Microsoft announced that when users upload files to its OneDrive, SharePoint and other cloud services,All ZIP files will be scanned, including password-encrypted files.
In response, security researcher Andrew Brandt attempted to upload ZIP files containing samples of malware to Microsoft's cloud service. After uploading, Microsoft did identify them as "malicious files."
For the act of scanning user encrypted files,Microsoft says this is to protect users' information.
Microsoft says cybercriminals have long used compressed files to distribute malware,Most of these files are encrypted in an attempt to bypass the virus engine.
Instead, they scan the encrypted ZIP file to avoid getting caught.
Microsoft has not disclosed how the technology works by scanning the contents of compressed files directly through encryption, but those who care can try a different compression format, such as 7-Zip, or use a non-default encryption algorithm.
User comments