Hacked Ad Seen on MySpace Served Spyware to a Million
An online banner advertisement that ran on MySpace.com and other sites over the past week used a Windows security flaw to infect more than a million users with spyware when people merely browsed the sites with unpatched versions of Windows …
Context & Ripple Effects
This attack lands on ground security researchers had been mapping since late 2005, when they began tracking thousands of websites distributing exploit code for the Windows Metafile vulnerability. What changed with this incident is the delivery vehicle: rather than luring users to malicious pages, attackers rented the banner-ad pipeline itself, letting the exploit run on MySpace.com and other high-traffic sites against unpatched Windows machines.
First-order effects
- More than a million users who merely browsed affected sites with unpatched versions of Windows had spyware installed on their machines, with no click required.
- MySpace and every other site that unknowingly carried the banner face an immediate trust problem: their ad inventory became the attack vector.
Second-order effects
- Ad networks and publishers selling third-party banner inventory come under pressure to vet creative before it runs, because a single compromised ad propagates across every site in the network at once.
- The scale of drive-by infection reinforces Microsoft's patch-management burden — with Windows dominant in business computing, unpatched machines convert any popular page into a mass-infection opportunity.
Third-order effects
- If hacked ads keep working as a distribution channel, the advertising supply chain — advertisers, networks, publishers — gets treated as part of the security perimeter, with scanning and vetting of third-party creative becoming standard practice rather than optional hygiene.
- Drive-by exploitation shifts the attacker calculus from building destinations to renting reach, meaning platform popularity itself becomes the vulnerability that platforms, not just end users, have to defend.
The trend: Online advertising's third-party delivery chain is emerging as a mass malware-distribution vector, turning ad-network vetting into a core platform-security function.