CVE-2023-23397
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: microsoft Outlook Elevation of Privilege Vulnerability EPSS 97% (100º percentile).
Data di correzione federale CISA 4 apr · data superata
Minacce · 110 giorni fa
APT28 sta diventando più difficile da intercettare per progettazione. Il gruppo si sta allontanando da un singolo implant stabile e si sta orientando verso moduli di breve durata, infrastruttura ospitata su edge e malware che può interagire con un LLM, il che accorcia la finestra in cui qualunque singola impronta resta utile.
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: microsoft Outlook Elevation of Privilege Vulnerability EPSS 97% (100º percentile).
Data di correzione federale CISA 4 apr · data superata
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: windows Print Spooler Elevation of Privilege Vulnerability EPSS 15% (96º percentile).
Data di correzione federale CISA 14 mag · data superata
1 fonte che coprono questa storia
APT28, an evolution of tradecraft
Context Sekoia’s Threat Detection & Research (TDR) team has been tracking APT28 for several years.
Part of the PlainSec briefing for 2026-06-12