CVE-2018-4878
published 2018-02-06CVE-2018-4878: A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK…
PriorityP192high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
89.53%
99.8th percentile
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | < 28.0.0.161 | 28.0.0.161 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2018-4878 is triggered by a crafted SWF file embedded in Office documents distributed via email; detect malicious SWF content inside Office document attachments delivered through email. ↗
- →The exploit is triggered by a crafted SWF file that dereferences a dangling pointer to a listener object in the Primetime SDK; look for SWF files causing access violation exceptions in Flash Player processes. ↗
- →CVE-2018-4878 was deployed by Scarcruft (APT37/North Korean nexus) via Microsoft Word documents distributed through at least one website; monitor for Word documents fetching or embedding Flash content from external URLs. ↗
- →Lazarus Group exploited CVE-2018-4878 for client-side execution; correlate Flash Player exploitation attempts with Lazarus Group TTPs such as spearphishing Word attachments.
- →CVE-2018-4878 was also leveraged by the Spelevo Exploit Kit alongside CVE-2018-15982 to distribute Maze ransomware; monitor exploit kit traffic patterns involving Flash Player vulnerabilities. ↗
- →The Underminer exploit kit uses cookie detection to prevent repeated exploit site visits and user-agent/browser profiling to determine Flash Player version; monitor for these EK fingerprinting behaviors in web proxy logs. ↗
- →Underminer exploit kit uses RSA encryption of traffic prior to exploitation; look for encrypted non-standard traffic patterns preceding Flash exploitation. ↗
- →Tenable Plugin ID 106606 detects Adobe Flash Player <= 28.0.0.137 vulnerable to CVE-2018-4878; use this plugin for asset identification. ↗
- →Tenable Plugin ID 106655 (KB4074595) detects unpatched Adobe Flash Player on Windows; use for patch-status detection. ↗
- ·Affected versions are Adobe Flash Player 28.0.0.137 and earlier across all platforms (Windows, Macintosh, Linux, Chrome OS); the fixed version is 28.0.0.161. Ensure detections target only these vulnerable version ranges. ↗
- ·Exploitation requires memory reuse of the freed listener object by another listener object; the mismatch between old and new objects is the condition enabling unintended memory access. Generic use-after-free detections may need tuning for this specific Primetime SDK listener object reuse pattern. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Adobe Flash Player Use-After-Free Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2018-4878 [HIGH] CWE-416 Adobe Flash Player Use-After-Free Vulnerability
Vulnerability: Adobe Flash Player Use-After-Free Vulnerability
Affected: Adobe Flash Player
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-4878
Remediation Due Date: 2022-05-03
Red Hat
flash-plugin: use-after-free causing remote code execution (APSB18-03)
vendor_redhat·2018-02-01·CVSS 7.8
CVE-2018-4878 [HIGH] CWE-416 flash-plugin: use-after-free causing remote code execution (APSB18-03)
flash-plugin: use-after-free causing remote code execution (APSB18-03)
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
GHSA
GHSA-2rf4-mpg3-phjw: A use-after-free vulnerability was discovered in Adobe Flash Player before 28
ghsa_unreviewed·2022-05-13
CVE-2018-4878 [CRITICAL] CWE-416 GHSA-2rf4-mpg3-phjw: A use-after-free vulnerability was discovered in Adobe Flash Player before 28
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
OSV
CVE-2018-4878: A use-after-free vulnerability was discovered in Adobe Flash Player before 28
osv·2018-02-06·CVSS 7.8
CVE-2018-4878 [HIGH] CVE-2018-4878: A use-after-free vulnerability was discovered in Adobe Flash Player before 28
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
VulnCheck
Adobe Flash Player Use-After-Free Vulnerability
vulncheck·2018·CVSS 7.8
