On Friday, October 21st, Google reported about the zero-day vulnerabilities to Microsoft and Adobe. Google publicly disclosed the critical Windows flaw, and because of that the two tech giants, Microsoft and Google were indulged in a verbal spat over the same. Microsoft was claiming that Google have given enough time to release the patch for the issue.
Google’s spokesperson has said that they have given enough time to Microsoft to find the solution for the issue a fix before the public disclosure of the Windows flaw. Hackers were already exploiting the privilege escalation bug by escaping Windows security sandboxing and exposing Flash Player flaws. Google closed the Flash exploits in Chrome as with an emergency fix last week, Adobe has patched the zero-day flaws in Flash.
Although, Microsoft has not issued any patch yet, it has scheduled to release its patch on November 8 to fix the Windows critical flaws. Google reported that hackers are behind the zero-day flaw vulnerabilities who want to trade on such flaws for their own profits. Microsoft reported on 2nd of November that the attacks were traced back to the Russian hacking group Strontium.
A few details about what is this hacking campaign?
Strontium is the group-code name for a Russian hacking group also known as Fancy Bear. The same group was blamed to be responsible the Democratic National Committee email hack by the U.S. intelligence officials. Washington put these allegations in line that the Russian government is making efforts to disrupt the upcoming 2016 U.S. elections. U.S. intelligence cybersecurity experts said that Strontium aka Fancy Bear works is association with the GRU (Glavnoye Razvedyvatel’noye Upravleniye) which is the military intelligence agency of the Russian Federation.
Microsoft tags and explains that Strontium/Fancy Bear is the group that is associated with more zero-day exploits than any other hacking group that tracked in 2016. Microsoft said, “STRONTIUM is the group that often uses compromised and hacked e-mail accounts to send infected and malicious e-mails from one victim to another victim and persistently pursue specific targets till the time they don’t get successful in compromising the target computer. Once they successfully gets inside, STRONTIUM gradually moves throughout the victim network, encroach itself as deeply as possible in order to get access to the victim’s computer and steals sensitive information.
To lead the recent Windows and Flash player exploit, the attacks were made using spear-phishing emails containing malicious links. Spear phishing is a term used for those hacking attempts where the aim of the hacker is to practice targeted email frauds aiming specifically at an organization or individual. Hackers send well-crafted emails that include identifiable personal data so that it look like as if emails are coming from trusted and legitimate sources. If hackers got successful in gaining your trust and you fall for the trap and open a malicious link or attachment, data theft software and spying malware may get installed on your machine or network that will leave you vulnerable to more attacks.
Phishing frauds/scams may be a real frightening experience for you, so it is essential that you keep yourself protected against such attempts. There are a few ways recommended below that Windows users may apply to protect themselves from latest zero-day attacks. As the latest zero-day attacks originate from a spear phishing campaign, so it is important that you don’t click on links in suspicious emails, don’t download unsolicited email attachments, especially from unknown sources. Don’t trust on every “official” emails that you receive from companies you don’t know and don’t do business with. Before following any instructions written in any email, verify its authenticity.
Windows 10 users are advised use Microsoft Edge running on the Windows 10 Anniversary Update until Microsoft doesn’t release patch for Windows flaws as these are believed to be protected from these attacks. Microsoft stated that users need to wait until the November 8 patch. Google encourages users to verify that auto-updaters have already updated Flash and if it not updated, update it manually. It also advised to the Windows users that apply Windows patches when Microsoft makes them available.
Otherwise, you have one more option to stop emerging zero-day attacks. Having the protection of potential security software can create a robust fence for the security of your computer and can keep you protected from latest and emerging internet threats like this Strontium/Fancy Bear campaign.
Like every other suite of software application, Windows also is not error free and has some flaws. Although Microsoft always try to fix the issue as soon as it is identified. If you are a Windows user and facing any problem, you can seek the help of certified technicians at PCTECH24.com.au at an affordable cost. Get the help at PCTECH24.com.au of Certified technicians who are 24*7 available.

























