Transportation sector targeted by both ransomware and APTs
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-11882 | Memory Corruption RCE in Microsoft Office via Legacy Equation Editor CVE-2017-11882 is a memory corruption vulnerability (CWE-119) in Microsoft Office, residing in the legacy Microsoft Equation Editor component (EQNEDT32.EXE), that allows remote code execution in the context of the current user. Attackers trigger it by persuading a user to open a crafted document, most commonly an RTF file or other Office document carrying a malicious embedded equation object, which overflows a buffer while the equation content is parsed. Successful exploitation lets the attacker run arbitrary code with the privileges of the signed-in user, a typical foothold for malware delivery and, per CISA, for ransomware operations. Any environment running affected Microsoft Office builds is exposed; the source data does not enumerate specific affected version ranges. The flaw is confirmed exploited in the wild: it was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use and holds a 99.9% EPSS score (percentile 100), though the source data lists no public PoC. Do: Apply Microsoft's Office security updates (November 2017 or later) across all endpoints, prioritizing this KEV-listed flaw given its known ransomware use. On systems that cannot yet be patched, disable or unregister the legacy Equation Editor (EQNEDT32.EXE) and consider blocking or warning on RTF attachments as interim mitigations. Check for indicators of abuse such as EQNEDT32.EXE spawning unexpected child processes after document opens. | 7.8 | 100% | KEV ransomware PoC ×10 |
| masshundreds of millions of users/installations (Office is near-ubiquitous on Windows and in enterprises; the share still unpatched is unknown) | |
| CVE-2018-0798 +1 in the same advisory: …0802 | Memory Corruption RCE in Microsoft Office Equation Editor (CVE-2018-0798) CVE-2018-0798 is a memory corruption flaw (out-of-bounds write, CWE-787) in the Microsoft Equation Editor component of Microsoft Office 2007, 2010, 2013, and 2016 that allows remote code execution when the component mishandles objects in memory. A remote attacker triggers it by persuading a user to open a specially crafted document containing a maliciously embedded equation; user interaction is required and no privileges are needed (CVSS vector AV:N/AC:L/PR:N/UI:R). Successful exploitation lets the attacker run arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Any organization running the affected legacy Office versions — including deployments using the Office Compatibility Pack — is exposed, with government, military, and transportation organizations named in related reporting on Office-document attack campaigns. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and its EPSS score of 95.1% (100th percentile) indicates a very high probability of active exploitation, with related headlines highlighting APT activity (notably the Bitter group's campaigns against military targets in South Asia) around Office document threats. Do: Apply Microsoft's security updates for this vulnerability across Office 2007, 2010, 2013, 2016 and the Office Compatibility Pack, per vendor instructions as required by CISA KEV, and upgrade off legacy Office 2007/2010 to a still-supported release since those versions no longer receive regular fixes. Enforce caution with untrusted Office documents (don't open unsolicited attachments or embedded equations from unknown sources) and consider stripping or blocking embedded OLE equation objects from external files. Prioritize patching for government, military, and transportation-sector environments given active APT targeting of those sectors via Office documents. | 8.8 group max | 95% | KEV |
| masshundreds of millions of Office users/endpoints worldwide |
Full article385 words · extracted from helpnetsecurity.com · click to collapse
Trellix released The Threat Report: Fall 2022 from its Advanced Research Center, which analyzes cybersecurity trends from the third quarter (Q3) of 2022.

The report includes evidence of malicious activity linked to ransomware and nation-state backed advanced persistent threat (APT) actors. It examines malicious cyberactivity including threats to email, the malicious use of legitimate third-party security tools, and more.
Q3 cybersecurity trends
- US ransomware activity leads the pack: In the US alone, ransomware activity increased 100% quarter over quarter in transportation and shipping. Globally, transportation was the second most active sector (following telecom). APTs were also detected in transportation more than in any other sector.
- Germany saw the highest detections: Not only did Germany generate the most threat detections related to APT actors in Q3 (29% of observed activity), but they also had the most ransomware detections. Ransomware detections rose 32% in Germany in Q3 and generated 27% of global activity.
- Emerging threat actors scaled: The China-linked threat actor, Mustang Panda, had the most detected threat indicators in Q3, followed by Russian-linked APT29 and Pakistan-linked APT36.
- Ransomware evolved: Phobos, a ransomware sold as a complete kit in the cybercriminal underground, has avoided public reports until now. It accounted for 10% of global detected activity and was the second most used ransomware detected in the US. LockBit continued to be the most detected ransomware globally, generating 22% of detections.
- Old vulnerabilities continued to prevail: Years-old vulnerabilities continue to be successful exploitation vectors. Trellix observed Microsoft Equation Editor vulnerabilities comprised by CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802 to be the most exploited among malicious emails received by customers during Q3.
- Malicious use of Cobalt Strike: Trellix saw Cobalt Strike used in 33% of observed global ransomware activity and in 18% of APT detections in Q3. Cobalt Strike, a legitimate third-party tool created to emulate attack scenarios to improve security operations, is a favorite tool of attackers who repurpose its capabilities for malicious intent.
“So far in 2022, we have seen unremitting activity out of Russia and other state-sponsored groups,” said John Fokker, Head of Threat Intelligence, Trellix. “This activity is compounded by a rise in politically motivated hacktivism and sustained ransomware attacks on healthcare and education. The need for increased inspection of cyberthreat actors and their methods has never been greater.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/11/18/cybersecurity-trends-q3-2022/