A team of hackers based in Russia dubbed the “Sandworm Team” has been exploiting a vulnerability in Windows, Windows Server 2008, and Windows Server 2012 in order to spy on multiple public, and private institutions.
iSight, a security firm that is working in concert with Microsoft to track the hackers and plug such flaws, says that when someone uses it to penetrate Windows, they have the ability to “remotely execute arbitrary code.”
iSight also said that anyone trying to take advantage of a flaw to compromise a system would “need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it.”
Sandworm has used this flaw in Windows and Windows Server to hit the North Atlantic Treaty Organization, or NATO, along with government organizations based in Western Europe, parts of the Ukrainian government, energy companies in Poland, multiple European telecom firms, and academic organizations here at home as well.
To combat the group’s activities, Microsoft has released security fixes that are designed to fix the flaw. Users with Automatic Update enabled on their Windows PCs will download all patches without any input from them.
Digital Trends has contacted iSight to get more information on how to avoid any potential pitfalls associated with flaw that the Sandworm Team has been exploiting. We’ll issue any updates if and when we obtain information from iSight.
Related Posts
RTX 5060 Ti price drop finally makes sense for budget gaming pcs
Now that this SFF-ready RTX 5060 Ti is down to $332.99 (a 29% cut), the value finally lines up with what the card actually does. At this price, it becomes a genuinely interesting pick for a budget or midrange gaming pc, especially if you’re building in a smaller case.
Blue Yeti USB mic drops to $84.97 in early streaming gear deal
get the deal
Logitech just gave your wallet some good news
Faber said Logitech is done with major price increases for now, as its supply-chain tweaks have helped stabilize costs.