Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

WARNING: A New Zero-Day Threat is On the Loose

WARNING: A New Zero-Day Threat is On the Loose

Zero-day threats are some of the most dangerous ones out there. What we mean by “zero day” threats are those that have been discovered by hackers before an official patch has been released by the developers, giving them exactly zero days before they are actively exploited in the wild. One of the more dangerous zero-day threats out there at the moment is one that takes advantage of Internet Explorer.

Before we start making Internet Explorer jokes, we want to mention that there is nothing funny about online threats--particularly those that haven’t been addressed yet by the developers. This newly discovered zero-day threat is called the “Double Kill” Internet Explorer vulnerability. Unfortunately, the Chinese developers who discovered this vulnerability--a computer security company called Qihoo--have been quiet about the details regarding the double-kill IE bug. It’s also difficult to tell if your organization is under threat, as they aren’t revealing any of the warning signs of such an attack.

The only thing known for sure about this threat is that it takes root by using Word documents. It’s likely that this is done through email attachments as well, as email is a major method of transporting threats of all kinds. When the document is opened up, Internet Explorer is opened in the background via some kind of shellcode that downloads an executable file. The vulnerability does all this without showing anything of note to the user, making it a difficult threat to identify, but the effects are well-known. Apparently, the downloaded executable file installs a Trojan horse malware on the user’s device which creates a backdoor into the system.

There are a lot more unknowns than anything else with this vulnerability, though. In particular, professionals aren’t sure if all Word documents are affected by this vulnerability, or if the threat even needs Microsoft Office in order to function as intended. It’s not even known what role Internet Explorer plays in the attack, or if the documents that can trigger this attack are identifiable. All we can tell you is that you need to keep security best practices in mind to keep these kinds of zero-day threats from becoming a problem for your organization.

To start, you should never download an unexpected file from an unexpected sender. This can come in the form of a resume, receipt, or other online document. You can never know for sure what you’re actually downloading, as criminals have been able to spoof email addresses to a dangerous degree in recent years. Just be cautious about everything you can, and augment caution with powerful security tools that can identify potential risks before they become major problems.

To get started with network security, reach out to Voyage Technology at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Monday, 08 December 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Hardware Network Security Efficiency User Tips Internet Malware IT Support Privacy Google Email Workplace Tips Computer Phishing IT Services Collaboration Hosted Solutions Users Workplace Strategy Ransomware Mobile Device Microsoft Small Business Backup Quick Tips Productivity Passwords Communication Cybersecurity Saving Money Smartphone Managed Service Data Backup Android Upgrade Data Recovery VoIP Business Management AI Smartphones Disaster Recovery Mobile Devices communications Windows Browser Social Media Microsoft Office Managed IT Services Current Events Network Tech Term Internet of Things Remote Facebook Miscellaneous Information Automation Artificial Intelligence Gadgets Covid-19 Cloud Computing Holiday Training Remote Work Server Managed Service Provider Outsourced IT Compliance Encryption Spam Employee/Employer Relationship IT Support Office Windows 10 Data Management Government Business Continuity Virtualization Blockchain Wi-Fi Business Technology Bandwidth Windows 10 Data Security Vendor Apps Two-factor Authentication Mobile Office Gmail Apple Networking App Employer-Employee Relationship BYOD Tip of the week Chrome Managed Services Voice over Internet Protocol Mobile Device Management Budget How To WiFi BDR HIPAA Applications Computing Information Technology Hacker Access Control Avoiding Downtime Office 365 Marketing Conferencing Bring Your Own Device Managed IT Services Big Data Operating System Router Risk Management Virtual Private Network Computers 2FA Help Desk Health Analytics Website Office Tips Augmented Reality Retail Healthcare Storage Password Scam Data loss Cooperation Free Resource Project Management Windows 7 The Internet of Things Microsoft 365 Social Going Green Patch Management Save Money Solutions Remote Monitoring End of Support Vulnerability Vendor Management Cybercrime Physical Security Customer Service Display Printer Windows 11 Monitoring Paperless Office Infrastructure Excel Document Management Remote Workers Telephone Firewall Mouse Entertainment Vulnerabilities Data Privacy Safety Administration Images 101 Telephone System Multi-Factor Authentication Mobility Cost Management Robot Settings Wireless Printing Employees Content Filtering Integration IT Management Customer Relationship Management YouTube Meetings VPN User Tip Modem Mobile Security Processor Cryptocurrency Hacking Presentation Holidays Computer Repair Data Storage Virtual Desktop Data storage LiFi Wireless Technology Smart Technology Supply Chain Video Conferencing Managed Services Provider Outlook Saving Time Virtual Machines Professional Services Machine Learning Money Humor Word Managed IT Service Downloads Maintenance iPhone Licensing Antivirus Sports Social Network Telework Education Cyber security Social Engineering Entrepreneur Multi-Factor Security Tech Human Resources CES IoT Communitications Remote Computing Dark Web Cables Trends Supply Chain Management Mobile Computing Customer Resource management FinTech Tablet Undo Regulations Search Google Calendar Term Google Apps Microsoft Excel IT Maintenance Data Analysis Best Practice Star Wars IT Assessment Alert Gamification Flexibility Buisness File Sharing Staff Value Business Intelligence Dark Data Managed IT Legal Organization IT solutions Social Networking How To Legislation Shortcuts Ransmoware Fileless Malware Digital Security Cameras Business Growth Smart Devices Notifications Content Remote Working Travel Application Wearable Technology Memory Vendors Techology Health IT Google Maps Motherboard Data Breach Cortana Comparison Google Play Be Proactive Permissions Workforce Directions Videos Alt Codes IBM Assessment Electronic Health Records Downtime Unified Threat Management Wasting Time Threats Unified Threat Management Hosted Solution Trend Micro Specifications Security Cameras Workplace Strategies Fraud Meta Microchip Typing Internet Exlporer Software as a Service Username Managing Costs Amazon Network Congestion Google Drive User Error Competition eCommerce Knowledge Black Friday SSID Virtual Assistant Outsource IT Database Surveillance Point of Sale IT Technicians Virtual Machine Environment 5G Media Google Docs Proxy Server Reviews Unified Communications Cookies Experience Cyber Monday Medical IT Hotspot Transportation Small Businesses Bitcoin Network Management Tactics Development Running Cable Tech Support User Mirgation Hypervisor Displays Monitors Google Wallet Shopping Nanotechnology Optimization PowerPoint Language Employer/Employee Relationships Outsourcing Windows 8 IP Address Addiction Laptop Websites Management PCI DSS Chatbots Navigation Drones SharePoint Gig Economy Screen Reader Electronic Medical Records Distributed Denial of Service Workplace Recovery Computing Infrastructure Teamwork Hiring/Firing Service Level Agreement Internet Service Provider Halloween Regulations Compliance Hard Drives Identity Writing Evernote Paperless Lenovo Bookmark Domains Smart Tech Memes Virtual Reality Co-managed IT Alerts SQL Server Technology Care Hacks Server Management Download Net Neutrality Scary Stories Private Cloud Financial Data Identity Theft Refrigeration History Fun Business Communications Superfish Browsers Smartwatch Deep Learning Public Speaking Connectivity IT Twitter Break Fix Scams Azure Hybrid Work Lithium-ion battery Upload Procurement Error

Blog Archive