Monday, December 30, 2024

Tech News, analysis, updates, comments, reviews

After some block and forth, Microsoft stops Office macros by default

Some attackers have used macros to corrupt Office files with ransomware.

The block is back.

Microsoft has disabled by default the oft-helpful, oft-malwared shortcuts known as macros. And it got confusing for a second. In February, Microsoft announced a block, then a rollback, then a clarification that the rollback was temporary, and now, finally, a rollout.

“To help improve security in Office, we’re changing the default behavior of Office applications to block macros in files from the internet,” according to a July 20 post from Microsoft.

Yay, macros! A macro is a small program or script, written in Visual Basic for Applications (VBA) and built to automate tasks in Office that would normally be done manually. With a macro, users can one-click their way through a number of efforts, like removing text wrap from an entire Excel spreadsheet, unmerging all merged cells, or saving a workbook with a time stamp in the name.

Nay, macros! Though macros can save time, they can also provide shortcuts for malware installation.

A Q1 2022 threat report from the managed detection and response provider Expel found that “threat actors used macro-enabled Word documents and zipped JavaScript files as the initial attack vector in 82% of all pre-ransomware incidents.” A February 2022 post from the software company Netskope revealed that 31% of all malware downloads blocked by the company were malicious Office files.

Now, according to the July 20 Microsoft post, macros from the internet will be blocked by default in Office, and when a reader opens a macro file, a security-risk warning will be displayed. While users are able to override the feature and enable macros if needed, the preselected setting is a step in the right direction, according to Roman Shain, information technology specialist at Nero Consulting.

“Microsoft is kind of helping everyone out in a way by saying, ‘Hey, look twice before crossing the street.’” Shain told IT Brew.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Get notified whenever we post something new!

spot_img

Migrate to the cloud

Make yourself future-proof by migrating your infrastructure and services to the cloud. Become resilient, efficient and distributed.

Continue reading

Salesforce Flaw Allows Full Account Takeover

A critical vulnerability has been discovered in Salesforce applications, which could potentially lead to a full account takeover. The flaw was identified during a penetration test and is tied to misconfigurations within Salesforce Communities, specifically within the Salesforce Lightning...

Concerns about the ICT Bill 2024 in Kenya

THis post has been updated after the attention it is gannering. The original post can be found here: https://web.archive.org/web/20240813033032/https://blog.blancorpsolutions.com/kenya/concerns-about-the-ict-bill-2024-in-kenya/ Kenya's tech industry has been a beacon of innovation and growth, thanks in part to a regulatory environment that has allowed...

What are the real intentions of tracking IMEI numbers?

Imagine if you had a magic map that could show you where all your favorite toys were at any time. Sounds pretty? Well, in Kenya, the government wants to do something similar, but with people’s phones. They plan to...

Enjoy exclusive discounts

Use the promo code SDBR002 to get amazing discounts to our software development services.