Skip to main content

Google employees discovered how to hack a corporate network just by sending an email

fireye exploit email network hacked dis
Image used with permission by copyright holder
What if, with a single email, an attacker could monitor all traffic on a supposedly protected network?

Researchers from Google’s Project Zero found, and silently reported, a bug in FireEye security software that allowed attackers to do just that. No, it’s a not a phishing scam. No one had to actually open the email. Just sending it was enough.

FireEye offers devices that scan all traffic flowing through a company’s network. If malware is detected in any transfer, the device intercepts the file and removes the malware.

Project Zero demonstrated they could use this constant screening process against the software, turning it from a security feature into a bug that monitors all Internet traffic inside the company. Google employee Tavis Ormandy outlined the process in a blog post.

“For networks with deployed FireEye devices, a vulnerability that can be exploited via the passive monitoring interface would be a nightmare scenario,” wrote Ormandy, adding that such an exploit could let hackers passively monitor all traffic on a company’s network. He then outlined an exploit that does exactly that.

Read the entire post if you’re technically inclined — everything is laid out in detail. But don’t worry, FireEye has been notified of the problem, and given a chance to fix it before Google published the exploit for the entire world to read.

Google’s Project Zero team is charged with discovering, documenting, and silently reporting zero day exploits before malicious hackers do. The team researches not only potential security issues in Google services, but any software used by large groups of people.

When the team discovers a flaw in another company’s software, they report it silently so that patches can be developed and released. It’s only after everything is fixed that they make their discoveries public — or 90 days, whichever comes first. The team caused controversy in 2014, when Microsoft did not fix an exploit in Windows 8 within the 90-day Window.

Editors' Recommendations

Justin Pot
Former Digital Trends Contributor
Justin's always had a passion for trying out new software, asking questions, and explaining things – tech journalism is the…
Razer made the best gaming mouse even better
The Razer Viper V3 Pro sitting among its accessories.

The Razer Viper has been one of the best gaming mice you can buy since its inception, and last year's Viper V3 was no exception. Just a few months after introducing the mouse, Razer is taking another swing at the design with the Viper V3 Pro. It promises the same excellent shape, high-performance sensor, and esports-level accuracy, but with a slew of additional features that build on the original design.

I've been testing out the Viper V3 Pro for a few days now. There are enough changes here to warrant a new entry into Razer's growing lineup of competitive gaming mice, and they not only make the mouse more performant, but also more comfortable to use. The $160 price tag is tough to stomach considering Razer's mainstream focus with the original Viper V3. But if you have the cash to spare, this Pro update is worth every penny.
Going for HyperSpeed

Read more
Save $300 on this HP desktop PC with an RTX 3060, 1TB SSD
hp envy desktop pc deal april 2024 te02 1075t

HP has a great discount one the HP Envy TE02-1075t desktop computer for anyone seeking a permanent inclusion in their home office or living room. Usually costing $1,600, it’s down to $1,300 so you save $300. One of the better desktop computer deals around, you can even play games on it making it great value for all kinds of reasons. Here’s what else you need to know before you hit the buy button.

Why you should buy the HP Envy TE02-1075t desktop computer
The HP Envy TE02-1075t has some great hardware contained within a sleek-looking shell which will look great in your home office. It has a 13th-generation Intel Core i7-13700 processor along with 16GB of memory. It also has 1TB of M.2 SSD storage so there’s plenty of storage here plus it’s super speedy. There’s also room for a great graphics card with the Nvidia GeForce RTX 3060 with 12GB of dedicated VRAM ensuring that the HP Envy TE02-1075t is capable of playing plenty of games without any issue.

Read more
Snag this 34-inch LG Curved Ultrawide WQHD monitor for $249
The 45-inch LG UltraGear curved gaming monitor with a game on the screen.

If you want a monitor that aids your productivity, check out the monitor deals at Walmart right now. Currently, you can buy an LG 34-inch Curved Ultrawide monitor for just $249. Normally costing $350, that means you’re saving $101 but the deal is only available for a limited time and already proving very popular. If it sounds immediately appealing, keep reading and we’ll tell you even more about why you’ll love it.

Why you should buy the LG 34-inch Curved Ultrawide monitor
LG is generally very well known for making great TVs and monitors with its panel technology some of the best around. With the LG 34-inch Curved Ultrawide monitor, you get everything you could need and within seconds. It’s possible to install it in moments thanks to its One Click Stand which doesn’t require any complex setup.

Read more