/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Microsoft starts blocking VBA macro scripts by default in Excel, PowerPoint, Access, Visio, and Word, after years of security experts requesting the change

Catalin Cimpanu / The Record :

The Record Catalin Cimpanu

Context & Ripple Effects

Microsoft’s move addresses an attack path already visible in related coverage: Chimborazo distributed a malicious Excel document designed to evade automated detection, while an earlier researcher used Word macros to bypass Windows 10 S protections.

The policy’s later rollout history shows the operational trade-off behind the change: Microsoft withdrew the default block after user feedback before resuming it for downloaded Office documents.

First-order effects

  • Users of Excel, PowerPoint, Access, Visio, and Word face a more restrictive default for VBA macros, reducing the immediate reach of macro-enabled documents.
  • Microsoft takes responsibility for balancing the new protection against the workflow disruption that later prompted its rollback.

Second-order effects

  • Attackers using malicious Office files, including the delivery pattern associated with Chimborazo, lose a lower-friction route to getting VBA code executed by recipients.
  • Organizations that depend on VBA-enabled documents must adapt document-handling practices, making compatibility feedback a material input to Microsoft’s rollout.

Third-order effects

  • The rollback-and-resumption sequence points to Office security moving toward safer defaults, with deployment controls adjusted when enterprise usability conflicts emerge.
  • If that pattern holds, protection against document-borne attacks will increasingly be set through centrally shipped product defaults rather than left to individual user judgment.

The trend: Microsoft is using its Office distribution and update controls to make historically abused document features opt-in rather than default behavior.

Discussion

  • @therecord_media @therecord_media on x
    In one of the most impactful changes made in recent years, Microsoft has announced today that it will block by default the execution of VBA macro scripts inside five Office applications https://therecord.media/...
  • @campuscodi Catalin Cimpanu on x
    More here: https://techcommunity.microsoft.com/ ... https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    This is the warning you'll now get when documents you've downloaded from the internet contain macros. If the document originates from inside your organization, macros will still run. This change will impact many malware distribution campaigns that rely on VBA macros. https://twit…