CVE-2018-4878 [HIGH] CWE-416 Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.fireeye.com/blog/threat-research/2018/02/attacks-leveraging-adobe-zero-day.html; https://www2.fireeye.com/rs/848-DID-242/images/rpt_APT37.pdf; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cve.org/CVERecord?id=CVE-2018-4878; https://www.fireeye.com/blog/threat-research/2018/02/apt37-overlooked-north-korean-actor.html; https://www.mcafee.com/blogs/other-blogs/mcafee-labs/hidden-cobra-targets-t
Suricata
ET MALWARE [Flashpoint] Possible CVE-2018-4878 Check-in
suricata·2018-02-02·CVSS 7.8
CVE-2018-4878 [HIGH] ET MALWARE [Flashpoint] Possible CVE-2018-4878 Check-in
ET MALWARE [Flashpoint] Possible CVE-2018-4878 Check-in
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE [Flashpoint] Possible CVE-2018-4878 Check-in"; flow:established,to_server; http.uri; content:"?id="; nocase; content:"&fp_vs="; nocase; distance:0; fast_pattern; content:"&os_vs="; nocase; distance:0; reference:url,www.flashpoint-intel.com/blog/targeted-attacks-south-korean-entities/; reference:cve,2018-4878; classtype:trojan-activity; sid:2025305; rev:4; metadata:created_at 2018_02_02, cve CVE_2018_4878, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_08_24;)
YARA
crime_ole_loadswf_cve_2018_4878
yara·CVSS 7.8
CVE-2018-4878 [HIGH] crime_ole_loadswf_cve_2018_4878
rule crime_ole_loadswf_cve_2018_4878
{
meta:
description = "Detects CVE-2018-4878"
vuln_type = "Remote Code Execution"
vuln_impact = "Use-after-free"
affected_versions = "Adobe Flash 28.0.0.137 and earlier versions"
mitigation0 = "Implement Protected View for Office documents"
mitigation1 = "Disable Adobe Flash"
weaponization = "Embedded in Microsoft Office first payloads"
actor = "Purported North Korean actors"
reference = "hxxps://www[.]krcert[.]or[.kr/data/secNoticeView.do?bulletin_writing_sequence=26998"
report = "https://www.flashpoint-intel.com/blog/targeted-attacks-south-korean-entities/"
author = "Vitali Kremez, Flashpoint"
version = "1.1"
strings:
// EMBEDDED FLASH OBJECT BIN HEADER
$header = "rdf:RDF" wide ascii
// OBJECT APPLICATION TYPE TITLE
$title = "Adobe Flex" wide ascii
Exploit-DB
Adobe Flash < 28.0.0.161 - Use-After-Free
exploitdb·2018-04-06·CVSS 7.8
CVE-2018-4878 [HIGH] Adobe Flash < 28.0.0.161 - Use-After-Free
Adobe Flash
""" + "" + """
"""
f = open("%s" % swf, "wb")
f.write(data)
f.close()
f = open("index.html", "wb")
f.write(html)
f.close()
HandlerClass = SimpleHTTPRequestHandler
ServerClass = BaseHTTPServer.HTTPServer
Protocol = "HTTP/1.0"
port = 8080
server_address = ('0.0.0.0', port)
HandlerClass.protocol_version = Protocol
httpd = ServerClass(server_address, HandlerClass)
sa = httpd.socket.getsockname()
print "Server ready", sa[0], "port", sa[1], "..."
httpd.serve_forever()
Exploit-DB
Flash ActiveX 28.0.0.137 - Code Execution (1)
exploitdb·2016-02-16·CVSS 7.8
CVE-2018-4878 [HIGH] Flash ActiveX 28.0.0.137 - Code Execution (1)
Flash ActiveX 28.0.0.137 - Code Execution (1)
---
## CVE-2018-4878 (flash exploit)
Pop up a calculator - tested with installation of flash activeX plugin 28.0.0.137
Download: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/44744.xlsx
Exploit-DB
Flash ActiveX 28.0.0.137 - Code Execution (2)
exploitdb·2016-02-13·CVSS 7.8
CVE-2018-4878 [HIGH] Flash ActiveX 28.0.0.137 - Code Execution (2)
Flash ActiveX 28.0.0.137 - Code Execution (2)
---
## CVE-2018-4878
Pop up a calculator - Requires Flash ActiveX 28.0.0.137
Download: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/44745.swf
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Sentinelone
Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone
blogs_sentinelone·2020-11-26·CVSS 7.8
[HIGH] Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone
## Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone
## Overview
Egregor ransomware is an offshoot of the Sekhmet malware family that has been active since mid-September 2020. The ransomware operates by compromising organizations, stealing sensitive user data, encrypting said data, and demanding a ransom to exchange encrypted documents. Egregor is ransomware associated with the cyberattacks against GEFCO and Barnes & Noble, Ubisoft, and numerous others.
