has been released by the developers, giving them exactly zero days before they are actively exploited in the wild. One of the more dangerous zero-day threats out there at the moment is one that takes advantage of Internet Explorer.

Before we start making Internet Explorer jokes, we want to mention that there is nothing funny about online threats--particularly those that haven’t been addressed yet by the developers. This newly discovered zero-day threat is called the “Double Kill” Internet Explorer vulnerability. Unfortunately, the Chinese developers who discovered this vulnerability--a computer security company called Qihoo--have been quiet about the details regarding the double-kill IE bug. It’s also difficult to tell if your organization is under threat, as they aren’t revealing any of the warning signs of such an attack.

The only thing known for sure about this threat is that it takes root by using Word documents. It’s likely that this is done through email attachments as well, as email is a major method of transporting threats of all kinds. When the document is opened up, Internet Explorer is opened in the background via some kind of shellcode that downloads an executable file. The vulnerability does all this without showing anything of note to the user, making it a difficult threat to identify, but the effects are well-known. Apparently, the downloaded executable file installs a Trojan horse malware on the user’s device which creates a backdoor into the system.

There are a lot more unknowns than anything else with this vulnerability, though. In particular, professionals aren’t sure if all Word documents are affected by this vulnerability, or if the threat even needs Microsoft Office in order to function as intended. It’s not even known what role Internet Explorer plays in the attack, or if the documents that can trigger this attack are identifiable. All we can tell you is that you need to keep security best practices in mind to keep these kinds of zero-day threats from becoming a problem for your organization.

To start, you should never download an unexpected file from an unexpected sender. This can come in the form of a resume, receipt, or other online document. You can never know for sure what you’re actually downloading, as criminals have been able to spoof email addresses to a dangerous degree in recent years. Just be cautious about everything you can, and augment caution with powerful security tools that can identify potential risks before they become major problems.

To get started with network security, reach out to Voyage Technology at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Wednesday, 28 January 2026

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Hardware Efficiency Network Security User Tips Internet Malware IT Support IT Services Privacy Google Email Workplace Tips Computer Phishing Collaboration Hosted Solutions Users Workplace Strategy Ransomware Mobile Device Small Business Microsoft Backup Productivity Quick Tips Managed Service Passwords Saving Money Communication Cybersecurity Smartphone Data Backup Android Disaster Recovery Data Recovery AI Upgrade Business Management VoIP Smartphones Mobile Devices communications Windows Browser Social Media Microsoft Office Managed IT Services Network Current Events Tech Term Internet of Things Remote Facebook Miscellaneous Information Holiday Automation Artificial Intelligence Gadgets Cloud Computing Covid-19 Training Compliance Server Remote Work Managed Service Provider Outsourced IT IT Support Encryption Spam Employee/Employer Relationship Office Windows 10 Business Continuity Government Data Management Virtualization Blockchain Wi-Fi Business Technology Windows 10 Bandwidth Data Security Apps Vendor Two-factor Authentication Mobile Office Managed Services Voice over Internet Protocol WiFi Apple Networking App Employer-Employee Relationship BYOD Mobile Device Management Tip of the week Chrome Gmail Budget How To BDR HIPAA Computing Hacker Applications Information Technology Avoiding Downtime Marketing Access Control Office 365 Conferencing Storage Password Bring Your Own Device Healthcare Big Data Managed IT Services Operating System Computers Router Virtual Private Network Risk Management Website Health Help Desk Office Tips Analytics 2FA Augmented Reality Retail Telephone The Internet of Things Scam Remote Workers Data loss Social Cooperation Going Green Patch Management Free Resource Project Management Save Money Remote Monitoring Windows 7 Vulnerability End of Support Vendor Management Customer Service Cybercrime Microsoft 365 Physical Security Solutions Display Printer Paperless Office Infrastructure Monitoring Windows 11 Firewall Document Management Excel Virtual Machines Professional Services Safety Maintenance Antivirus Sports Downloads Mouse Licensing Entertainment Administration iPhone Vulnerabilities Telephone System Data Privacy Robot Customer Relationship Management Cost Management Settings Images 101 Printing Wireless Content Filtering Mobility Multi-Factor Authentication Hacking IT Management Presentation VPN YouTube Meetings Cryptocurrency Wireless Technology User Tip Modem Computer Repair Mobile Security Processor Employees Integration Virtual Desktop Data storage LiFi Word Smart Technology Holidays Outlook Machine Learning Money Saving Time Data Storage Supply Chain Humor Video Conferencing Managed Services Provider Managed IT Service Twitter Alerts Workplace Gig Economy Deep Learning Download Undo Internet Service Provider Error Teamwork Hiring/Firing Evernote Paperless Browsers Regulations Compliance Education Connectivity Social Engineering Break Fix Memes Remote Computing Co-managed IT Upload Mobile Computing Social Network Net Neutrality SQL Server Technology Care Multi-Factor Security Business Communications Financial Data Tablet IoT History Search Dark Web IT Alert Scams Smartwatch Application Best Practice Trends Managed IT Customer Resource management Procurement Buisness File Sharing Regulations Azure Hybrid Work Dark Data Google Calendar Tech Human Resources IBM Legal Data Analysis Telework IT solutions Star Wars Cyber security How To Microsoft Excel Communitications Notifications Staff Cables CES Business Growth Gamification Supply Chain Management Travel Social Networking Legislation Term Google Apps Techology Fileless Malware FinTech Google Maps Cortana Alt Codes Content IT Assessment Wearable Technology IT Maintenance Competition Health IT Flexibility Downtime Unified Threat Management Motherboard Value Business Intelligence Comparison Permissions Shortcuts Unified Threat Management Directions Organization Hosted Solution Assessment Typing Smart Devices Ransmoware Digital Security Cameras Remote Working Memory Vendors Network Congestion Specifications Knowledge Fraud Google Play Be Proactive Google Drive User Error Microchip User Internet Exlporer Data Breach Videos Username Electronic Health Records Workforce Point of Sale Wasting Time Threats 5G Black Friday Trend Micro Experience Security Cameras Workplace Strategies IP Address Google Docs Unified Communications Database Bitcoin Network Management Software as a Service Running Cable Tech Support IT Technicians Meta Google Wallet Proxy Server Cookies Managing Costs Amazon Monitors Cyber Monday eCommerce Hotspot SSID Recovery Tactics Hard Drives Windows 8 Surveillance Laptop Websites Mirgation Virtual Assistant Outsource IT Media Domains Drones Nanotechnology Virtual Machine Environment Electronic Medical Records Language Medical IT SharePoint Reviews Addiction Refrigeration Management Development Halloween Chatbots Transportation Small Businesses Public Speaking Lenovo Screen Reader Hypervisor Displays Writing Distributed Denial of Service Optimization Virtual Reality Computing Infrastructure PowerPoint Lithium-ion battery Shopping Service Level Agreement Hacks Server Management Entrepreneur Scary Stories Private Cloud Identity Employer/Employee Relationships Outsourcing Navigation Superfish Bookmark PCI DSS Identity Theft Smart Tech Fun

Blog Archive