Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

WARNING: A New Zero-Day Threat is On the Loose

WARNING: A New Zero-Day Threat is On the Loose

Zero-day threats are some of the most dangerous ones out there. What we mean by “zero day” threats are those that have been discovered by hackers before an official patch has been released by the developers, giving them exactly zero days before they are actively exploited in the wild. One of the more dangerous zero-day threats out there at the moment is one that takes advantage of Internet Explorer.

Before we start making Internet Explorer jokes, we want to mention that there is nothing funny about online threats--particularly those that haven’t been addressed yet by the developers. This newly discovered zero-day threat is called the “Double Kill” Internet Explorer vulnerability. Unfortunately, the Chinese developers who discovered this vulnerability--a computer security company called Qihoo--have been quiet about the details regarding the double-kill IE bug. It’s also difficult to tell if your organization is under threat, as they aren’t revealing any of the warning signs of such an attack.

The only thing known for sure about this threat is that it takes root by using Word documents. It’s likely that this is done through email attachments as well, as email is a major method of transporting threats of all kinds. When the document is opened up, Internet Explorer is opened in the background via some kind of shellcode that downloads an executable file. The vulnerability does all this without showing anything of note to the user, making it a difficult threat to identify, but the effects are well-known. Apparently, the downloaded executable file installs a Trojan horse malware on the user’s device which creates a backdoor into the system.

There are a lot more unknowns than anything else with this vulnerability, though. In particular, professionals aren’t sure if all Word documents are affected by this vulnerability, or if the threat even needs Microsoft Office in order to function as intended. It’s not even known what role Internet Explorer plays in the attack, or if the documents that can trigger this attack are identifiable. All we can tell you is that you need to keep security best practices in mind to keep these kinds of zero-day threats from becoming a problem for your organization.

To start, you should never download an unexpected file from an unexpected sender. This can come in the form of a resume, receipt, or other online document. You can never know for sure what you’re actually downloading, as criminals have been able to spoof email addresses to a dangerous degree in recent years. Just be cautious about everything you can, and augment caution with powerful security tools that can identify potential risks before they become major problems.

To get started with network security, reach out to Voyage Technology at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Thursday, 04 June 2026

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Efficiency Hardware Network Security User Tips IT Services Internet Malware IT Support Workplace Tips Phishing Privacy Google Email Computer Workplace Strategy Small Business Hosted Solutions Collaboration Backup Ransomware Managed Service Users AI Productivity Mobile Device Microsoft Saving Money Passwords Quick Tips Communication Cybersecurity Data Backup Smartphone Data Recovery Disaster Recovery Android Upgrade VoIP Business Management Smartphones Mobile Devices communications Windows Social Media Browser Managed IT Services Microsoft Office Current Events Network Tech Term Internet of Things Remote Miscellaneous Information Training Holiday Artificial Intelligence Facebook Automation Gadgets Outsourced IT Compliance Cloud Computing Covid-19 Server Managed Service Provider IT Support Remote Work Encryption Spam Employee/Employer Relationship Office Windows 10 Government Data Management Business Continuity Virtualization Wi-Fi Blockchain Vendor Windows 10 Bandwidth Business Technology Tip of the week Managed Services Apps Data Security Two-factor Authentication Mobile Office Apple App Voice over Internet Protocol Employer-Employee Relationship Networking BYOD Mobile Device Management Chrome Gmail Budget WiFi Conferencing Managed IT Services Computing How To Hacker BDR Information Technology Avoiding Downtime Marketing HIPAA Office 365 Physical Security Applications Password Access Control Big Data Retail Healthcare Operating System Computers Risk Management Website Office Tips Router Analytics Augmented Reality Virtual Private Network Storage Health 2FA Help Desk Bring Your Own Device Excel Social Document Management Remote Workers Managed IT Service Going Green Telephone Scam Data loss Customer Service Cybercrime Cooperation Free Resource Project Management Windows 7 Patch Management Save Money Microsoft 365 Remote Monitoring Vulnerability End of Support Vendor Management Solutions Firewall Display Printer Paperless Office Windows 11 Infrastructure The Internet of Things Monitoring Video Conferencing Machine Learning Managed Services Provider Administration Saving Time Virtual Machines Professional Services Maintenance Downloads Customer Relationship Management Antivirus Settings iPhone Printing Wireless Licensing Content Filtering Hacking Entertainment Vulnerabilities Presentation YouTube Data Privacy Cryptocurrency Images 101 Wireless Technology Telephone System Multi-Factor Authentication Robot Mobility Cost Management Virtual Desktop Data storage LiFi Word IT Management VPN Employees Meetings Outlook Integration Money User Tip Modem Humor Processor Computer Repair Mobile Security Holidays Safety Sports Mouse Data Storage Smart Technology Supply Chain Mobile Computing SharePoint Addiction Electronic Medical Records Language Employer/Employee Relationships Outsourcing Chatbots Navigation Management PCI DSS Search Application Best Practice Lenovo Gig Economy Screen Reader Writing Distributed Denial of Service Workplace Buisness Service Level Agreement Internet Service Provider Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Private Cloud Identity Evernote Paperless IBM Legal IT solutions Server Management Regulations Compliance Business Growth Superfish Bookmark Identity Theft Smart Tech Memes Co-managed IT Download Net Neutrality Twitter Alerts SQL Server Technology Care Cortana Error History Business Communications Financial Data Alt Codes Browsers Smartwatch Connectivity IT Social Engineering Break Fix Scams Competition Downtime Upload Procurement Remote Computing Azure Hybrid Work Cyber security Multi-Factor Security Tech Human Resources Hosted Solution Social Network Telework Typing CES Tablet IoT Communitications Dark Web Cables Trends Supply Chain Management Alert Knowledge File Sharing Regulations Dark Data Google Calendar Term Google Apps Google Drive User Managed IT Customer Resource management FinTech Data Analysis Star Wars IT Assessment How To Microsoft Excel IT Maintenance Gamification Flexibility 5G Notifications Staff Value Business Intelligence Organization Experience Travel Social Networking Legislation Shortcuts IP Address Google Docs Unified Communications Bitcoin Techology Fileless Malware Digital Security Cameras Running Cable Google Maps Smart Devices Ransmoware Wearable Technology Memory Vendors Google Wallet Content Remote Working Health IT Unified Threat Management Motherboard Data Breach Comparison Google Play Be Proactive Recovery Hard Drives Windows 8 Unified Threat Management Directions Videos Laptop Assessment Electronic Health Records Permissions Workforce Wasting Time Threats Domains Drones Trend Micro Network Congestion Specifications Security Cameras Workplace Strategies Refrigeration User Error Microchip Halloween Internet Exlporer Software as a Service Fraud Meta Managing Costs Amazon Public Speaking Username Point of Sale eCommerce Black Friday SSID Lithium-ion battery Hacks Entrepreneur Scary Stories Database Surveillance Virtual Assistant Outsource IT Tech Support IT Technicians Virtual Machine Environment Media Network Management Fun Proxy Server Reviews Cookies Monitors Cyber Monday Medical IT Deep Learning Undo Tactics Development Hotspot Transportation Small Businesses Websites Mirgation Hypervisor Displays Education Shopping Nanotechnology Optimization PowerPoint

Blog Archive