Multiple intelligence and security companies believe that there are ties between past, now defunct, Maze affiliates and Egregor. There have been reports of ties to Sekhmet , ProLock , and LockBit as well (both of which have also been tied to Maze). With regard to Sekhmet, there are deep similarities in the configuration form
Sentinelone
Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone - SentinelLabs
blogs_sentinelone·2020-11-25·CVSS 7.8
[HIGH] Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone - SentinelLabs
## Overview
Egregor ransomware is an offshoot of the Sekhmet malware family that has been active since mid-September 2020. The ransomware operates by compromising organizations, stealing sensitive user data, encrypting said data, and demanding a ransom to exchange encrypted documents. Egregor is ransomware associated with the cyberattacks against GEFCO and Barnes & Noble, Ubisoft, and numerous others.
Multiple intelligence and security companies believe that there are ties between past, now defunct, Maze affiliates and Egregor. There have been reports of ties to Sekhmet, ProLock, and LockBit as well (both of which have also been tied to Maze). With regard to Sekhmet, there are deep similarities in the configuration format and obfuscation style. SentinelOne-affiliated security researcher
Unit42
The State of Exploit Development: 80% of Exploits Publish Faster than CVEs
blogs_unit42·2020-08-26
The State of Exploit Development: 80% of Exploits Publish Faster than CVEs
Threat Research Center
Threat Research
Vulnerabilities
## The State of Exploit Development: 80% of Exploits Publish Faster than CVEs
Jay Chen
Published: August 26, 2020
Threat Research
Vulnerabilities
Exploit
## Executive Summary
With the ever-increasing number of new vulnerabilities, vulnerability management becomes one of the most critical processes in ensuring continuous business operation. While it is clear that timely patching is essential, it’s also important to know quantitatively how a delay could increase risk. What is the chance that attackers breach my organization using a CVE just disclosed or using an unknown (zero-day) vulnerability? To understand the state of vulnerability disclosure and exploit development, Unit 42 researchers analyzed 45,450 publicly availabl
Unit42
The State of Exploit Development: 80% of Exploits Publish Faster than CVEs
blogs_unit42·2020-08-26
The State of Exploit Development: 80% of Exploits Publish Faster than CVEs
## Executive Summary
With the ever-increasing number of new vulnerabilities, vulnerability management becomes one of the most critical processes in ensuring continuous business operation. While it is clear that timely patching is essential, it’s also important to know quantitatively how a delay could increase risk. What is the chance that attackers breach my organization using a CVE just disclosed or using an unknown (zero-day) vulnerability? To understand the state of vulnerability disclosure and exploit development, Unit 42 researchers analyzed 45,450 publicly available exploits in Exploit Database at the time of this writing. The research correlated the exploit data with vulnerability and patch information to study exploit development in multiple facets.
The research reveals that:
-
Unit42
Threat Brief: Maze Ransomware
blogs_unit42·2020-05-08·CVSS 7.8
[HIGH] Threat Brief: Maze Ransomware
## Executive Summary
Since the beginning of the calendar year, Palo Alto Networks has detected an uptick in Maze ransomware samples across multiple industries. As a result, we've created this general threat assessment post on the Maze ransomware activities and full visualization of these techniques can be viewed in the Unit 42 Playbook Viewer.
Maze ransomware, a variant of ChaCha ransomware, was first observed in May 2019 and has targeted organizations in North America, South America, Europe, Asia, and Australia. This ransomware is typically distributed via emails containing weaponized Word or Excel attachments. However, it has also been distributed via exploit kits such as the Spelevo Exploit Kit, which has been used with Flash Player vulnerabilities CVE-2018-15982 and CVE-2018-4878. Ma
Unit42
Threat Brief: Maze Ransomware
blogs_unit42·2020-05-08·CVSS 7.8
[HIGH] Threat Brief: Maze Ransomware
Threat Research Center
High Profile Threats
Ransomware
## Threat Brief: Maze Ransomware
Brittany Barbehenn
Doel Santos
Published: May 8, 2020
High Profile Threats
Ransomware
Maze
SpelevoEK
## Executive Summary
Since the beginning of the calendar year, Palo Alto Networks has detected an uptick in Maze ransomware samples across multiple industries. As a result, we've created this general threat assessment post on the Maze ransomware activities and full visualization of these techniques can be viewed in the Unit 42 Playbook Viewer .
Maze ransomware, a variant of ChaCha ransomware, was first observed in May 2019 and has targeted organizations in North America, South America, Europe, Asia, and Australia. This ransomware is typically distributed via emails containing weaponized
Tenable
Critical Vulnerabilities You Need to Find and Fix to Protect the Remote Workforce
blogs_tenable·2020-04-13
Critical Vulnerabilities You Need to Find and Fix to Protect the Remote Workforce
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Qualys
Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking
blogs_qualys·2019-12-27·CVSS 8.8
[HIGH] Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking
A recent report identified 19+ vulnerabilities that should be mitigated by end of year 2019. These are a range of top vulnerabilities attacked and leveraged by Advance Persistent Threat (APT) actors from all parts of the world.
