Hackers target APAC Windows vulnerability

Close to 70 per cent of Windows-based PCs are vulnerable to this attack: Websense

Websense estimates that close to 70 per cent of Windows-based PCs are vulnerable to attack, by a zero-day exploit.

The vulnerability allows attackers to execute code on a machine when the user visits a malicious website.

This can happen when the user is tricked into clicking a link in an email or via compromised legitimate websites.

Websense senior security research manager Carl Leonard said the discovery suggests that the hackers were using this exploit to specifically target companies in APAC.

“Websense estimates that close to 70 percent of Windows-based PCs are vulnerable to this exploit,” he said. “Given the huge attack surface, the actors behind these campaigns are racing to target companies before a patch becomes available.

“We anticipate that as more information of this zero day comes to light, the exploit will be weaponised and packaged into exploit kits rapidly, greatly increasing the number of attackers with access to this exploit.

But Leonard said all was not lost as they generally fell into an attack pattern.

“When you take the approach of looking at the entire attack chain for suspicious behaviour, rather than waiting and hoping to catch something on the last step of the process, you have many more opportunities to spot and disrupt an attack - even if it's malware you've never seen before," he said.

“Websense strongly encourages IT administrators to install the Microsoft FixIt patch to stop the vulnerability while waiting for a formal patch from Microsoft.”

2015 ARN ICT Industry Awards: NOMINATE NOW!!!: Nominations for the 2015 ARN ICT Industry Awards are now open. Once again, it is time to NOMINATE NOW!!!

Join the ARN newsletter!

Error: Please check your email address.

Tags hackersWindowswebsensezero-day vulnerability

More about APACMicrosoftWebsense

ARN Directory | Distributors relevant to this article

Show Comments
 
Computerworld
CIO
Techworld
CMO

Latest News

09:42AM
Will enterprise jump on the Windows 10 bandwagon sooner or later?
09:08AM
Avaya finalises Ensa acquisition
07:03AM
Data here, data there, by 2019 data’s a billionaire…
06:33AM
IBM unveils industry-specific predictive analytics services
More News
04 Jun
Websense Data Theft Prevention Breakfast - Melbourne
04 Jun
IM Experience, Sydney
09 Jun
Ascom Nurse Call product launch
10 Jun
D-Link IP Surveillance Training and Certification
View all events