Microsoft has announced a significant security policy change, decreeing that users will soon no longer be able to activate VBA macros in certain documents from five of its most popular Office apps.
When it finally pulls the plug, users will no longer be able to run any VBA macros in Microsoft Word, Excel, Access, PowerPoint and Visio, for “untrusted” documents.
It seems that all files shared from outside the company network will be deemed “untrusted”, meaning all files coming from the same domain should still be able to keep their macros.
[HEADING=1]Macros - a super-useful liability[/HEADING]
Macros are a big deal, for both businesses, and cybercriminals.
They are usually used to automate various tasks, such as importing or updating data coming from third-party sources. But the problem is that they can easily be abused by malicious actors to distribute ransomware, malware, steal sensitive data, or for other nefarious deeds.
For years, cybercrime groups have been sharing macro-powered malicious Office documents, preying on gullible or exhausted workers. Payment receipts, warnings of failed payments, job offers, Covid-19 and vaccine information, are just some of the document types crooks would share to have people run macros and infect their endpoints.
Read more
Microsoft has tried to tackle the issue with a tentative solution - to disable the macros in downloaded files by default, and to leave the user with the option of activating it or not.
However, as most people are not aware of the reason behind Microsoft’s decision to disable macros by default, they often end up enabling them after all.
Now, after years of pleads by various cybersecurity firms and experts, Microsoft has finally bit the bullet and gone for the extreme option of killing macros altogether.
The change is set to start in early April 2022, with Microsoft Office version 2203, which will be the public preview version.
[ul]
[li]You might also want to check out our list of the best malware removal software right now[/li][/ul]
Via: The Record
Continue reading…
When it finally pulls the plug, users will no longer be able to run any VBA macros in Microsoft Word, Excel, Access, PowerPoint and Visio, for “untrusted” documents.
It seems that all files shared from outside the company network will be deemed “untrusted”, meaning all files coming from the same domain should still be able to keep their macros.
[HEADING=1]Macros - a super-useful liability[/HEADING]
Macros are a big deal, for both businesses, and cybercriminals.
They are usually used to automate various tasks, such as importing or updating data coming from third-party sources. But the problem is that they can easily be abused by malicious actors to distribute ransomware, malware, steal sensitive data, or for other nefarious deeds.
For years, cybercrime groups have been sharing macro-powered malicious Office documents, preying on gullible or exhausted workers. Payment receipts, warnings of failed payments, job offers, Covid-19 and vaccine information, are just some of the document types crooks would share to have people run macros and infect their endpoints.
Read more
Microsoft to disable old-school macros to shield users from attacks
Microsoft Excel is making a big change to protect against malware
Hackers are weaponizing Excel documents to infiltrate corporate networks
However, as most people are not aware of the reason behind Microsoft’s decision to disable macros by default, they often end up enabling them after all.
Now, after years of pleads by various cybersecurity firms and experts, Microsoft has finally bit the bullet and gone for the extreme option of killing macros altogether.
The change is set to start in early April 2022, with Microsoft Office version 2203, which will be the public preview version.
[ul]
[li]You might also want to check out our list of the best malware removal software right now[/li][/ul]
Via: The Record
Continue reading…