The list below shows those top 19 vulnerabilities, and it should be no surprise that you can easily track and remediate them via a dashboard within Qualys. Import the dashboard into your subscription for easy insight into what assets and vulnerabilities in your organization are at risk.
No.
CVE
Products Affected by CVE
CVSS Score (NVD)
Examples of Threat Actors
1
CVE-2017-11882
Microsoft Office
7.8
APT32 (Vietnam), APT34 (Iran), APT40 (China), APT-C-35 (India), Cobalt Group (Spain, Ukraine), Silent Group (Russia), Lotus Blossom (China), FIN7 (Russia)
2
Qualys
Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking | Qualys
blogs_qualys·2019-12-27·CVSS 8.8
[HIGH] Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking | Qualys
A recent report identified 19+ vulnerabilities that should be mitigated by end of year 2019. These are a range of top vulnerabilities attacked and leveraged by Advance Persistent Threat (APT) actors from all parts of the world.
The list below shows those top 19 vulnerabilities, and it should be no surprise that you can easily track and remediate them via a dashboard within Qualys. Import the dashboard into your subscription for easy insight into what assets and vulnerabilities in your organization are at risk.
No.
CVE
Products Affected by CVE
CVSS Score (NVD)
Examples of Threat Actors
1
CVE-2017-11882
Microsoft Office
7.8
APT32 (Vietnam), APT34 (Iran), APT40 (China), APT-C-35 (India), Cobalt Group (Spain, Ukraine), Silent Group (Russia), Lotus Blossom (China), FIN7 (Russia)
2
CVE-2018-
Trendmicro
Capesand verwendet öffentliche Exploits und Tools
blogs_trendmicro·2019-11-07
Capesand verwendet öffentliche Exploits und Tools
Ausnutzung von Schwachstellen
## Capesand verwendet öffentliche Exploits und Tools
Die Sicherheitsforscher von Trend Micro haben kürzlich ein neues Exploit Kit namens Capesand entdeckt, das auf neuere Sicherheitslücken in Adobe Flash und Microsoft Internet Explorer (IE) zielt.
By: Elliot Cao, Joseph C Chen, William Gamazo Sanchez Nov 07, 2019 Read time: ( words)
Save to Folio
Originalbeitrag von Elliot Cao, Joseph C. Chen, William Gamazo Sanchez
Die Sicherheitsforscher von Trend Micro haben kürzlich ein neues Exploit Kit namens Capesand entdeckt. Das Exploit Kit zielt auf neuere Sicherheitslücken in Adobe Flash und Microsoft Internet Explorer (IE). Die Recherche offenbarte auch den Missbrauch einer Sicherheitslücke für IE von 2015. Die kriminellen Hintermänner entwickeln das Kit stän
Trendmicro
New Capesand Exploit Kit Reuses Public Exploits, Tools
blogs_trendmicro·2019-11-05
New Capesand Exploit Kit Reuses Public Exploits, Tools
Malware
# New Capesand Exploit Kit Reuses Public Exploits, Tools
We found exploit kit Capesand abusing recently disclosed gaps in Adobe Flash and Internet Explorer (IE). Further investigation showed it also exploits a 2015 flaw in IE, appearing to reuse source code from a publicly shared exploit kit code.
By: Elliot Cao, Joseph C Chen, William Gamazo Sanchez
2019/11/05
Read time: ( words)
Save to Folio
Updated as of 7:00 PM Eastern Standard Time to remove one included image.
We discovered a new exploit kit named Capesand in October 2019. Capesand attempts to exploit recent vulnerabilities in Adobe Flash and Microsoft Internet Explorer (IE). Based on our investigation, it also exploits a 2015 vulnerability for IE. It seems the cybercriminals behind the exploit kit are continuously de
Trendmicro
New Capesand Exploit Kit Reuses Public Exploits, Tools
blogs_trendmicro·2019-11-05
New Capesand Exploit Kit Reuses Public Exploits, Tools
Malware
# New Capesand Exploit Kit Reuses Public Exploits, Tools
We found exploit kit Capesand abusing recently disclosed gaps in Adobe Flash and Internet Explorer (IE). Further investigation showed it also exploits a 2015 flaw in IE, appearing to reuse source code from a publicly shared exploit kit code.
