Geekmaster 👽:system76: · @Geekmaster
191 followers · 1373 posts · Server ioc.exchange

Attackers have advanced their for leveraging the "search-ms" uniform resource identifier () from to direct users to websites that exploit -ms functionality using hosted on the page.

The search-ms protocol lets Windows users conduct search operations via a URI. Normally, it’s a operation, but if combined with another vulnerability such as within documents, can potentially use it as a part of a broader or campaign.

This attack requires at multiple layers of an organization’s defenses. First, properly leveraging email filters with URL rewriting and malicious content controls will limit the impact of a search-ms attack. Second, it relies on limited restrictions on outbound internet browsing — both at the firewall and internet proxy level. Once again, outbound controls are critical.

scmagazine.com/news/attackers-

Full blog post with technical details available here: trellix.com/en-us/about/newsro

#techniques #uri #protocol #malicious #documents #search #javascript #benign #windows #attackers #phishing #malware #gaps

Last updated 1 year ago

tom donald · @tomclearwood
486 followers · 754 posts · Server mastodon.scot

I enjoyed this blurb on the website where I reported racist graffiti to City Council:

"My Council Services offer a fully automated solution, where all your reports are directly loaded into your Citizen Management System. To comment on our service or to receive more information about how to offer more functionality to your citizen, please contact us... "

Who wouldn't want more functionality? I'm pro-functionality for yr citizens as long as we're all citizens


#phildickian #benign #glasgow

Last updated 1 year ago

Robin Forlonge Patterson · @RFPatterson
80 followers · 708 posts · Server mastodon.nz

I wonder whether I was the first man in to have a on my . (Result: .)

#newzealand #mammogram #80th #birthday #benign

Last updated 2 years ago