Ausnahme gefangen: SSL certificate problem: certificate is not yet valid 📌 Microsoft Uncovers Evidence of Russian Hackers Exploiting Outlook Vulnerability

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 Microsoft Uncovers Evidence of Russian Hackers Exploiting Outlook Vulnerability


💡 Newskategorie: Hacking
🔗 Quelle: blackhatethicalhacking.com

Microsoft Uncovers Evidence of Russian Hackers Exploiting Outlook Vulnerability

Premium Content

Patreon
Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes

Critical Flaw in Outlook Could Lead to Theft of NTLM Hashes

Microsoft has issued guidance to help its customers detect the indicators of compromise (IoCs) associated with a recently fixed Outlook vulnerability. The critical flaw, tracked as CVE-2023-23397, allowed attackers to carry out privilege escalation, enabling them to steal NT Lan Manager (NTLM) hashes and stage a relay attack without any user interaction. The vulnerability was fixed by Microsoft in March 2023 as part of its Patch Tuesday updates. However, it had been weaponized by Russian-based threat actors who attacked various government, transportation, energy, and military sectors in Europe. Microsoft’s incident response team found evidence of potential exploitation of the shortcoming as early as April 2022.

Outlook vulnerability

Source: thehackernews.com

See Also: So you want to be a hacker?
Offensive Security, Bug Bounty Courses

Net-NTLMv2 Relay attack chain

Microsoft described a successful Net-NTLMv2 Relay attack chain, which enabled the attackers to gain unauthorized access to an Exchange Server and modify mailbox folder permissions for persistent access. The compromised email account was used to extend the adversary’s access within the compromised environment by sending additional malicious messages to target other members of the same organization.

Microsoft recommends reviewing SMBClient event logging, Process Creation events, and other available network telemetry to identify potential exploitation via CVE-2023-23397.

Untitled Goose Tool by CISA

To help detect signs of malicious activity in Microsoft cloud environments, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a new open-source incident response tool called Untitled Goose Tool.

The Python-based utility provides novel authentication and data gathering methods to analyze Microsoft Azure, Azure Active Directory, and Microsoft 365 environments. Microsoft has also urged its customers to keep their on-premises Exchange servers updated and take steps to bolster their networks to mitigate potential threats.

Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com

Source: thehackernews.com

Source Link

Merch

Offensive Security & Ethical Hacking Course

Begin the learning curve of hacking now!


Information Security Solutions

Find out how Pentesting Services can help you.

The post Microsoft Uncovers Evidence of Russian Hackers Exploiting Outlook Vulnerability first appeared on Black Hat Ethical Hacking. ...



📌 Microsoft Uncovers Evidence of Russian Hackers Exploiting Outlook Vulnerability


📈 69.27 Punkte

📌 Russian hackers exploiting Outlook bug to hijack Exchange accounts


📈 32.65 Punkte

📌 Microsoft Uncovers Austrian Company Exploiting Windows and Adobe Zero-Day Exploits


📈 31.06 Punkte

📌 Russian Hackers Exploiting Microsoft Follina Vulnerability Against Ukraine


📈 30.03 Punkte

📌 Hackers Exploiting Microsoft Outlook Vulnerability Warns America


📈 29.49 Punkte

📌 USCYBERCOM Warned that Hackers Exploiting Microsoft Outlook Security Vulnerability to Deliver Malware


📈 29.49 Punkte

📌 Russian APT Hackers Exploiting Exim Vulnerability Since 2019 – NSA Warns


📈 28.11 Punkte

📌 NSA warns of Russian state-sponsored hackers exploiting VMWare vulnerability


📈 28.11 Punkte

📌 Pro-Russian Hackers Exploiting Recent WinRAR Vulnerability in New Campaign


📈 28.11 Punkte

📌 Russian Hackers Exploiting JetBrain Vulnerability to Hack Servers


📈 28.11 Punkte

📌 US Cyber Command issues alert about hackers exploiting Outlook vulnerability


📈 27.56 Punkte

📌 New Evidence Links Raspberry Robin Malware to Dridex and Russian Evil Corp Hackers


📈 27.2 Punkte

📌 No Evidence Russian Hackers Changed Votes in 2016 Election: Senators


📈 27.2 Punkte

📌 Merkel Cites 'Hard Evidence' Russian Hackers Targeted Her


📈 27.2 Punkte

📌 Chancellor Merkel has ‘hard evidence’ of Russian hackers targeted her


📈 27.2 Punkte

📌 Microsoft Warns of Stealthy Outlook Vulnerability Exploited by Russian Hackers


📈 26.71 Punkte

📌 Reddit uncovers Russian campaign to spread leaked UK documents


📈 26.36 Punkte

📌 France Uncovers a Vast Russian Disinformation Campaign In Europe


📈 26.36 Punkte

📌 Microsoft Uncovers New Post-Compromise Malware Used by Nobelium Hackers


📈 25.42 Punkte

📌 NSA: Russian govt hackers exploiting critical Exim flaw since 2019


📈 24.87 Punkte

📌 Russian Hackers Exploiting Recently Patched VMware Flaw, NSA Warns


📈 24.87 Punkte

📌 Top 12 Security Flaws Russian Spy Hackers Are Exploiting in the Wild


📈 24.87 Punkte

📌 NSA: Russian Hackers Exploiting VPN Vulnerabilities - Patch Immediately


📈 24.87 Punkte

📌 U.S. and U.K. Warn of Russian Hackers Exploiting Cisco Router Flaws for Espionage


📈 24.87 Punkte

📌 Russian Hackers Caught Exploiting Roundcube Webmail Zero-Day


📈 24.87 Punkte

📌 Russian hackers exploit Outlook zero-day vulnerability to target European organizations


📈 24.79 Punkte

📌 Russian hackers use old Outlook vulnerability to target Polish orgs (CVE-2023-23397)


📈 24.79 Punkte

📌 Microsoft Warns of Russian Cybercriminals Exploiting Zerologon Vulnerability


📈 24.57 Punkte

📌 US Cyber Command warns of Iran-linked hackers exploiting CVE-2017-11774 Outlook flaw


📈 24.33 Punkte

📌 Microsoft Warns of Kremlin-Backed APT28 Exploiting Critical Outlook Vulnerability


📈 24.03 Punkte

📌 Google Uncovers Tool Used by Iranian Hackers to Steal Data from Email Accounts


📈 23.5 Punkte

📌 Digital Forensics: Hackers-Arise Uncovers Mastermind of Global Scam!


📈 23.5 Punkte

📌 Microsoft fixes Outlook zero-day used by Russian hackers since April 2022


📈 23.48 Punkte

📌 Russian Hackers Target Russian Companies With Ransomware


📈 22.1 Punkte











matomo