Russian hackers use old Outlook vulnerability to target Polish orgs (CVE-2023-23397)Help Net Security·Dec 5, 00:00 UTC · Dec 5, 2023VulnerabilityCVE-2023-23397CVE-2023-38831CVE-2021-4044460
Microsoft patches zero-days used by state-sponsored and ransomware threat actors (CVE-2023-23397, CVE-2023-24880)Help Net Security·Mar 14, 00:00 UTC · Mar 14, 2023Ransomware in the wildCVE-2023-23397CVE-2023-24880CVE-2022-44698+3 CVEs60
Russia-linked APT28 group spotted exploiting Outlook flaw to hijack MS Exchange accountsSecurity Affairs·Dec 5, 14:19 UTC · Dec 5, 2023Threat actorCVE-2023-23397CVE-2023-38831CVE-2021-40444+4 CVEs60
Microsoft shares guidance for investigating attacks exploiting CVE-2023Security Affairs·Mar 26, 14:41 UTC · Mar 26, 2023VulnerabilityCVE-2023-2339747
NATO and the EU formally condemned APT28 cyber espionageSecurity Affairs·May 12, 16:39 UTC · May 12, 2024Threat actorCVE-2023-23397CVE-2022-30190CVE-2020-12641+2 CVEs60
Comprehensive analysis of initial attack samples exploiting CVE-2023Kaspersky Securelist·Jul 19, 12:00 UTC · Jul 19, 2023Exploit / PoCCVE-2023-23397CVE-2023-2932460
Easily bypassed patch makes zero-click Outlook flaw exploitable again (CVE-2023-29324)Help Net Security·May 10, 00:00 UTC · May 10, 2023VulnerabilityCVE-2023-29324CVE-2023-2339760
Threat Advisory: Microsoft Outlook privilege escalation vulnerability being exploited in the wildCisco Talos·Mar 15, 23:46 UTC · Mar 15, 2023Exploit / PoC in the wildCVE-2023-2339760
Microsoft Warns of Kremlin-Backed APT28 Exploiting Critical Outlook VulnerabilityThe Hacker News·Dec 8, 08:55 UTC · Dec 8, 2023VulnerabilityCVE-2023-23397CVE-2023-3883160
Russia's APT8 exploited Outlook 0day to target EU NATO membersSecurity Affairs·Dec 8, 00:07 UTC · Dec 8, 2023Threat actorCVE-2023-23397CVE-2022-30190CVE-2020-12641+2 CVEs60
Kaspersky malware report for Q3 2023Kaspersky Securelist·Dec 1, 16:01 UTC · Dec 1, 2023MalwareCVE-2023-23397CVE-2023-2932460
Russian APT28 Hackers Targeting HighThe Hacker News·Feb 3, 06:31 UTC · Feb 3, 2024Threat actorCVE-2023-23397CVE-2023-3883160
Microsoft Warns of Stealthy Outlook Vulnerability Exploited by Russian HackersThe Hacker News·May 1, 08:04 UTC · May 1, 2023VulnerabilityCVE-2023-2339760
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and MoreThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-34621160
Microsoft Outlook Flaw Exploited by Russia's APT28 to Hack Czech, German EntitiesThe Hacker News·May 9, 05:20 UTC · May 9, 2024Threat actorCVE-2023-23397CVE-2022-3802860
Russia-linked APT28 compromised Ubiquiti EdgeRouters to facilitate cyber operationsSecurity Affairs·Feb 28, 11:43 UTC · Feb 28, 2024Threat actorCVE-2021-36260CVE-2022-46169CVE-2021-35394+1 CVEs160
Week in review: Booking.com hotel booking scam, Kali Linux 2023.4 releasedHelp Net Security·Dec 15, 12:15 UTC · Dec 15, 2023Phishing & fraudCVE-2023-50164CVE-2023-23397CVE-2023-26360+4 CVEs60
Microsoft Patch Tuesday, December 2023 EditionKrebs on Security·Dec 15, 00:00 UTC · Dec 15, 2023Vulnerability in the wildCVE-2023-35628CVE-2023-35641CVE-2023-35636+1 CVEs60
December 2023 Patch Tuesday: 33 fixes to wind the year downHelp Net Security·Dec 12, 00:00 UTC · Dec 12, 2023Vulnerability in the wildCVE-2023-35628CVE-2023-35636CVE-2023-23397+4 CVEs60
More evidence of Russian intelligence exploiting old Outlook flawThe Record·Dec 8, 15:25 UTC · Dec 8, 2023Data breachCVE-2023-2339760
Russian APT28 Exploits Outlook Bug to Access ExchangeInfosecurity Magazine·Dec 5, 10:40 UTC · Dec 5, 2023Threat actorCVE-2023-23397CVE-2023-38831CVE-2021-4044460
A zero-click flaw in Windows allows stealing NTLM credentialsSecurity Affairs·May 11, 07:23 UTC · May 11, 2023VulnerabilityCVE-2023-29324CVE-2023-2339760
Security Affairs newsletter Round 413 by Pierluigi PaganiniSecurity Affairs·Apr 2, 15:10 UTC · Apr 2, 2023Ransomware in the wildCVE-2023-23529CVE-2023-23397CVE-2023-22809+1 CVEs60
Microsoft Patch Tuesday fix Outlook zeroSecurity Affairs·Mar 26, 12:22 UTC · Mar 26, 2023Vulnerability in the wildCVE-2023-23397CVE-2023-24880160
Week in review: Kali Linux gets Purple, Microsoft zero-days get patchedHelp Net Security·Mar 19, 00:00 UTC · Mar 19, 2023Vulnerability in the wildCVE-2023-23397CVE-2023-24880160
Microsoft Rolls Out Patches for 80 New Security Flaws — Two Under Active AttackThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2023Vulnerability in the wildCVE-2023-23397CVE-2023-24880CVE-2022-44698+10 CVEs60
Microsoft Patch Tuesday, March 2023 EditionKrebs on Security·Mar 15, 00:00 UTC · Mar 15, 2023Vulnerability in the wildCVE-2023-23397CVE-2023-2488060
Russia-Aligned TAG-70 Targets European Government and Military Mail Servers in New Espionage CampaignRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Threat actorCVE-2023-2339760
BlueDelta Exploits Ukrainian Government Roundcube Mail Servers to Support Espionage ActivitiesRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Threat actorCVE-2020-35730CVE-2023-23397CVE-2020-12641+1 CVEs60
Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid LogisticsThe Hacker News·May 22, 07:30 UTC · May 22, 2025VulnerabilityCVE-2023-23397CVE-2020-12641CVE-2020-35730+2 CVEs35
Russia-linked APT28 targets western logistics entities and technology firmsSecurity Affairs·May 22, 06:36 UTC · May 22, 2025Threat actorCVE-2023-23397CVE-2023-3883160
Multi-national warning issued over Russia’s targeting of logistics, tech firmsCyberScoop·May 21, 18:41 UTC · May 21, 2025Exploit / PoC in the wildCVE-2023-23397CVE-2023-3883160
⚡ Weekly Recap: Nation-State Hacks, Spyware Alerts, Deepfake Malware, Supply Chain BackdoorsThe Hacker News·May 6, 05:03 UTC · May 6, 2025MalwareCVE-2025-3928CVE-2025-1976CVE-2025-46271+33 CVEs60
France links Russian APT28 to attacks on dozen French entitiesSecurity Affairs·Apr 30, 13:58 UTC · Apr 30, 2025Threat actorCVE-2023-2339760
Microsoft Uncovers Sandworm Subgroup's Global Cyber Attacks Spanning 15+ CountriesThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2025Threat actorCVE-2024-1709CVE-2023-48788CVE-2021-34473+4 CVEs160
Russia-linked APT Seashell Blizzard is behind the long-running global access operation BadPilot campaignSecurity Affairs·Feb 13, 12:21 UTC · Feb 13, 2025Threat actorCVE-2021-34473CVE-2022-41352CVE-2023-32315+4 CVEs160
Sandworm APT's initial access subgroup hits organizations accross the globeHelp Net Security·Feb 13, 00:00 UTC · Feb 13, 2025Threat actorCVE-2021-34473CVE-2022-41352CVE-2023-32315+4 CVEs160
Subgroup of Russia’s Sandworm compromising US and European organizations, Microsoft saysThe Record·Feb 12, 18:22 UTC · Feb 12, 2025Threat actorCVE-2024-1709CVE-2023-48788CVE-2021-34473+4 CVEs160
Russian state threat group shifts focus to US, UK targetsCyberScoop·Feb 12, 17:58 UTC · Feb 12, 2025Exploit / PoC in the wildCVE-2024-1709CVE-2023-48788CVE-2021-34473+4 CVEs160
Microsoft enforces defenses preventing NTLM relay attacksHelp Net Security·Dec 11, 00:00 UTC · Dec 11, 2024VulnerabilityCVE-2024-21413CVE-2023-23397CVE-2023-3656335