Users of Internet Explorer 8 at risk of 'water hole attack' - wave3.com-Louisville News, Weather & Sports

Users of Internet Explorer 8 at risk of 'water hole attack,' urged to take security measures

Users of Internet Explorer 8 are at risk of what is known as a "watering hole" attack. Users of Internet Explorer 8 are at risk of what is known as a "watering hole" attack.
  • Cyber crimeMore>>

  • Zuckerberg meeting with EU parliament leaders to be webcast

    Zuckerberg meeting with EU parliament leaders to be webcast

    Monday, May 21 2018 5:41 AM EDT2018-05-21 09:41:58 GMT
    Monday, May 21 2018 11:46 AM EDT2018-05-21 15:46:31 GMT
    (AP Photo/Marcio Jose Sanchez, File). FILE- In this May 1, 2018, file photo, Facebook CEO Mark Zuckerberg makes the keynote speech at F8, Facebook's developer conference, in San Jose, Calif. Facebook is suspending about 200 apps that it believes may ha...(AP Photo/Marcio Jose Sanchez, File). FILE- In this May 1, 2018, file photo, Facebook CEO Mark Zuckerberg makes the keynote speech at F8, Facebook's developer conference, in San Jose, Calif. Facebook is suspending about 200 apps that it believes may ha...

    Facebook CEO Mark Zuckerberg's Tuesday meeting with the leaders of the European parliament about the data protection scandal that has engulfed his company will be open to the public through web streaming.

    More >>

    Facebook CEO Mark Zuckerberg's Tuesday meeting with the leaders of the European parliament about the data protection scandal that has engulfed his company will be open to the public through web streaming.

    More >>
  • Correction: Cyberattack Fighter-Detained story

    Correction: Cyberattack Fighter-Detained story

    Wednesday, May 16 2018 11:23 AM EDT2018-05-16 15:23:25 GMT
    Thursday, May 17 2018 6:44 PM EDT2018-05-17 22:44:57 GMT
    (AP Photo/Frank Augstein, File). FILE - This May 15, 2017, file photo shows British cybersecurity expert Marcus Hutchins during an interview in Ilfracombe, England. Hutchins, accused of creating and distributing malware designed to steal banking passwo...(AP Photo/Frank Augstein, File). FILE - This May 15, 2017, file photo shows British cybersecurity expert Marcus Hutchins during an interview in Ilfracombe, England. Hutchins, accused of creating and distributing malware designed to steal banking passwo...
    A British cybersecurity expert accused of creating and distributing malware designed to steal banking passwords is headed to court for a hearing on what evidence may be used in the case.More >>
    A British cybersecurity expert accused of creating and distributing malware designed to steal banking passwords is headed to court for a hearing on what evidence may be used in the case.More >>
  • Mexico acknowledges banks were hacked; losses unknown

    Mexico acknowledges banks were hacked; losses unknown

    Tuesday, May 15 2018 12:03 PM EDT2018-05-15 16:03:55 GMT
    Wednesday, May 16 2018 8:12 PM EDT2018-05-17 00:12:39 GMT
    Mexico has established a one-day waiting period on electronic money transfers of over $2,500 in the wake of a hacking attack that may have taken as much as $20 million from several Mexican banks.More >>
    Mexico has established a one-day waiting period on electronic money transfers of over $2,500 in the wake of a hacking attack that may have taken as much as $20 million from several Mexican banks.More >>

(RNN) - Users of Internet Explorer 8 could be at risk for a major cyber security threat unless they take steps to safeguard their browser.

Microsoft, which owns the Internet Explorer browser system, issued a security advisory that explained users of Internet Explorer 8 are at risk of a "remote code execution vulnerability."

"The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer," Microsoft said on their website. "An attacker could host a specially crafted website that is designed to exploit this vulnerability through Internet Explorer and then convince a user to view the website."

According to The Hacker News, the attack is known as a "watering hole" attack and the website for the U.S. Department of Labor is just one of several high-profile web sites that have been corrupted.

The computer security news site also explained that in watering hole attacks, "victims are not affected directly. Rather, attackers compromise a trusted, third-party website that the intended targets are likely to visit, then launch a silent attack when they visit the site."

Microsoft explained further how this type of attack operates:

"In a web-based attack scenario, an attacker could host a website that contains a webpage that is used to exploit this vulnerability. In addition, compromised websites and websites that accept or host user-provided content or advertisements could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit these websites. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes users to the attacker's website."

Only users of Internet Explorer 8 are at risk, according to Microsoft. Users of Internet Explorer 6, 7, 9, and 10 are safe.

Users of Internet Explorer 8 are urged to visit Microsoft's page that explains how to enable a security measure that is designed to prevent the attack.

The Hacker News said the attack may have begun in mid-March and there is evidence that it is the work of a China-based hacking group known as "DeepPanda."

Copyright 2013 Raycom News Network. All rights reserved.

Powered by Frankly