Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Microsoft is searching within your secure folders for malware, even if you have a password

  • May 16, 2023
Total
0
Shares
0
0
0


Microsoft has reportedly started scanning password-protected .ZIP archives for malware (opens in new tab), and not everyone is happy about the decision.

Ars Technica reported several users on Mastodon, including cybersecurity researchers, confirmed that Microsoft’s antivirus program had started scanning .ZIP archives for malicious content, even those protected by a password. 

Password-protected .ZIP archives are one of the most popular tactics among cybercriminals looking to deploy malware via email, as email security services rarely flag them.

“Nosy practices”

The publication claims that the practice was “well-known to some people”, but came as a surprise to others. Cybersecurity researcher Andrew Brandt, for example, wasn’t too thrilled about the idea, as it made it difficult for him to share malware with his fellow researchers through SharePoint.

“While I totally understand doing this for anyone other than a malware analyst, this kind of nosy, get-inside-your-business way of handling this is going to become a big problem for people like me who need to send their colleagues malware samples,” Brandt wrote. “The available space to do this just keeps shrinking and it will impact the ability of malware researchers to do their jobs.”

Another researcher, Kevin Beaumont, said the company scans files not just stored in SharePoint, but everywhere in its Microsoft 365 cloud services, adding that there are multiple methods of peeking into password-protected archives. One way, it seems, is to scan the contents of the email itself, for potential passwords. Sometimes, people mailing .ZIP archives to one another will share the password in the body of the email.

“If you mail yourself something and type something like ‘ZIP password is Soph0s’, ZIP up EICAR and ZIP password it with Soph0s, it’ll find (the) password, extract and find,” he wrote.

While this might come as a surprise to some people, Ars Technica reminds that password-protected .ZIP files “provide minimal assurance” that an unauthorized third-party will read the contents. “The default means for encrypting zip files in Windows, is trivial to override. A more dependable way is to use an AES-256 encryptor built into many archive programs when creating 7z files,” the report concludes.

Via: Ars Technica (opens in new tab)


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

Hippocratic is building a large language model for healthcare

  • May 16, 2023
View Post
Next Article
  • Technology

Bumble users can share their favorite artists with new Spotify feature

  • May 16, 2023
View Post
You May Also Like
View Post
  • News

WWDC 2023: the 3 big reveals we need from Apple

  • June 4, 2023
View Post
  • News

GTA 5 took 10 years to introduce this feature and we’re so pleased it’s finally here

  • June 4, 2023
View Post
  • News

This new Steam update will show you the lowest price a game has sold for in the last 30 days

  • June 4, 2023
View Post
  • News

This Google Workspace security flaw could let hackers quietly steal your Drive files

  • June 4, 2023
View Post
  • News

Apple rumored to be announcing major Siri updates at WWDC 2023

  • June 4, 2023
View Post
  • News

These Activists Distrust Voting Machines. Just Don’t Call Them Election Deniers.

  • June 4, 2023
View Post
  • News

Quordle today – hints and answers for Sunday, June 4 (game #496)

  • June 4, 2023
View Post
  • News

Diablo 4’s authentication servers are down, preventing players from logging in

  • June 3, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.