Share

Hacking group targets Windows, Adobe Flash

accreditation

Seattle - Microsoft Corp. said a computer-hacking group that has previously targeted government agencies attacked its Windows software and Adobe Systems Inc.’s Flash program.

The company will release a security patch for its operating system on Novomber 8, Windows chief Terry Myerson said on Tuesday in a blog post on Microsoft’s website.

Users of Microsoft’s Edge browser on the latest update to Windows 10 are protected from the flaw, the company said.

The security exploit, by a group Microsoft calls Strontium, was discovered by Google’s Threat Analysis Group and announced on Monday.

The attacks, which sought to take control of a user’s computer, took advantage of so-called zero-day flaws, or security holes that are unknown to the product’s vendor and therefore no patch has yet been developed.

"Strontium is an activity group that usually targets government agencies, diplomatic institutions, and military organizations, as well as affiliated private sector organizations such as defense contractors and public policy research institutes," according to the Microsoft blog.

"Microsoft has attributed more 0-day exploits to Strontium than any other tracked group in 2016."

The group is also known as Fancy Bear and APT 28 and has been previously linked to the Russian government and U.S. political hacks, Reuters reported.

Google’s Disclosure

In a blog post on Monday, Google said it reported the issue to Adobe and Microsoft on Oct. 21, and Adobe updated Flash five days later.

The internet-search giant, a unit of Alphabet Inc., said its policy is to disclose actively exploited security vulnerabilities after seven days.

Still, Microsoft expressed displeasure with Google for announcing the hack before a patch for Windows was available.

"Responsible technology industry participation puts the customer first, and requires coordinated vulnerability disclosure," Myerson wrote in the blog.

"Google’s decision to disclose these vulnerabilities before patches are broadly available and tested is disappointing, and puts customers at increased risk."

Read Fin24's top stories trending on Twitter:

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.21
-0.5%
Rand - Pound
23.95
-0.7%
Rand - Euro
20.56
-0.5%
Rand - Aus dollar
12.48
-0.7%
Rand - Yen
0.12
-0.2%
Platinum
912.40
-0.8%
Palladium
1,005.00
-2.1%
Gold
2,314.58
-0.3%
Silver
27.17
-0.5%
Brent Crude
88.42
+1.6%
Top 40
68,574
+0.8%
All Share
74,514
+0.7%
Resource 10
60,444
+1.4%
Industrial 25
104,013
+1.2%
Financial 15
15,837
-0.4%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders