March 17, 2023
By
Olivia Cate,
Justin Elze,
Nick Gilberti,
Leo Bastidas,
Robert R. Lee Jr.,
Andrew Schwartz,
Carlos Perez and
Oddvar Moe in
Incident Response,
Incident Response & Forensics,
Purple Team Adversarial Detection & Countermeasures,
Research,
Vulnerability Assessment
Threat Overview Earlier this week, Microsoft released a patch for Outlook vulnerability CVE-2023-23397, which has been actively exploited for almost an entire year. This exploit has caught the attention of a hacking group linked to Russian military intelligence that is using it to target European organizations. CVE-2023-23397 allows threat actors to steal NTLM credentials of...