Microsoft Outlook to block more risky attachments used in attacks

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/security/microsoft-outlook-to-block-more-risky-attachments-used-in-attacks/

ONE SENTENCE SUMMARY: Microsoft will block .library-ms and .search-ms attachments in Outlook starting July 2025 to counter phishing and malware threats.

MAIN POINTS:

  1. Microsoft expands Outlook’s blocked attachment list to include .library-ms and .search-ms files.
  2. The update applies to Outlook Web and the new Outlook for Windows starting July 2025.
  3. Attackers previously exploited .library-ms files in phishing campaigns targeting governments and companies.
  4. .search-ms protocol handler was exploited since June 2022 for phishing and malware delivery.
  5. Most organizations will not be affected due to rarity of these file types’ usage.
  6. Organizations relying on these file types must manually adjust allowed file type settings.
  7. Microsoft provides documentation to help Exchange Server administrators manage attachment security.
  8. Blocking these files is part of Microsoft’s larger strategy to eliminate exploited features.
  9. Microsoft previously disabled Office VBA macros, XLM macros, XLL add-ins, and ActiveX controls.
  10. VBScript support will also be discontinued by Microsoft starting April 2025.

TAKEAWAYS:

  1. Outlook security updates proactively block file types historically exploited by attackers.
  2. Organizations should review attachment policies to ensure operational continuity.
  3. Microsoft continues to remove legacy features to reduce security risks.
  4. Administrators can manually configure allowed file types to accommodate business requirements.
  5. Regularly reviewing Microsoft’s security documentation can help organizations stay informed and prepared.