Tag Archive for: GIFs

Hackers can now sneak malware into the GIFs you share


How low will malware go to get onto your device? We thought using Minecraft to gain access to your computer was the most nefarious method hackers have produced, but there’s a new, even lower type of attack that uses Microsoft Teams and GIFs to mount phishing attacks on your computer.

The new attack is called GIFShell and it installs malware on your computer to steal data. It does so by sneaking itself into innocent-looking GIFs and then waiting for you to share the GIF with your colleagues via Microsoft Teams.

A video call in progress on Microsoft Teams.

The problem was discovered by cybersecurity expert Bobby Rauch, who shared his findings exclusively with Bleeping Computers. This new GIF attack exploits multiple vulnerabilities in Microsoft Teams to create a chain of command executions.

The only thing the attackers need is a way to get into Microsoft Teams in the first place, and they have settled on one of everyone’s favorite web items: GIFs. The attacks include malicious code in base64 encoded GIFs. They then use Microsoft’s own web infrastructure to unpack the commands and install them directly on your computer.

Microsoft Teams is fairly secure and has multiple levels of protection against malicious file sharing. However, GIFs are usually benign, and people love sharing them. They’re the perfect conduit for attacks.

The files can spoof your computer into opening Windows programs such as Excel. It can then send data back to its originator by tricking Windows into connecting to a remote server.

Rauch disclosed his findings to Microsoft in May 2022, but the company has yet to fix the flaws. Microsoft told Bleeping Computers the GIF attacks “do not meet the bar for an urgent security fix.”

The best thing you can do for now is to not open any GIFs someone may share with you on Teams. We’ll keep an eye on this story and let you know when, and if, Microsoft gets around to fixing the vulnerability.

Editors’ Recommendations




Source…

All your reaction GIFs now belong to Facebook, as it buys Giphy for $400M

Ironically, their logo is static, not animated.

Enlarge / Ironically, their logo is static, not animated. (credit: Giphy)

Seven years ago, Facebook claimed not to support the 21st century’s new favorite communication tool, the animated GIF. Oh, how times have changed: Today, Facebook’s newest acquisition is one of the Internet’s most popular GIF hosting sites.

Facebook is making Giphy part of the Instagram team, the company said today. Axios, which was first to report the transaction, said the deal was valued at about $ 400 million.

According to Facebook, about half of Giphy’s current traffic already comes from Facebook products, especially Instagram. That’s perhaps unsurprising, given that Facebook’s big three apps—WhatsApp, Instagram, and flagship Facebook—have literally billions of daily users among them.

Read 5 remaining paragraphs | Comments

Biz & IT – Ars Technica

GIFs for Mac Makes Sure You Always Have the Perfect Reaction GIF Handy

OS X: GIF is a simple, free app for the Mac that lets you search for the perfect GIF at the perfect time, get a link to paste it into a chat or email, or download it to your computer. If you communicate with GIFs (and honestly, who doesn’t at this point …
mac hacker – read more