{"id":14422,"date":"2023-02-10T15:13:59","date_gmt":"2023-02-10T20:13:59","guid":{"rendered":"https:\/\/tsisupport.com\/?p=14422"},"modified":"2023-04-15T09:54:09","modified_gmt":"2023-04-15T13:54:09","slug":"dont-let-the-recent-onenote-exploit-threaten-your-cybersecurity","status":"publish","type":"post","link":"https:\/\/tsisupport.com\/tsistaging\/?p=14422","title":{"rendered":"Don&#8217;t Let The Recent OneNote Exploit Threaten Your Cybersecurity"},"content":{"rendered":"<p style=\"font-weight: 400;\">We have noticed that malware threat actors have found an exploit within OneNote and we\u2019ve\u00a0observed a significant increase in the number of malicious files delivered and opened via OneNote email attachments.<\/p>\n<p style=\"font-weight: 400;\"><em>\u00a0<\/em>Unlike malicious Word and Excel files, OneNote malware and the associated infected files do not require the security prompt asking the end-user to allow macros, thus increasing the chances of unknowingly running the malicious executable.<\/p>\n<h2 style=\"font-weight: 400;\">\u00a0<strong>What you can do<\/strong><\/h2>\n<p style=\"font-weight: 400;\"><strong><em>\u00a0<\/em><\/strong>This vulnerability can be addressed by configuring your email to block these potentially malicious OneNote attachments \u2013 notably those with .one file extensions- and will only take a few minutes to apply this fix.<\/p>\n<p style=\"font-weight: 400;\">Here are\u00a0<a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/security\/office-365-security\/anti-malware-protection-about?view=o365-worldwide&amp;mkt_tok=ODQwLU9TUS02NjEAAAGJ0KQzTg8gqqiB4O5QTdEQdaSJpaTvYql9kUKTnhwfYk_jStMrDUsOy665_dBHWMzgKnwlspcT-llC3gAS7vpLXb2OhE4iYmpFFEpza0eC2AZ2Ig#anti-malware-policies\">more details about the issue.<\/a><\/p>\n<p style=\"font-weight: 400;\">As always, if you\u2019re an existing TSI client, please don\u2019t hesitate to reach out to your Account Manager at any time to help apply this fix or to learn more about this vulnerability- we\u2019re here to help!\u00a0 If you\u2019re not currently a TSI client, please share this security update with your IT support team or reach out to us at any time using the contact information below. Thank you for taking the time to read our notification and we look forward to providing any further updates as they arise.<\/p>\n<div class=\"fl-builder-content fl-builder-content-13857 fl-builder-template fl-builder-row-template fl-builder-global-templates-locked\" data-post-id=\"13857\"><div class=\"fl-row fl-row-full-width fl-row-bg-photo fl-node-ej4nhsmpruwa fl-row-default-height fl-row-align-center fl-row-bg-overlay sec-pad cta\" data-node=\"ej4nhsmpruwa\">\n\t<div class=\"fl-row-content-wrap\">\n\t\t\t\t\t\t\t\t<div class=\"fl-row-content fl-row-fixed-width fl-node-content\">\n\t\t\n<div class=\"fl-col-group fl-node-po9ljei370yq\" data-node=\"po9ljei370yq\">\n\t\t\t<div class=\"fl-col fl-node-ot3bs8xqau9e fl-col-bg-color\" data-node=\"ot3bs8xqau9e\">\n\t<div class=\"fl-col-content fl-node-content\"><div class=\"fl-module fl-module-heading fl-node-g4xtehoz1vqk sec-title-big\" data-node=\"g4xtehoz1vqk\">\n\t<div class=\"fl-module-content fl-node-content\">\n\t\t<h3 class=\"fl-heading\">\n\t\t<span class=\"fl-heading-text\">Get in Touch with TSI<\/span>\n\t<\/h3>\n\t<\/div>\n<\/div>\n<div class=\"fl-module fl-module-rich-text fl-node-n3cuvj09qsar\" data-node=\"n3cuvj09qsar\">\n\t<div class=\"fl-module-content fl-node-content\">\n\t\t<div class=\"fl-rich-text\">\n\t<p>For more information on Microsoft\u2019s CVE 2022 - 30190 MDST vulnerability or If you have any questions or concerns, please do not hesitate to give us a call at <a href=\"tel:508-543-6979\">508-543-6979<\/a> or send us a message here to get started.<\/p>\n<\/div>\n\t<\/div>\n<\/div>\n<div class=\"fl-module fl-module-button fl-node-4wvx6gcbomdt fl-animation fl-fade-down primary-btn red-btn\" data-node=\"4wvx6gcbomdt\" data-animation-delay=\"0\" data-animation-duration=\"1\">\n\t<div class=\"fl-module-content fl-node-content\">\n\t\t<div class=\"fl-button-wrap fl-button-width-auto fl-button-center\">\n\t\t\t<a href=\"https:\/\/tsisupport.com\/tsistaging\/contact\/\"  target=\"_self\"  class=\"fl-button\" >\n\t\t\t\t\t\t\t<span class=\"fl-button-text\">get in touch<\/span>\n\t\t\t\t\t<\/a>\n<\/div>\n\t<\/div>\n<\/div>\n<style>.fl-node-4wvx6gcbomdt.fl-animation:not(.fl-animated){opacity:0}<\/style><\/div>\n<\/div>\n\t<\/div>\n\t\t<\/div>\n\t<\/div>\n<\/div>\n<\/div><div class=\"uabb-js-breakpoint\" style=\"display: none;\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p>We have noticed that malware threat actors have found an exploit within OneNote and we\u2019ve\u00a0observed a significant increase in the number of malicious files delivered and opened via OneNote email attachments. \u00a0Unlike malicious Word and Excel files, OneNote malware and the associated infected files do not require the security prompt asking the end-user to allow&hellip;<\/p>\n","protected":false},"author":40,"featured_media":14434,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_links_to":"","_links_to_target":""},"categories":[20],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Don&#039;t Let The Recent OneNote Exploit Threaten Your Cybersecurity - TSI Support<\/title>\n<meta name=\"description\" content=\"Protect your cybersecurity from the recent OneNote security issue. Learn more about the threat and how to remediate it from TSI\u2019s IT and cybersecurity experts.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Don&#039;t Let The Recent OneNote Exploit Threaten Your Cybersecurity - TSI Support\" \/>\n<meta property=\"og:description\" content=\"Protect your cybersecurity from the recent OneNote security issue. Learn more about the threat and how to remediate it from TSI\u2019s IT and cybersecurity experts.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/tsisupport.com\/tsistaging\/?p=14422\" \/>\n<meta property=\"og:site_name\" content=\"TSI Support\" \/>\n<meta property=\"article:published_time\" content=\"2023-02-10T20:13:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-04-15T13:54:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2023\/02\/Dont-Let-The-Recent-OneNote-Exploit-Threaten-Your-Cybersecurity-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"715\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Chris Riani, CISSP &amp; CMMC Registered Practitioner\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Chris Riani, CISSP &amp; CMMC Registered Practitioner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=14422\",\"url\":\"https:\/\/tsisupport.com\/tsistaging\/?p=14422\",\"name\":\"Don't Let The Recent OneNote Exploit Threaten Your Cybersecurity - TSI Support\",\"isPartOf\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=14422#primaryimage\"},\"image\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=14422#primaryimage\"},\"thumbnailUrl\":\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2023\/02\/Dont-Let-The-Recent-OneNote-Exploit-Threaten-Your-Cybersecurity-1.png\",\"datePublished\":\"2023-02-10T20:13:59+00:00\",\"dateModified\":\"2023-04-15T13:54:09+00:00\",\"author\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/2ab31f44f09e232e313a6068278c98f8\"},\"description\":\"Protect your cybersecurity from the recent OneNote security issue. Learn more about the threat and how to remediate it from TSI\u2019s IT and cybersecurity experts.\",\"breadcrumb\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=14422#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/tsisupport.com\/tsistaging\/?p=14422\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=14422#primaryimage\",\"url\":\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2023\/02\/Dont-Let-The-Recent-OneNote-Exploit-Threaten-Your-Cybersecurity-1.png\",\"contentUrl\":\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2023\/02\/Dont-Let-The-Recent-OneNote-Exploit-Threaten-Your-Cybersecurity-1.png\",\"width\":1920,\"height\":715},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=14422#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/tsisupport.com\/tsistaging\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Don&#8217;t Let The Recent OneNote Exploit Threaten Your Cybersecurity\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#website\",\"url\":\"https:\/\/tsisupport.com\/tsistaging\/\",\"name\":\"TSI Support\",\"description\":\"TSI - Technical Support International\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/tsisupport.com\/tsistaging\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/2ab31f44f09e232e313a6068278c98f8\",\"name\":\"Chris Riani, CISSP &amp; CMMC Registered Practitioner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/6135092c12abc44dfda7e5a9dcad816a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/6135092c12abc44dfda7e5a9dcad816a?s=96&d=mm&r=g\",\"caption\":\"Chris Riani, CISSP &amp; CMMC Registered Practitioner\"},\"url\":\"https:\/\/tsisupport.com\/tsistaging\/?author=40\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Don't Let The Recent OneNote Exploit Threaten Your Cybersecurity - TSI Support","description":"Protect your cybersecurity from the recent OneNote security issue. Learn more about the threat and how to remediate it from TSI\u2019s IT and cybersecurity experts.