home.social

#benign — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #benign, aggregated by home.social.

fetched live
  1. Attackers have advanced their #techniques for leveraging the "search-ms" uniform resource identifier (#URI) #protocol from #malicious #documents to direct users to websites that exploit #search-ms functionality using #JavaScript hosted on the page.

    The search-ms protocol lets Windows users conduct search operations via a URI. Normally, it’s a #benign operation, but if combined with another vulnerability such as within #Windows documents, #attackers can potentially use it as a part of a broader #phishing or #malware campaign.

    This attack requires #gaps at multiple layers of an organization’s defenses. First, properly leveraging email filters with URL rewriting and malicious content controls will limit the impact of a search-ms attack. Second, it relies on limited restrictions on outbound internet browsing — both at the firewall and internet proxy level. Once again, outbound controls are critical.

    scmagazine.com/news/attackers-

    Full blog post with technical details available here: trellix.com/en-us/about/newsro