Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Skype Exposed By Login Attack
News & Analysis

Skype Exposed By Login Attack

ISBuzz TeamBy ISBuzz TeamApril 25, 2017Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Following the news that the instant messaging application, SKYPE, has been affected by a vulnerability called SPYKE. SPYKE is an attack that affects any SKYPE installation as long as the attacker has local access to the login screen of a running SKYPE instance. The vulnerability primarily affects Windows OS clients but users of other OS’s might be vulnerable. IT security experts from Comparitech, ESET, AlienVault and AlertLogic commented below.

Lee Munson, Security Researcher at Comparitech: 

Lee Munson“The ‘SPYKE’ attack is only effective in limited circumstances so most people should not be overly concerned about it.

The fact that an attacker needs local access to a machine should ensure that all but the most unfortunate of home users should have absolutely nothing to worry about, though they should always keep all their software up to date at all times.

Additionally, in this age of laptops and smartphones, only a tiny minority of people are likely to be using public machines so the potential size of the attack is tiny.

That said, anyone who is successfully duped could be in real trouble, especially in term of identity theft following the acquisition of their login credentials.

Therefore, it is essential that organisations offering Skype terminals in public places immediately update the clients to remove the Facebook login feature.

Those few people who need to use such services should think twice before doing so. If unavoidable, they should ensure that they login directly and not through Facebook. Furthermore, it is always good practice to use different login credentials for every online account – such an approach would certainly mitigate the risk of a widespread attack in this case.

Additionally, users should always be aware of the information they share with any company, not only Skype. Do they need to enter their correct names, dates of birth, postal addresses, etc., for every account or can they be a bit more liberal with the truth as a means of minimising the amount of personal information they share online?”

Mark James, IT Security Specialist at ESET:

mark-james“Any attack that can potentially steal your login credentials is bad. When you’re presented with a login page within the application the chances of a successful phish are extremely high. When this fake page is shown, a level of trust has already been gained so putting your credentials in could seem like a normal thing to do. Once you have entered your details they almost certainly will be used elsewhere and distribution of spam or malware from your Skype account could lead from this attack.

Ensuring you’re on the latest version of Skype will protect you from this attack, specifically versions older than SKYPE Client 7.31.0.104 should update immediately. Keeping all your software up-to-date is the best way to keep safe. It’s something you hear all too often, update this, update that, but the bad guys never sleep, there is always someone looking for the next vulnerability and or exploit. Having a good regularly updating internet security product and the latest operating system will all help in your multi layered security approach.”

Javvad Malik, Security Advocate at AlienVault:

Javvad Malik“Overall it’s not such a serious attack as it requires an attacker to have local machine access.

It’s a type of attack that is prevalent against public-facing machines such as kiosks. Organisations should always take care in hardening public-facing machines to minimise the risk of tampering and gaining access to back end systems. They should also deploy additional monitoring controls to detect any active threats against such endpoints.

Users should update their Skype installations as soon as possible as part of their patch cycle to close off this vulnerability.”

Oliver Pinson-Roxburgh, Director of EMEA at Alert Logic:

oliver-pinson-roxburgh“In the scenario where you are restricted by the tools on the system as an attacker, this attack is massive.  If all the attacker has access to is Skype, this exposes the system to pretty much any website so it’s a massive oversight. From this, cybercriminals could gain access to malicious tools. If the attacker has access to a restricted terminal they can use this flaw to extend access by browsing to exploit kits or download tools. In addition, you could steal local credentials through phishing using this to trick the user.  The other key thing is that a lot of this would look like just normal skype activity. As damage control for such attacks, I would use a proxy for local connections and limit access to areas within Facebook as a start. Training users is critical to limiting bad decisions and I would also be monitoring for malicious activity on the network, focusing on exposed systems. I would also recommend updating as soon as possible.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}