Kryptovaluta-ticker:
sysadmin fra Cyber Security News

7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen

Tushar Subhra Dutta
5 hours ago
6 Visninger
0 Kommentarer
7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen

Windows can protect users before a suspicious download runs. But a newly documented 7-Zip behavior can remove an important warning layer and allow a malicious program to start without a Windows SmartScreen prompt. ZIP archives are common in phishing campaigns. The gap grows when an archive looks like an invoice, update, or shared document. An attacker sends a link or attachment that leads to an archive, persuades the recipient to extract it with 7-Zip, then relies on the unmarked file being launched. This is not a newly disclosed exploit in 7-Zip code, but a security-control gap caused by the program’s default handling of download-origin metadata. Attackd analysts identified the behavior while testing phishing delivery...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!