Skip to main content

Google employees discovered how to hack a corporate network just by sending an email

fireye exploit email network hacked dis
Image used with permission by copyright holder
What if, with a single email, an attacker could monitor all traffic on a supposedly protected network?

Researchers from Google’s Project Zero found, and silently reported, a bug in FireEye security software that allowed attackers to do just that. No, it’s a not a phishing scam. No one had to actually open the email. Just sending it was enough.

Recommended Videos

FireEye offers devices that scan all traffic flowing through a company’s network. If malware is detected in any transfer, the device intercepts the file and removes the malware.

Please enable Javascript to view this content

Project Zero demonstrated they could use this constant screening process against the software, turning it from a security feature into a bug that monitors all Internet traffic inside the company. Google employee Tavis Ormandy outlined the process in a blog post.

“For networks with deployed FireEye devices, a vulnerability that can be exploited via the passive monitoring interface would be a nightmare scenario,” wrote Ormandy, adding that such an exploit could let hackers passively monitor all traffic on a company’s network. He then outlined an exploit that does exactly that.

Read the entire post if you’re technically inclined — everything is laid out in detail. But don’t worry, FireEye has been notified of the problem, and given a chance to fix it before Google published the exploit for the entire world to read.

Google’s Project Zero team is charged with discovering, documenting, and silently reporting zero day exploits before malicious hackers do. The team researches not only potential security issues in Google services, but any software used by large groups of people.

When the team discovers a flaw in another company’s software, they report it silently so that patches can be developed and released. It’s only after everything is fixed that they make their discoveries public — or 90 days, whichever comes first. The team caused controversy in 2014, when Microsoft did not fix an exploit in Windows 8 within the 90-day Window.

Justin Pot
Former Digital Trends Contributor
Justin's always had a passion for trying out new software, asking questions, and explaining things – tech journalism is the…
Upgrade to this Samsung OLED gaming monitor while it’s $300 off
The Samsung Odyssey OLED G6 gaming monitor on a white background.

Upgrading your rig with gaming PC deals won't matter if you're still using an old screen. If budget permits, we highly recommend investing in a top-of-the-line display, such as the 27-inch Samsung Odyssey OLED G6. Originally $900, this gaming monitor is down to $650 from B&H Photo Video, for savings of $250. You can also clip a $50 coupon to drop it down to $600. You're going to want to hurry in completing this transaction though, as we're not sure how long stocks will last. Before more gamers discover and take advantage of this offer, push through with your purchase right now.

Why you should buy the 27-inch Samsung Odyssey OLED G6 gaming monitor
Samsung's Odyssey line is a fixture in our roundup of the best gaming monitors, which currently includes the Samsung Odyssey OLED G8 and Samsung Odyssey OLED G9. The Samsung Odyssey OLED G6, however, is also an excellent option for gamers. It all begins with Samsung's OLED technology, bringing it from OLED TVs to this gaming monitor for stunning visuals while you play the best PC games. The 27-inch screen also offers a 360 Hz refresh rate and 0.03 ms response time, eliminating lag and motion blur for a completely immersive experience, and 2560 x 1440 resolution for lifelike details and colors.

Read more
Windows 11 to finally address this webcam deficiency
Lenovo Yoga Slim 7x front view showing webcam.

The latest Windows 11 Insider Preview Build (26120.2702) was released a couple of days ago and it adds a new camera feature that probably should have been added ages ago. Once the build rolls out to all Windows 11 PCs, you'll be able to let multiple apps use your camera at the same time.

Microsoft says the reason it developed this feature is to "enable video streaming to both a sign language interpreter and the end audience at the same time" but users will surely find a range of uses for it.

Read more
I tried out Google’s latest AI tool that generates images in a fun, new way
Google's Whisk AI tool being used with images.

Google’s latest AI tool helps you automate image generation even further. The tool is called Whisk, and it's based on Google’s latest Imagen 3 image generation model. Rather than relying solely on text prompts, Whisk helps you create your desired images using other images as the base prompt.

Whisk is currently in an experimental phase, but once set up it's fairly easy to navigate. Google detailed in a blog post introducing Whisk that it is intended for “rapid visual exploration, not pixel-perfect edits.”

Read more