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Don't Let The Recent OneNote Exploit Threaten Your Cybersecurity - TSI Support","og_description":"Protect your cybersecurity from the recent OneNote security issue. Learn more about the threat and how to remediate it from TSI\u2019s IT and cybersecurity experts.","og_url":"https:\/\/tsisupport.com\/tsistaging\/?p=14422","og_site_name":"TSI Support","article_published_time":"2023-02-10T20:13:59+00:00","article_modified_time":"2023-04-15T13:54:09+00:00","og_image":[{"width":1920,"height":715,"url":"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2023\/02\/Dont-Let-The-Recent-OneNote-Exploit-Threaten-Your-Cybersecurity-1.png","type":"image\/png"}],"author":"Chris Riani, CISSP &amp; CMMC Registered Practitioner","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Chris Riani, CISSP &amp; CMMC Registered Practitioner","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/tsisupport.com\/tsistaging\/?p=14422","url":"https:\/\/tsisupport.com\/tsistaging\/?p=14422","name":"Don't Let The Recent OneNote Exploit Threaten Your Cybersecurity - TSI Support","isPartOf":{"@id":"https:\/\/tsisupport.com\/tsistaging\/#website"},"primaryImageOfPage":{"@id":"https:\/\/tsisupport.com\/tsistaging\/?p=14422#primaryimage"},"image":{"@id":"https:\/\/tsisupport.com\/tsistaging\/?p=14422#primaryimage"},"thumbnailUrl":"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2023\/02\/Dont-Let-The-Recent-OneNote-Exploit-Threaten-Your-Cybersecurity-1.png","datePublished":"2023-02-10T20:13:59+00:00","dateModified":"2023-04-15T13:54:09+00:00","author":{"@id":"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/2ab31f44f09e232e313a6068278c98f8"},"description":"Protect your cybersecurity from the recent OneNote security issue. Learn more about the threat and how to remediate it from TSI\u2019s IT and cybersecurity experts.","breadcrumb":{"@id":"https:\/\/tsisupport.com\/tsistaging\/?p=14422#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/tsisupport.com\/tsistaging\/?p=14422"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/tsisupport.com\/tsistaging\/?p=14422#primaryimage","url":"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2023\/02\/Dont-Let-The-Recent-OneNote-Exploit-Threaten-Your-Cybersecurity-1.png","contentUrl":"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2023\/02\/Dont-Let-The-Recent-OneNote-Exploit-Threaten-Your-Cybersecurity-1.png","width":1920,"height":715},{"@type":"BreadcrumbList","@id":"https:\/\/tsisupport.com\/tsistaging\/?p=14422#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/tsisupport.com\/tsistaging\/"},{"@type":"ListItem","position":2,"name":"Don&#8217;t Let The Recent OneNote Exploit Threaten Your Cybersecurity"}]},{"@type":"WebSite","@id":"https:\/\/tsisupport.com\/tsistaging\/#website","url":"https:\/\/tsisupport.com\/tsistaging\/","name":"TSI Support","description":"TSI - Technical Support International","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/tsisupport.com\/tsistaging\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/2ab31f44f09e232e313a6068278c98f8","name":"Chris Riani, CISSP &amp; CMMC Registered Practitioner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/6135092c12abc44dfda7e5a9dcad816a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6135092c12abc44dfda7e5a9dcad816a?s=96&d=mm&r=g","caption":"Chris Riani, CISSP &amp; CMMC Registered Practitioner"},"url":"https:\/\/tsisupport.com\/tsistaging\/?author=40"}]}},"_links":{"self":[{"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/posts\/14422"}],"collection":[{"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/users\/40"}],"replies":[{"embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=14422"}],"version-history":[{"count":1,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/posts\/14422\/revisions"}],"predecessor-version":[{"id":14796,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/posts\/14422\/revisions\/14796"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/media\/14434"}],"wp:attachment":[{"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=14422"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=14422"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=14422"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}