惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
H
Help Net Security
Jina AI
Jina AI
V
V2EX
G
Google Developers Blog
B
Blog
GbyAI
GbyAI
U
Unit 42
爱范儿
爱范儿
腾讯CDC
Engineering at Meta
Engineering at Meta
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 三生石上(FineUI控件)
宝玉的分享
宝玉的分享
小众软件
小众软件
D
DataBreaches.Net
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - Franky
博客园 - 聂微东
The Cloudflare Blog
I
InfoQ
Microsoft Azure Blog
Microsoft Azure Blog
Hugging Face - Blog
Hugging Face - Blog
大猫的无限游戏
大猫的无限游戏

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
MonikerLink: Outlook's Achilles' Heel, Navigating the Per...
Intel 471 · 2024-02-22 · via Intel 471 Blog

CVE-2024-21413 (MonikerLink) is a critical security vulnerability in the Microsoft Outlook software. This vulnerability, released by CheckPoint and Microsoft in February 2024, is suspected to impact all prior versions of Microsoft Outlook due to the method in which it interacts with COM API's. CheckPoint research stated in their analysis of MonikerLink "we've confirmed this #MonikerLink bug/attack vector on the latest Windows 10/11 + Microsoft 365 (Office 2021) environments. Other Office editions/versions are likely affected (by MonikerLink), too. In fact, we believe this is an overlooked issue which existed in the Windows/COM ecosystem for decades, since it lies in the core of the COM APIs." (CheckPoint, 2024). MonikerLink is being actively exploited.

GO TO COLLECTION

DOWNLOAD THE REPORT

Get your FREE Community Account today on the HUNTER Platform and get access to behavioral threat hunting content for your SIEM, EDR, NDR, and XDR platforms!

GET YOUR FREE HUNTER COMMUNITY ACCOUNT!

Hunt Packages

Microsoft Outlook Communicating Over Unusual Ports - Potential Exploitation

This Hunt Package was originally generated in response to a critical vulnerability in Microsoft Outlook, tracked as CVE-2024-21413. In addition to this vulnerability, this Hunt Package identifies potentially suspect network activities over port 80 or 445. While Outlook may generate a normal request over port 80, singular requests can often be an indication of malice. In February 2024, a zero-day was announced in Microsoft Outlook, tracked as CVE-2024-21413. The vulnerability enables attackers to obtain NTLM hashes from targeted users. Additionally in some cases a remote code execution scenario can occur without user interaction after a malicious link is clicked inside an email. The malicious email will likely appear like a typical phishing email, however instead of prompting a user to ensure they want to open the link, it bypasses this security check and automatically downloads and opens the attacker controlled file. Initial POCs that surfaced after the vulnerability disclosure, utilized SMB shares, external to the target machine to host files for the malicious link to download/execute. It is important to note, at the time of this Hunt Package's creation, it is unclear the extent of applications or file types that can be abused as part of this vulnerability. As such, aside from mshta, other likely suspicious applications have been included to provide a more complete picture if the vulnerability expands

ACCESS HUNT PACKAGE

Suspicious Child Process to Microsoft Outlook - Potential Outlook Exploitation or Suspicious Script Execution

This Hunt Package was originally created in response to a critical vulnerability in Outlook, tracked as CVE-2024-21413. In February 2024, a zero-day was announced in Microsoft Outlook, tracked as CVE-2024-21413. The vulnerability enables attackers to obtain NTLM hashes from targeted users. Additionally in some cases a remote code execution scenario can occur without user interaction after a malicious link is clicked inside an email. The malicious email will likely appear like a typical phishing email, however instead of prompting a user to ensure they want to open the link, it bypasses this security check and automatically downloads and opens the attacker controlled file. It is important to note, at the time of this Hunt Package's creation, it is unclear the extent of applications or file types that can be abused as part of this vulnerability. As such, aside from mshta, other likely suspicious applications have been included to provide a more complete picture if the vulnerability expands.

ACCESS HUNT PACKAGE

Microsoft Office Parent of Suspicious LOLB

Microsoft Office products have various methods of calling Windows scripting and execution programs and binaries. This logic looks for common LOLB, such as and several others, that are abused to launch malicious programs and malware. The occurrence of Office products being a parent of these LOLB is an indication of malware attempting to communicate with its Command and Control, download additional files or perform other malicious actions in order to compromise the system.

ACCESS HUNT PACKAGE

Possible SMB/LDAP External Communication (CVE-2023-23397)

This hunt package is designed to identify potential instances of CVE-2023-23397, a critical Microsoft Outlook vulnerability that has the potential to enable attackers to compromise user credentials through external LDAP or SMB calls. The package focuses on identifying suspicious interactions between the System process (as associated processes) and external hosts which should be abnormal in most environments.

ACCESS HUNT PACKAGE