New Worm Infects Through Explorer Flaw

LOS ANGELES – A new version of the Bugbear.e virus emerged on the Internet this week, infecting computers by exploiting a flaw in Windows-based Internet Explorer.

The worm uses an HTML email that exploits the flaw in browsers to cause its dangerous executable file to silently run without the user clicking on it.

The email messages that carry Bugbear.e are blank, use fake "from" addresses and can have one of many subject lines, including "Click on this!", "25 merchants and rising” and "15 FREE Bonus!" It carries an attachment with a name that's randomly chosen from a file found on the infected computer and has either a .zip or .htm ending. Clicking on the attachment also will cause infection by the virus.

As of Wednesday, there is no available fix or "patch" for Bugbear.e, which first appeared on Monday. But antivirus companies have rolled out software updates that can block Bugbear.e and other variants that also have emerged.

The virus isn't prevalent on the Internet, though its auto-execution feature could help it gain ground, according to Network Associates Inc.'s virus-response center, which also warned of a medium-risk virus known as "Netsky.s," which first emerged Sunday.

Such attacks are somewhat common in Trojan horses but worms like Bugbear.e unnerve security experts because large numbers of computers could be vulnerable to attack and quick defenses would be harder to come by.

Bugbear.e's use of a flaw with no available patch illustrates how the gap between the knowledge of a vulnerability and the release of malicious code that brings us ever closer to a zero-day network worm, an attack using a flaw that security experts don't yet know about.

Microsoft wasn't immediately able to comment on the flaw or when a fix might be available, but its support site, support.Microsoft.com, has additional information available.

The flaw that Bugbear.e exploits was disclosed in February and has since been used by several Trojan horses, which are dropped onto PCs by malicious websites. The virus essentially advances the delivery of a Trojan by using email to push PC users into viewing malicious web content.

Bugbear.e finds sensitive personal information and sends it to the attacker, including cookies, text from open windows and data captured by a program that logs keystrokes to grab passwords and credit card numbers.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Utah Governor Signs 'Porn Tax' and VPN Rule Into Law

Governor Spencer Cox on Friday signed into law a bill to tax adult websites and make them liable if minors circumvent geolocation.

BranditScan Launches 'White Glove' Subscription Tier

BranditScan has launched its new White Glove subscription tier for creators.

German Court: Regulator Can't Block Creator's IG Account, Only Posts

A German court has ruled that while a regional media regulatory agency may block specific Instagram posts that include material deemed harmful to minors, it cannot ban an entire Instagram account due to such a post.

Brazil Lays Out Preliminary Guidelines for New AV Requirements

President Luiz Inácio Lula da Silva on Wednesday signed a decree establishing guidelines for new regulations requiring adult websites to age-verify users located in Brazil.

Senate Committee Debates Section 230 Reform

The U.S. Senate Committee on Commerce, Science, and Transportation held a hearing Wednesday on potential changes to Section 230 of the Communications Decency Act, which protects interactive computer services — including adult platforms — from liability for user-generated content.

Pearl Industry Network Offers Free Creator Memberships

Industry trade group Pearl Industry Network (PiN) has launched its free creator membership initiative.

Sam Bird Acquires Fanblast

Sam Bird, former co-director of global talent agency Surge, has acquired creator monetization tool Fanblast and named himself CEO.

'SheHerGirls' Launches Through Paysite.com

The braintrust behind PoleVixens has officially launched a new membership site, SheHerGirls, also through Paysite.com.

FTC Invites Public Comment on 'Click to Cancel' Rulemaking

The Federal Trade Commission (FTC) announced this week that it is seeking public comment on whether it should amend its Negative Option Rule to better address deceptive or unfair practices.

Aylo Rebuts Indiana AV Suit Claims Over VPN Access

Aylo this week asked a Marion Superior Court judge to dismiss Indiana’s lawsuit alleging that the company violated the state’s age verification law by failing to prevent access by users who employ VPNs and similar means to avoid geolocation.

Show More