Sophos discovers new compromised websites that exploit the CVE-2012-1889 MSXML vulnerability An unpatched vulnerability in the Microsoft XML Core Services (MSXML) is being exploited in attacks launched from compromised websites to infect computers with malware, according to security researchers from antivirus vendor Sophos.One such attack was spotted Wednesday on the website of a European aeronautical parts supplier that had been hacked, Sophos senior technology consultant Graham Cluley said in a blog post. It follows a similar attack detected over the weekend on the compromised website of an European medical company, he said.Both compromised websites had rogue code injected into them that loaded an exploit for the CVE-2012-1889 MSXML vulnerability when accessed in Internet Explorer. SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe “A hacker who manages to plant malicious code on the website of, say, a company which supplies aeronautical parts may reasonably predict that staff at a larger organisation – such as an arms manufacturer or defence ministry – might have reason to access the site,” Cluley said. The MSXML vulnerability is believed to have been exploited in state-sponsored attacks against Gmail users earlier this month. Microsoft issued a security advisory about the flaw on June 12 and advised customers to apply one of several proposed work-arounds until a final security patch is released.Exploit code that works on all versions of Internet Explorer on Windows XP, Vista and 7 has been added to the Metasploit penetration testing framework. “We expect this vulnerability to grow even more dangerous since there’s no patch, and it’s rather easy to trigger,” the Metasploit developers said Monday in a blog post. Even though a patch is not yet available, Microsoft has released a “Fix it” solution that prevents the exploitation of this vulnerability in Internet Explorer. “We strongly suggest that you consider this workaround – for now,” Sophos senior threat researcher Paul Baccas said in a blog post on Tuesday. Related content feature Mastercard preps for the post-quantum cybersecurity threat A cryptographically relevant quantum computer will put everyday online transactions at risk. Mastercard is preparing for such an eventuality — today. By Poornima Apte Sep 22, 2023 6 mins CIO 100 CIO 100 CIO 100 feature 9 famous analytics and AI disasters Insights from data and machine learning algorithms can be invaluable, but mistakes can cost you reputation, revenue, or even lives. These high-profile analytics and AI blunders illustrate what can go wrong. By Thor Olavsrud Sep 22, 2023 13 mins Technology Industry Generative AI Machine Learning feature Top 15 data management platforms available today Data management platforms (DMPs) help organizations collect and manage data from a wide array of sources — and are becoming increasingly important for customer-centric sales and marketing campaigns. By Peter Wayner Sep 22, 2023 10 mins Marketing Software Data Management opinion Four questions for a casino InfoSec director By Beth Kormanik Sep 21, 2023 3 mins Media and Entertainment Industry Events Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe