Dienstag, Dezember 5, 2023
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
Liga Technews
No Result
View All Result
  • Home
  • Marketing Tech
    • Artificial Intelligence
    • Cybersecurity
    • Blockchain and Crypto
    • Business Automation
  • Apps
  • Digital Transformation
  • Internet of Things
  • SaaS
  • Tech Investments
  • Contact Us
Liga Technews
No Result
View All Result
Microsoft Warns of Stealthy Outlook Vulnerability Exploited by Russian Hackers

Microsoft Warns of Stealthy Outlook Vulnerability Exploited by Russian Hackers

admin by admin
März 27, 2023
in Cybersecurity
0 0
0
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


Mar 25, 2023Ravie LakshmananEnterprise Safety / Microsoft

Outlook vulnerability

Microsoft on Friday shared steering to assist clients uncover indicators of compromise (IoCs) related to a just lately patched Outlook vulnerability.

Tracked as CVE-2023-23397 (CVSS rating: 9.8), the critical flaw pertains to a case of privilege escalation that might be exploited to steal NT Lan Supervisor (NTLM) hashes and stage a relay attack with out requiring any person interplay.

„Exterior attackers may ship specifically crafted emails that can trigger a connection from the sufferer to an untrusted location of attackers‘ management,“ the corporate noted in an advisory launched this month.

„This can leak the Net-NTLMv2 hash of the sufferer to the untrusted community which an attacker can then relay to a different service and authenticate because the sufferer.“

The vulnerability was resolved by Microsoft as a part of its Patch Tuesday updates for March 2023, however not earlier than Russia-based risk actors weaponized the flaw in assaults focusing on authorities, transportation, vitality, and army sectors in Europe.

Microsoft’s incident response workforce mentioned it discovered proof of potential exploitation of the shortcoming as early as April 2022.

In a single assault chain described by the tech big, a profitable Internet-NTLMv2 Relay assault enabled the risk actor to achieve unauthorized entry to an Change Server and modify mailbox folder permissions for persistent entry.

Outlook vulnerability

The compromised e-mail account was then used to increase the adversary’s entry throughout the compromised atmosphere by sending extra malicious messages to focus on different members of the identical group.

„Whereas leveraging NTLMv2 hashes to achieve unauthorized entry to sources just isn’t a brand new method, the exploitation of CVE-2023-23397 is novel and stealthy,“ Microsoft said.

„Organizations ought to overview SMBClient occasion logging, Course of Creation occasions, and different accessible community telemetry to establish potential exploitation through CVE-2023-23397.“

WEBINAR

Uncover the Hidden Risks of Third-Celebration SaaS Apps

Are you conscious of the dangers related to third-party app entry to your organization’s SaaS apps? Be a part of our webinar to be taught in regards to the sorts of permissions being granted and easy methods to decrease danger.

RESERVE YOUR SEAT

The disclosure comes because the U.S. Cybersecurity and Infrastructure Safety Company (CISA) released a brand new open supply incident response instrument that helps detect indicators of malicious exercise in Microsoft cloud environments.

Dubbed Untitled Goose Tool, the Python-based utility provides „novel authentication and information gathering strategies“ to research Microsoft Azure, Azure Lively Listing, and Microsoft 365 environments, the company mentioned.

Earlier this 12 months, Microsoft additionally urged customers to maintain their on-premises Change servers up to date in addition to take steps to bolster their networks to mitigate potential threats.

Discovered this text attention-grabbing? Comply with us on Twitter  and LinkedIn to learn extra unique content material we publish.



Related Posts

Shield your self from ticketing scams forward of the Premier League Summer time Sequence USA Tour
Cybersecurity

Shield your self from ticketing scams forward of the Premier League Summer time Sequence USA Tour

Dezember 5, 2023
How cybersecurity groups ought to put together for geopolitical disaster spillover
Cybersecurity

How cybersecurity groups ought to put together for geopolitical disaster spillover

Dezember 5, 2023
Provide-chain ransomware assault causes outages at over 60 credit score unions
Cybersecurity

Provide-chain ransomware assault causes outages at over 60 credit score unions

Dezember 5, 2023
New BLUFFS Bluetooth Assault Expose Gadgets to Adversary-in-the-Center Assaults
Cybersecurity

New BLUFFS Bluetooth Assault Expose Gadgets to Adversary-in-the-Center Assaults

Dezember 4, 2023
Cloud forensics – An introduction to investigating safety incidents in AWS, Azure and GCP
Cybersecurity

How group collaboration instruments and Cybersecurity can safeguard hybrid workforces

Dezember 4, 2023
Sophos DNS Safety – Be part of the EAP – Sophos Information
Cybersecurity

Sophos DNS Safety – Be part of the EAP – Sophos Information

Dezember 4, 2023
Next Post
Supporting REST and HTML with a gRPC Microservice

Supporting REST and HTML with a gRPC Microservice

Schreibe einen Kommentar Antworten abbrechen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

Neueste Beiträge

  • OpenAI Rival Mistral AI Set to Elevate Funds from a16z and Others at $2B Valuation Dezember 5, 2023
  • Leveling Up Your Advertising and marketing Sport with Act-On Software program’s New Functionalities Dezember 5, 2023
  • Knowledgeable Spotlights Potential $25,000 Liquidity Sweep Dezember 5, 2023
  • GTM 71: Author Founder Tells All: Securing Enterprise Clients with a PLG Movement | Might Habib Dezember 5, 2023
  • Watch out for Expired or Compromised Code Signing Certificates Dezember 5, 2023

Categories

  • Apps (972)
  • Artificial Intelligence (794)
  • Blockchain and Crypto (3.270)
  • Business Automation (613)
  • Cybersecurity (1.180)
  • Digital Transformation (205)
  • Internet of Things (771)
  • Marketing Tech (474)
  • SaaS (809)
  • Tech Investments (803)

Liga Tech News

Welcome to Liga Tech News The goal of Liga Tech News is to give you the absolute best news sources for any topic! Our topics are carefully curated and constantly updated as we know the web moves fast so we try to as well.

Kategorien

  • Apps
  • Artificial Intelligence
  • Blockchain and Crypto
  • Business Automation
  • Cybersecurity
  • Digital Transformation
  • Internet of Things
  • Marketing Tech
  • SaaS
  • Tech Investments

Recent News

  • OpenAI Rival Mistral AI Set to Elevate Funds from a16z and Others at $2B Valuation
  • Leveling Up Your Advertising and marketing Sport with Act-On Software program’s New Functionalities
  • Knowledgeable Spotlights Potential $25,000 Liquidity Sweep
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

© 2023 Liga Tech News | All Rights Reserved

No Result
View All Result
  • Home
  • Marketing Tech
    • Artificial Intelligence
    • Blockchain and Crypto
    • Business Automation
    • Cybersecurity
  • Digital Transformation
  • Apps
  • Internet of Things
  • SaaS
  • Tech Investments
  • Contact Us

© 2023 Liga Tech News | All Rights Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In