Thursday, January 21, 2010

Microsoft releases patch for IE hole

SAN FRANCISCO — Microsoft on Thursday released a patch for an Internet Explorer 6 (IE 6) software hole through which China-based cyber spies attacked Google and other firms.

"Microsoft continues to see limited and targeted attacks against Internet Explorer 6 only," Jerry Bryant, senior security program manager at Microsoft, said in a statement.

"Microsoft recommends customers deploy this security update as soon as possible to protect themselves against the known attacks," he said.

Microsoft deemed the software fix so important that it veered from its usual protocol of releasing security updates the second Tuesday of each month.

Microsoft will host a public webcast starting at 1:00 pm Pacific time (21H00 GMT) on Thursday to discuss the security update and field questions.

Attacks that prompted a showdown between Internet giant Google and global power China only worked against IE 6, so computer users can protect themselves by switching to newer versions of the Web browser, according to Microsoft.

No matter which Web browser people use, upgrading to the most current version promises to increase protection against hackers.

Microsoft confirmed last week that a previously unknown security vulnerability in its IE 6 browser was used in cyberattacks which prompted Google to threaten to shut down its operations in China.

Revealing the attacks on January 12, Google said they originated from China and targeted the email accounts of Chinese human rights activists around the world but did not explicitly accuse the Chinese government of responsibility.

Web security firm McAfee Inc. said that the attacks on Google and other companies showed a level of sophistication beyond that of cyber criminals and more typical of a nation-state.

Google said more than 20 other unidentified firms were targeted in the "highly sophisticated" attacks while other reports have put the number of companies attacked at more than 30.

Only one other company, Adobe, has come forward so far and acknowledged that it was a target.

Attackers used email or some other lure to get employees of a targeted company to click on a link and visit a specially crafted website using Internet Explorer.

Malicious software would then be downloaded that has the capability to essentially install 'back doors' in machines and give hackers access.

No comments: