WashingtonWeeklyTimes.com
  • Home
  • US News
    Sean Duffy calls Virginia bus crash driver’s lack of English ‘unacceptable’

    Sean Duffy calls Virginia bus crash driver’s lack of English ‘unacceptable’

    Has Iran Won the War? It Thinks So Update By Howard Bloom

    Has Iran Won the War? It Thinks So Update By Howard Bloom

    Five artists President Donald Trump should call to perform at Freedom 250 concert this summer

    Five artists President Donald Trump should call to perform at Freedom 250 concert this summer

    Charlamagne rips Jill Biden, Democrats for hiding Biden cognitive decline

    Charlamagne rips Jill Biden, Democrats for hiding Biden cognitive decline

    12-year-old boy drowns during school rafting trip in Pocono Mountains

    12-year-old boy drowns during school rafting trip in Pocono Mountains

  • Politics
    Trump Spends Friday Getting His Butt Kicked Everywhere In Court

    Trump Spends Friday Getting His Butt Kicked Everywhere In Court

    Has Iran Won the War? It Thinks So Update By Howard Bloom

    Has Iran Won the War? It Thinks So Update By Howard Bloom

    Democrats Are On The Verge Of Killing Trump’s Entire Senate Agenda

    Democrats Are On The Verge Of Killing Trump’s Entire Senate Agenda

    Power To The People Protest Festival Will Be The Final Pre-Midterm Nail In Trump’s Coffin

    Power To The People Protest Festival Will Be The Final Pre-Midterm Nail In Trump’s Coffin

  • Business
    America finally crushed smoking—then defunded the playbook

    America finally crushed smoking—then defunded the playbook

    Russia warns war costs are ravaging its finances as Ukrainian ‘drone overmatch’ halts Putin’s forces

    Russia warns war costs are ravaging its finances as Ukrainian ‘drone overmatch’ halts Putin’s forces

    Girls Who Code CEO: 70% of teen girls want to work in cybersecurity. We’re losing them before they start

    Girls Who Code CEO: 70% of teen girls want to work in cybersecurity. We’re losing them before they start

    What’s rarer than a unicorn? Anthropic is almost the first  trillion private company in history

    What’s rarer than a unicorn? Anthropic is almost the first $1 trillion private company in history

  • Science
    How the success of D-Day hinged on a weather forecast

    How the success of D-Day hinged on a weather forecast

    Aim high but don’t shoot for the moon, mathematicians advise

    Aim high but don’t shoot for the moon, mathematicians advise

    Blue Origin Rocket Explodes in Fiery Setback

    Blue Origin Rocket Explodes in Fiery Setback

    The Brain Circuit That Decides Where One Memory Ends and the Next Begins

    The Brain Circuit That Decides Where One Memory Ends and the Next Begins

  • Technology
    SpaceX awarded .45B in Space Force contracts ahead of IPO

    SpaceX awarded $6.45B in Space Force contracts ahead of IPO

    The Best Robotic Pool Cleaners of 2026: Beatbot, iGarden, Dreame

    The Best Robotic Pool Cleaners of 2026: Beatbot, iGarden, Dreame

    This chip startup just raised 5M on a bet that AI’s biggest bottleneck isn’t compute — it’s memory

    This chip startup just raised $135M on a bet that AI’s biggest bottleneck isn’t compute — it’s memory

    Bartesian Discount Codes: 35% Off

    Bartesian Discount Codes: 35% Off

  • Lifestyle
    14 Best Mother-Daughter Movies and TV Shows to Watch Together

    14 Best Mother-Daughter Movies and TV Shows to Watch Together

    Healthy Summer Meals a Nutritionist Actually Eats

    Healthy Summer Meals a Nutritionist Actually Eats

    30 Summer Bucket List Ideas for Your Most Magical Season Yet

    30 Summer Bucket List Ideas for Your Most Magical Season Yet

    Dress Code: Marlowe | FashionBeans

    Dress Code: Marlowe | FashionBeans

  • Music
    Trump Acknowledges Defeat in Kennedy Center Name Change

    Trump Acknowledges Defeat in Kennedy Center Name Change

    Watch Big Thief Debut Three Songs in an Irish Field

    Watch Big Thief Debut Three Songs in an Irish Field

    Tool, Twenty One Pilots, Alanis Morissette & More

    Tool, Twenty One Pilots, Alanis Morissette & More

    Nottingham’s Rock City issue statement after fire breaks out at iconic venue

    Nottingham’s Rock City issue statement after fire breaks out at iconic venue

  • Television
    ‘Miss You, Love You’ Stars Break Down the Dark Comedy’s Real-Life Inspiration (Exclusive)

    ‘Miss You, Love You’ Stars Break Down the Dark Comedy’s Real-Life Inspiration (Exclusive)

    5 Best True Crime Shows Of 2026 (So Far)

    5 Best True Crime Shows Of 2026 (So Far)

    Rivals Finally Went There With Declan and Cameron — And It Works

    Rivals Finally Went There With Declan and Cameron — And It Works

    Bosses Talk Kelly’s Death, What’s Next in Season 6 (Exclusive)

    Bosses Talk Kelly’s Death, What’s Next in Season 6 (Exclusive)

  • Film
    Red Dead Redemption 2 Free Download Officially Up For 48 More Hours

    Red Dead Redemption 2 Free Download Officially Up For 48 More Hours

    Hacks was always a love story

    Hacks was always a love story

    Havana Rose Liu Talks Processing Grief Through ‘Tuner’   

    Havana Rose Liu Talks Processing Grief Through ‘Tuner’   

    GTA 6 Unreal Loading Times Shown In Leaked Gameplay

    GTA 6 Unreal Loading Times Shown In Leaked Gameplay

  • Literature
    A Debut Novel That Exposes the Ugliness of American Subjectivity

    A Debut Novel That Exposes the Ugliness of American Subjectivity

    All of the 2026 Best Books of 2026 So Far Lists

    All of the 2026 Best Books of 2026 So Far Lists

    A Meaningful Chapter in a Continuing Story

    A Meaningful Chapter in a Continuing Story

    THE NEW YORKER Best Books of 2026 So Far

    THE NEW YORKER Best Books of 2026 So Far

    Literary Hub » Why the internet is re-litigating Belle Burden’s divorce.

    Literary Hub » Why the internet is re-litigating Belle Burden’s divorce.

    I Had a Neighbor Whose Husband Constantly Shouted

    I Had a Neighbor Whose Husband Constantly Shouted

    The Best New Books Out in June, According to Indie Booksellers

    The Best New Books Out in June, According to Indie Booksellers

    Literary Hub » How Medieval Doctors, Christian and Muslim, Treated the Black Death

    Literary Hub » How Medieval Doctors, Christian and Muslim, Treated the Black Death

    Angel, Those Wings Look Ridiculous on You

    Angel, Those Wings Look Ridiculous on You

  • Contact
    • About
  • Home
  • US News
    Sean Duffy calls Virginia bus crash driver’s lack of English ‘unacceptable’

    Sean Duffy calls Virginia bus crash driver’s lack of English ‘unacceptable’

    Has Iran Won the War? It Thinks So Update By Howard Bloom

    Has Iran Won the War? It Thinks So Update By Howard Bloom

    Five artists President Donald Trump should call to perform at Freedom 250 concert this summer

    Five artists President Donald Trump should call to perform at Freedom 250 concert this summer

    Charlamagne rips Jill Biden, Democrats for hiding Biden cognitive decline

    Charlamagne rips Jill Biden, Democrats for hiding Biden cognitive decline

    12-year-old boy drowns during school rafting trip in Pocono Mountains

    12-year-old boy drowns during school rafting trip in Pocono Mountains

  • Politics
    Trump Spends Friday Getting His Butt Kicked Everywhere In Court

    Trump Spends Friday Getting His Butt Kicked Everywhere In Court

    Has Iran Won the War? It Thinks So Update By Howard Bloom

    Has Iran Won the War? It Thinks So Update By Howard Bloom

    Democrats Are On The Verge Of Killing Trump’s Entire Senate Agenda

    Democrats Are On The Verge Of Killing Trump’s Entire Senate Agenda

    Power To The People Protest Festival Will Be The Final Pre-Midterm Nail In Trump’s Coffin

    Power To The People Protest Festival Will Be The Final Pre-Midterm Nail In Trump’s Coffin

  • Business
    America finally crushed smoking—then defunded the playbook

    America finally crushed smoking—then defunded the playbook

    Russia warns war costs are ravaging its finances as Ukrainian ‘drone overmatch’ halts Putin’s forces

    Russia warns war costs are ravaging its finances as Ukrainian ‘drone overmatch’ halts Putin’s forces

    Girls Who Code CEO: 70% of teen girls want to work in cybersecurity. We’re losing them before they start

    Girls Who Code CEO: 70% of teen girls want to work in cybersecurity. We’re losing them before they start

    What’s rarer than a unicorn? Anthropic is almost the first  trillion private company in history

    What’s rarer than a unicorn? Anthropic is almost the first $1 trillion private company in history

  • Science
    How the success of D-Day hinged on a weather forecast

    How the success of D-Day hinged on a weather forecast

    Aim high but don’t shoot for the moon, mathematicians advise

    Aim high but don’t shoot for the moon, mathematicians advise

    Blue Origin Rocket Explodes in Fiery Setback

    Blue Origin Rocket Explodes in Fiery Setback

    The Brain Circuit That Decides Where One Memory Ends and the Next Begins

    The Brain Circuit That Decides Where One Memory Ends and the Next Begins

  • Technology
    SpaceX awarded .45B in Space Force contracts ahead of IPO

    SpaceX awarded $6.45B in Space Force contracts ahead of IPO

    The Best Robotic Pool Cleaners of 2026: Beatbot, iGarden, Dreame

    The Best Robotic Pool Cleaners of 2026: Beatbot, iGarden, Dreame

    This chip startup just raised 5M on a bet that AI’s biggest bottleneck isn’t compute — it’s memory

    This chip startup just raised $135M on a bet that AI’s biggest bottleneck isn’t compute — it’s memory

    Bartesian Discount Codes: 35% Off

    Bartesian Discount Codes: 35% Off

  • Lifestyle
    14 Best Mother-Daughter Movies and TV Shows to Watch Together

    14 Best Mother-Daughter Movies and TV Shows to Watch Together

    Healthy Summer Meals a Nutritionist Actually Eats

    Healthy Summer Meals a Nutritionist Actually Eats

    30 Summer Bucket List Ideas for Your Most Magical Season Yet

    30 Summer Bucket List Ideas for Your Most Magical Season Yet

    Dress Code: Marlowe | FashionBeans

    Dress Code: Marlowe | FashionBeans

  • Music
    Trump Acknowledges Defeat in Kennedy Center Name Change

    Trump Acknowledges Defeat in Kennedy Center Name Change

    Watch Big Thief Debut Three Songs in an Irish Field

    Watch Big Thief Debut Three Songs in an Irish Field

    Tool, Twenty One Pilots, Alanis Morissette & More

    Tool, Twenty One Pilots, Alanis Morissette & More

    Nottingham’s Rock City issue statement after fire breaks out at iconic venue

    Nottingham’s Rock City issue statement after fire breaks out at iconic venue

  • Television
    ‘Miss You, Love You’ Stars Break Down the Dark Comedy’s Real-Life Inspiration (Exclusive)

    ‘Miss You, Love You’ Stars Break Down the Dark Comedy’s Real-Life Inspiration (Exclusive)

    5 Best True Crime Shows Of 2026 (So Far)

    5 Best True Crime Shows Of 2026 (So Far)

    Rivals Finally Went There With Declan and Cameron — And It Works

    Rivals Finally Went There With Declan and Cameron — And It Works

    Bosses Talk Kelly’s Death, What’s Next in Season 6 (Exclusive)

    Bosses Talk Kelly’s Death, What’s Next in Season 6 (Exclusive)

  • Film
    Red Dead Redemption 2 Free Download Officially Up For 48 More Hours

    Red Dead Redemption 2 Free Download Officially Up For 48 More Hours

    Hacks was always a love story

    Hacks was always a love story

    Havana Rose Liu Talks Processing Grief Through ‘Tuner’   

    Havana Rose Liu Talks Processing Grief Through ‘Tuner’   

    GTA 6 Unreal Loading Times Shown In Leaked Gameplay

    GTA 6 Unreal Loading Times Shown In Leaked Gameplay

  • Literature
    A Debut Novel That Exposes the Ugliness of American Subjectivity

    A Debut Novel That Exposes the Ugliness of American Subjectivity

    All of the 2026 Best Books of 2026 So Far Lists

    All of the 2026 Best Books of 2026 So Far Lists

    A Meaningful Chapter in a Continuing Story

    A Meaningful Chapter in a Continuing Story

    THE NEW YORKER Best Books of 2026 So Far

    THE NEW YORKER Best Books of 2026 So Far

    Literary Hub » Why the internet is re-litigating Belle Burden’s divorce.

    Literary Hub » Why the internet is re-litigating Belle Burden’s divorce.

    I Had a Neighbor Whose Husband Constantly Shouted

    I Had a Neighbor Whose Husband Constantly Shouted

    The Best New Books Out in June, According to Indie Booksellers

    The Best New Books Out in June, According to Indie Booksellers

    Literary Hub » How Medieval Doctors, Christian and Muslim, Treated the Black Death

    Literary Hub » How Medieval Doctors, Christian and Muslim, Treated the Black Death

    Angel, Those Wings Look Ridiculous on You

    Angel, Those Wings Look Ridiculous on You

  • Contact
    • About
No Result
View All Result
WashingtonWeeklyTimes.com
No Result
View All Result
Home Technology

Microsoft Follina Vulnerability in Windows Can Be Exploited Through Office 365

by Admin
June 3, 2022
in Technology
Microsoft Follina Vulnerability in Windows Can Be Exploited Through Office 365


Researchers warned last weekend that a flaw in Microsoft’s Support Diagnostic Tool could be exploited using malicious Word documents to remotely take control of target devices. Microsoft released guidance on Monday, including temporary defense measures. By Tuesday, the United States Cybersecurity and Infrastructure Security Agency had warned that “a remote, unauthenticated attacker could exploit this vulnerability,” known as Follina, “to take control of an affected system.” But Microsoft would not say when or whether a patch is coming for the vulnerability, even though the company acknowledged that the flaw was being actively exploited by attackers in the wild. And the company still had no comment about the possibility of a patch when asked by WIRED yesterday.

The Follina vulnerability in a Windows support tool can be easily exploited by a specially crafted Word document. The lure is outfitted with a remote template that can retrieve a malicious HTML file and ultimately allow an attacker to execute Powershell commands within Windows. Researchers note that they would describe the bug as a “zero-day,” or previously unknown vulnerability, but Microsoft has not classified it as such.

“After public knowledge of the exploit grew, we began seeing an immediate response from a variety of attackers beginning to use it,” says Tom Hegel, senior threat researcher at security firm SentinelOne. He adds that while attackers have primarily been observed exploiting the flaw through malicious documents thus far, researchers have discovered other methods as well, including the manipulation of HTML content in network traffic.

 “While the malicious document approach is highly concerning, the less documented methods by which the exploit can be triggered are troubling until patched,” Hegel says. “I would expect opportunistic and targeted threat actors to use this vulnerability in a variety of ways when the option is available—it’s just too easy.” 

The vulnerability is present in all supported versions of Windows and can be exploited through Microsoft Office 365, Office 2013 through 2019, Office 2021, and Office ProPlus. Microsoft’s main proposed mitigation involves disabling a specific protocol within Support Diagnostic Tool and using Microsoft Defender Antivirus to monitor for and block exploitation. 

But incident responders say that more action is needed, given how easy it is to exploit the vulnerability and how much malicious activity is being detected. 

“We are seeing a variety of APT actors incorporate this technique into longer infection chains that utilize the Follina vulnerability,” says Michael Raggi, a staff threat researcher at the security firm Proofpoint who focuses on Chinese government-backed hackers. “For instance, on May 30, 2022, we observed Chinese APT actor TA413 send a malicious URL in an email which impersonated the Central Tibetan Administration. Different actors are slotting in the Follina-related files at different stages of their infection chain, depending on their preexisting toolkit and deployed tactics.”

Researchers have also seen malicious documents exploiting Follina with targets in Russia, India, the Philippines, Belarus, and Nepal. An undergraduate researcher first noticed the flaw in August 2020, but it was first reported to Microsoft on April 21. Researchers also noted that Follina hacks are particularly useful to attackers because they can stem from malicious documents without relying on Macros, the much-abused Office document feature that Microsoft has worked to rein in.

“Proofpoint has identified a variety of actors incorporating the Follina vulnerability within phishing campaigns,” says Sherrod DeGrippo, Proofpoint’s vice president of threat research.

With all this real-world exploitation, the question is whether the guidance Microsoft has published so far is adequate and proportionate to the risk. 

“Security teams could view Microsoft’s nonchalant approach as a sign that this is ‘just another vulnerability,’ which it most certainly is not,” says Jake Williams, director of cyber threat intelligence at the security firm Scythe. “It’s not clear why Microsoft continues to downplay this vulnerability, especially while it’s being actively exploited in the wild.”





Original Source Link

Previous Post

Miscarriage: How losing access to abortion will affect treatment for pregnancy loss

Next Post

Inside the Race to Save Ukraine’s Greatest Treasures – Tug of War

Admin

Admin

Next Post
Inside the Race to Save Ukraine’s Greatest Treasures – Tug of War

Inside the Race to Save Ukraine’s Greatest Treasures - Tug of War

1/6 Committee To Use First Televised Hearing To Shock Nation With ‘Mountain of New Evidence’

1/6 Committee To Use First Televised Hearing To Shock Nation With 'Mountain of New Evidence'

The Great Resignation resulted in women leaving the workforce in droves. Denying them abortion care could dent the labor market

The Great Resignation resulted in women leaving the workforce in droves. Denying them abortion care could dent the labor market

PopularPosts

Nevada judge retires amid stalking accusations after court grants protective order

Nevada judge retires amid stalking accusations after court grants protective order

January 23, 2026
Virtual Moon Walking The Next Giant Leap For Astronaut Training

Virtual Moon Walking The Next Giant Leap For Astronaut Training

April 15, 2025
‘Cities: Skylines II’ Found a Solution for High Rents: Get Rid of Landlords

‘Cities: Skylines II’ Found a Solution for High Rents: Get Rid of Landlords

June 15, 2024
Mo Ostin, Longtime Warner Bros. and Reprise Records Chief, Dies at 95

Mo Ostin, Longtime Warner Bros. and Reprise Records Chief, Dies at 95

August 2, 2022
‘SNL’ Video, Beetlejuice, Andy Samberg, Michal Keaton Monologue

‘SNL’ Video, Beetlejuice, Andy Samberg, Michal Keaton Monologue

October 20, 2024
One star being eaten by another will take revenge as a black hole

One star being eaten by another will take revenge as a black hole

April 27, 2023

Categories

  • Business (7,458)
  • Events (10)
  • Film (7,389)
  • Lifestyle (5,290)
  • Literature (5,503)
  • Music (7,440)
  • Politics (7,265)
  • Science (6,830)
  • Technology (7,383)
  • Television (7,450)
  • Uncategorized (6)
  • US News (7,489)

RecentPosts

How the success of D-Day hinged on a weather forecast

How the success of D-Day hinged on a weather forecast

by
May 30, 2026

If it weren’t for a weather forecast, D-Day—the largest seaborne...

Red Dead Redemption 2 Free Download Officially Up For 48 More Hours

Red Dead Redemption 2 Free Download Officially Up For 48 More Hours

by
May 30, 2026

It may not have received the same love as Grand...

‘Miss You, Love You’ Stars Break Down the Dark Comedy’s Real-Life Inspiration (Exclusive)

‘Miss You, Love You’ Stars Break Down the Dark Comedy’s Real-Life Inspiration (Exclusive)

by
May 30, 2026

Jim Rash is packing an emotional punch with his latest...

A Debut Novel That Exposes the Ugliness of American Subjectivity

A Debut Novel That Exposes the Ugliness of American Subjectivity

by
May 30, 2026

Bobuq Sayed’s début, No God but Us, reinvents the modern...

Trump Acknowledges Defeat in Kennedy Center Name Change

Trump Acknowledges Defeat in Kennedy Center Name Change

by
May 30, 2026

Donald Trump rarely admits defeat, but he appears to be...

America finally crushed smoking—then defunded the playbook

America finally crushed smoking—then defunded the playbook

by
May 30, 2026

The cigarette smoking rate among U.S. adults dropped to another...

Archives

Editor's Picks

Mathematical AI helps researchers crack 50-year-old problem

Mathematical AI helps researchers crack 50-year-old problem

May 29, 2026
NCIS Boss Credits This Actor With Saving The Show When Mark Harmon Quit

NCIS Boss Credits This Actor With Saving The Show When Mark Harmon Quit

May 26, 2026
Bosses Talk Kelly’s Death, What’s Next in Season 6 (Exclusive)

Bosses Talk Kelly’s Death, What’s Next in Season 6 (Exclusive)

May 29, 2026

Browse By Category

  • Business (7,458)
  • Events (10)
  • Film (7,389)
  • Lifestyle (5,290)
  • Literature (5,503)
  • Music (7,440)
  • Politics (7,265)
  • Science (6,830)
  • Technology (7,383)
  • Television (7,450)
  • Uncategorized (6)
  • US News (7,489)

Useful Links

  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Earnings Disclaimer
  • Fair Use Disclaimer
  • FTC Compliance
  • Medical Disclaimer
  • Privacy Policy
  • Social Media Disclaimer
  • Terms and Conditions

Copyright © 2022 by Washington Weekly Times. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms of Use and Privacy Policy.

No Result
View All Result
  • Home
  • US News
  • Politics
  • Business
  • Science
  • Technology
  • Lifestyle
  • Music
  • Television
  • Film
  • Literature
  • Contact
    • About

Copyright © 2022 by Washington Weekly Times. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms of Use and Privacy Policy.

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT