惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
Y
Y Combinator Blog
月光博客
月光博客
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 三生石上(FineUI控件)
S
SegmentFault 最新的问题
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
美团技术团队
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
Last Week in AI
Last Week in AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
有赞技术团队
有赞技术团队
博客园 - 司徒正美
V
Visual Studio Blog
小众软件
小众软件
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
Tailwind CSS Blog
Apple Machine Learning Research
Apple Machine Learning Research
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
A
About on SuperTechFans
The Cloudflare Blog

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
MonikerLink: Outlook's Achilles' Heel, Navigating the Per...
Intel 471 · 2024-02-22 · via Intel 471 Blog

CVE-2024-21413 (MonikerLink) is a critical security vulnerability in the Microsoft Outlook software. This vulnerability, released by CheckPoint and Microsoft in February 2024, is suspected to impact all prior versions of Microsoft Outlook due to the method in which it interacts with COM API's. CheckPoint research stated in their analysis of MonikerLink "we've confirmed this #MonikerLink bug/attack vector on the latest Windows 10/11 + Microsoft 365 (Office 2021) environments. Other Office editions/versions are likely affected (by MonikerLink), too. In fact, we believe this is an overlooked issue which existed in the Windows/COM ecosystem for decades, since it lies in the core of the COM APIs." (CheckPoint, 2024). MonikerLink is being actively exploited.

GO TO COLLECTION

DOWNLOAD THE REPORT

Get your FREE Community Account today on the HUNTER Platform and get access to behavioral threat hunting content for your SIEM, EDR, NDR, and XDR platforms!

GET YOUR FREE HUNTER COMMUNITY ACCOUNT!

Hunt Packages

Microsoft Outlook Communicating Over Unusual Ports - Potential Exploitation

This Hunt Package was originally generated in response to a critical vulnerability in Microsoft Outlook, tracked as CVE-2024-21413. In addition to this vulnerability, this Hunt Package identifies potentially suspect network activities over port 80 or 445. While Outlook may generate a normal request over port 80, singular requests can often be an indication of malice. In February 2024, a zero-day was announced in Microsoft Outlook, tracked as CVE-2024-21413. The vulnerability enables attackers to obtain NTLM hashes from targeted users. Additionally in some cases a remote code execution scenario can occur without user interaction after a malicious link is clicked inside an email. The malicious email will likely appear like a typical phishing email, however instead of prompting a user to ensure they want to open the link, it bypasses this security check and automatically downloads and opens the attacker controlled file. Initial POCs that surfaced after the vulnerability disclosure, utilized SMB shares, external to the target machine to host files for the malicious link to download/execute. It is important to note, at the time of this Hunt Package's creation, it is unclear the extent of applications or file types that can be abused as part of this vulnerability. As such, aside from mshta, other likely suspicious applications have been included to provide a more complete picture if the vulnerability expands

ACCESS HUNT PACKAGE

Suspicious Child Process to Microsoft Outlook - Potential Outlook Exploitation or Suspicious Script Execution

This Hunt Package was originally created in response to a critical vulnerability in Outlook, tracked as CVE-2024-21413. In February 2024, a zero-day was announced in Microsoft Outlook, tracked as CVE-2024-21413. The vulnerability enables attackers to obtain NTLM hashes from targeted users. Additionally in some cases a remote code execution scenario can occur without user interaction after a malicious link is clicked inside an email. The malicious email will likely appear like a typical phishing email, however instead of prompting a user to ensure they want to open the link, it bypasses this security check and automatically downloads and opens the attacker controlled file. It is important to note, at the time of this Hunt Package's creation, it is unclear the extent of applications or file types that can be abused as part of this vulnerability. As such, aside from mshta, other likely suspicious applications have been included to provide a more complete picture if the vulnerability expands.

ACCESS HUNT PACKAGE

Microsoft Office Parent of Suspicious LOLB

Microsoft Office products have various methods of calling Windows scripting and execution programs and binaries. This logic looks for common LOLB, such as and several others, that are abused to launch malicious programs and malware. The occurrence of Office products being a parent of these LOLB is an indication of malware attempting to communicate with its Command and Control, download additional files or perform other malicious actions in order to compromise the system.

ACCESS HUNT PACKAGE

Possible SMB/LDAP External Communication (CVE-2023-23397)

This hunt package is designed to identify potential instances of CVE-2023-23397, a critical Microsoft Outlook vulnerability that has the potential to enable attackers to compromise user credentials through external LDAP or SMB calls. The package focuses on identifying suspicious interactions between the System process (as associated processes) and external hosts which should be abnormal in most environments.

ACCESS HUNT PACKAGE