Escaping the Black Hole: Engineering ML Pipelines That Defy Data Gravity
For years, we’ve heard the mantra that data is the new oil, a valuable resource to be extracted and refined. But any IT director managing a growing...
1 min read
Heroic Technologies : Updated on August 5, 2025
You may not know the name Matthew Hickey, but you should thank him for a recent discovery that could save you a lot of grief.
Hickey is the co-founder of a company called Hacker House. He recently discovered a flaw that could allow for the opening of a remote search window simply by opening a Word or RTF document.
This newly discovered zero-day vulnerability is about as serious as it gets.
Here’s how it works:
A specially crafted Word Document or RTF is created which, when launched, will automatically launch a “search-MS” command, which opens a Windows Search window.
This window lists executable files on a remote share and the share can be given any name the attacker desires such as “Critical Updates” and the like. That would naturally prompt an unsuspecting user to click the file name to run that file.
Naturally, clicking the file name wouldn’t do anything other than install malware, which is exactly what the hackers are trying to do.
Although not quite as dangerous as the MS-MSDT remote code execution security flaw, this one is still incredibly serious. Even worse, there is not currently a patch that will make your system safer.
The good news however, is that there are steps you can take to minimize your risks.
Kudos to the sharp eyes of Matthew Hickey for first spotting this flaw. We can only hope when the next zero-day rears its head, researchers like Mr. Hickey will be there to help point them out and show us how to defeat them.
For years, we’ve heard the mantra that data is the new oil, a valuable resource to be extracted and refined. But any IT director managing a growing...
If you run a business in Portland, there is a good chance you have felt at least one of these in the last year:
The OCPA is Here to Stay: What Portland Businesses Need to Know in 2026 When the Oregon Consumer Privacy Act (OCPA) first went into effect in July...
Microsoft recently announced that it was doing a bit of re-branding.
Are you a OneDrive user running Windows 7, Windows 8, or Windows 8.1? If so be aware that on January 1st, 2022 your OneDrive desktop application will...
Are you excited at the prospect of Windows 11? If so then you will be pleased to know that Microsoft’s latest OS now has an official release date....