Skip to main content

Now Microsoft Office is blocking macros by default

Image by Alex Castro / The Verge

There’s been a bit of back and forth since the change was originally announced, but this week Microsoft started rolling out an update to Microsoft Office that blocks the use of Visual Basic for Applications (VBA) macros on downloaded documents.

Last month, Microsft was testing the new default setting when it suddenly rolled back the update, “temporarily while we make some additional changes to enhance usability.” Despite saying it was temporary, many experts worried that Microsoft might not go through with changing the default setting, leaving systems vulnerable to attacks. Google Threat Analysis Group leader Shane Huntley tweeted, “Blocking Office macros would do infinitely more to actually defend against real threats than all the threat intel blog posts.”

Now the new default setting is rolling out, but with updated language to alert users and administrators what options they have when they try to open a file and it’s blocked. This only applies if Windows, using the NTFS file system, notes it as downloaded from the internet and not a network drive or site that admins have marked as safe, and it isn’t changing anything on other platforms like Mac, Office on Android / iOS, or Office on the web.

Microsoft:

We’re resuming the rollout of this change in Current Channel. Based on our review of customer feedback, we’ve made updates to both our end user and our IT admin documentation to make clearer what options you have for different scenarios. For example, what to do if you have files on SharePoint or files on a network share. Please refer to the following documentation:

• For end users, A potentially dangerous macro has been blocked

• For IT admins, Macros from the internet will be blocked by default in Office

If you ever enabled or disabled the Block macros from running in Office files from the Internet policy, your organization will not be affected by this change.

While some people use the scripts to automate tasks, hackers have abused the feature with malicious macros for years, tricking people into downloading a file and running it to compromise their systems. Microsoft noted how administrators could use Group Policy settings in Office 2016 to block macros across their organization’s systems. Still, not everyone turned it on, and the attacks continued, allowing hackers to steal data or distribute ransomware.

Users who try to open files and are blocked will get a pop-up sending them to this page, explaining why they probably don’t need to open that document. It starts by running through several scenarios where someone might try to trick them into executing malware. If they really do need to see what’s inside the downloaded file, it goes on to explain ways to get access, which are all more complicated than what happened before, where users could usually enable macros by pressing one button in the warning banner.

This change may not always stop someone from opening up a malicious file, but it does provide several more layers of warnings before they can get there while still providing access for the people that say they absolutely need it.



Source: The Verge

Popular posts from this blog

Apple Releases First Public Beta of tvOS 17

Apple today seeded the first beta of the upcoming tvOS 17 update to its public beta testing group, allowing the general public to download and test the update ahead of its September launch. Public beta testers can download the tvOS 17 beta by opening up the Settings app on Apple TV , choosing the Software Updates section under System, and then toggling on the Get Public Beta Updates option. Signing up on Apple's public beta website is also required. tvOS 17 adds FaceTime to the ‌Apple TV‌, with an iPhone or iPad serving as the camera. The ‌FaceTime‌ interface shows up on the bigger display of the TV, and Center Stage keeps you front and center as you move around the room. There's even a Split View option so you can use ‌FaceTime‌ while watching TV or playing a game on the other part of the screen. There's a revamped Control Center that makes it quicker to get to key settings and information without needing to go into the Settings app, plus it supports useful sho

Apple Releases macOS Ventura 13.4.1 With Security Fixes

Apple today released macOS Ventura 13.4, a minor update for the ‌macOS Ventura‌ operating system that was released last October. ‌macOS Ventura‌ 13.4.1 comes more than a month after the launch of macOS Ventura 13.4 . The ‌‌‌‌‌macOS Ventura‌‌‌‌‌ 13.4.1 update can be downloaded for free on all eligible Macs using the Software Update section of System Settings. According to Apple's release notes, the update provides important security fixes and is recommended for all users. Apple has also released macOS 11.7.8 and macOS 12.6.7 security updates for those who are unable to run Ventura. Related Roundup: macOS Ventura Related Forum: macOS Ventura This article, " Apple Releases macOS Ventura 13.4.1 With Security Fixes " first appeared on MacRumors.com Discuss this article in our forums Source: TechRadar

Apple Says 128GB iPhone 15 Pro Limited to 1080p ProRes Video Recording Unless External Storage Connected

ProRes video recording remains limited to 1080p quality at 30 frames per second on the 128GB model of the iPhone 15 Pro, unless the device is recording directly to a connected external storage drive , according to Apple. On the 256GB and higher iPhone 15 Pro and iPhone 15 Pro Max, ProRes video recording is supported in up to 4K quality at 60 frames per second to both internal storage and external storage. Apple does not mention this information on the iPhone 15 Pro's tech specs page on its website, but the limitation is listed when comparing the iPhone 15 Pro to another iPhone model in the Apple Store app, as seen in the screenshot below. The same limitation applied to iPhone 13 Pro and iPhone 14 Pro models with 128GB of storage, but those devices cannot record ProRes video to external storage, so at least iPhone 15 Pro users have that option this time around. The limitation does not apply to the iPhone 15 Pro Max, as that model starts with 256GB of storage. ProRes video fi

Hands-On With Volvo's Dual-Screen Apple Maps CarPlay Experience

A few months ago, Volvo and Polestar announced updates for their infotainment systems to support dual-screen Apple Maps displays from CarPlay , allowing a supplementary Apple Maps view to appear in the driver display separate from the main infotainment screen. While an increasing number of vehicles are supporting text-based ‌Apple Maps‌ navigation prompts in the driver display and/or head-up display, Volvo is one of the first to adopt a full map view on a second screen, and I recently had a chance to test it out in a 2024 S60 Recharge . The driver display ‌Apple Maps‌ screen is only active when there is a navigation route running in CarPlay , and it provides a familiar ‌Apple Maps‌ view with your vehicle position and your route, including upcoming traffic lights as well as surrounding streets, points of interest, and other features. At the bottom of the screen is a thin black box displaying your arrival time plus the time and distance remaining in the current trip. This second