The Digital Source For China's Tech Innovation Since 2000

Microsoft Flaw Found by Chinese Security Researcher

Chinese security researcher Liu Die Yu discovered and released details of new Microsoft Explorer 6 flaws on the Bugtraq mailing list. If the exploit is used on a computer, a cracker can download and execute a malicious file on a user's system.

Security professionals say that the only present fix is to disable MS Explorer's active scripting so that the feature can't be used to attack the machine.

Liu Die Yu also says that other minor flaws found can lead to a larger crack of a system.

Presently Microsoft is working on a fix and will make patches available soon.

Other China Tech Buzz:

CISA, the FBI, the ACSC, and the NCSC issue a joint advisory warning of an Iranian cyber campaign exploiting known vulnerabilities in Fortinet and Microsoft Exchange. A Belarusian connection to Ghostwriter. Candiru tools reported in watering holes. SideCopy’s interest in Afghanistan. RAMP shows an interest in attracting Chinese operators. Josh Ray from Accenture Security digs into the CONTI playbook leak. Our guest is Matt Keeley from Bishop Fox on fuzzing. And Pompompurin wants to sell you leaked Robinhood data.