By: Elliot Cao, Joseph C Chen, William Gamazo Sanchez
Nov 05, 2019
Read time: ( words)
Save to Folio
Updated as of 7:00 PM Eastern Standard Time to remove one included image.
We discovered a new exploit kit named Capesand in October 2019. Capesand attempts to exploit recent vulnerabilities in Adobe Flash and Microsoft Internet Explorer (IE). Based on our investigation, it also exploits a 2015 vulnerability for IE. It seems the cybercriminals behind the exploit kit are continuously
Sentinelone
From Zero to Hero, Chapter 3: RIG Exploit Kit - VBScript CVE-2018-8174 & Flash CVE-2018-4878 Exploit
blogs_sentinelone·2019-10-11·CVSS 7.8
CVE-2018-8174 [HIGH] From Zero to Hero, Chapter 3: RIG Exploit Kit - VBScript CVE-2018-8174 & Flash CVE-2018-4878 Exploit
Platform
- Platform Overview
- Singularity Platform
Welcome to IntegratedEnterprise Security
- AI Security Portfolio
Leading the Way in AI-Powered Security Solutions
- How It Works
The Singularity XDR Difference
- Singularity Marketplace
One-Click Integrations to Unlock the Power of XDR
- Pricing & Packaging
Comparisons and Guidance at a Glance
- Data & AI
- Purple AI
Accelerate SecOps with Generative AI
- Singularity Hyperautomation
Easily Automate Security Processes
- AI-SIEM
The AI SIEM for the Autonomous SOC
- Singularity Data Lake
AI-Powered, Unified Data Lake
- Singularity Data Lake for Log Analytics
Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
- Endpoint Security
- Singularity Endpoint
Autonomous Prevention, Detection, and Response
- Singularity XDR
Native &
Sentinelone
From Zero to Hero, Chapter 3: RIG Exploit Kit - VBScript CVE-2018-8174 & Flash CVE-2018-4878 Exploit
blogs_sentinelone·2019-10-11·CVSS 7.8
[HIGH] From Zero to Hero, Chapter 3: RIG Exploit Kit - VBScript CVE-2018-8174 & Flash CVE-2018-4878 Exploit
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Sentinelone
RIG Exploit Kit Chain Internals - SentinelLabs
blogs_sentinelone·2019-09-12
RIG Exploit Kit Chain Internals - SentinelLabs
Vitali Kremez explaining the RIG Exploit Kit and the infection chain internals that led to the Amadey Stealer and Clipboard Hijacker.
## Summary
One of the active malware distribution vectors lately remain to be exploit kits via drive-by infections. Exploit kits (EK) have various components from landing page filtering and serving relevant browser exploit with the end goal of downloading and running various malware of choice on the victim host.
## Background
Exploit kits essentially experienced their heyday in 2012-2014 from the Blackhole Exploit Kit distribution to the Angler (XXX) Exploit Kit to their eventual demise. In many cases, some of the most high-profile sophisticated exploit kits disappeared due to the significant law enforcement operations, which led to the arrest of the mai
Sentinelone
RIG Exploit Kit Chain Internals
blogs_sentinelone·2019-09-12
RIG Exploit Kit Chain Internals
## RIG Exploit Kit Chain Internals
Vitali Kremez explaining the RIG Exploit Kit and the infection chain internals that led to the Amadey Stealer and Clipboard Hijacker.
## Summary
One of the active malware distribution vectors lately remain to be exploit kits via drive-by infections. Exploit kits (EK) have various components from landing page filtering and serving relevant browser exploit with the end goal of downloading and running various malware of choice on the victim host.
## Background
Exploit kits essentially experienced their heyday in 2012-2014 from the Blackhole Exploit Kit distribution to the Angler (XXX) Exploit Kit to their eventual demise. In many cases, some of the most high-profile sophisticated exploit kits disappeared due to the significant law enforcement operations
Trendmicro
ShadowGate taucht wieder auf
blogs_trendmicro·2019-07-01
ShadowGate taucht wieder auf
Malware
## ShadowGate taucht wieder auf
Nach fast zwei Jahren der teilweise eingeschränkten Aktivität startet die ShadowGate-Kampagne mit dem Platzieren von Kryptowährungs-Minern mithilfe einer aktualisierten Version des Greenflash Sundown Exploit Kits.
By: Trend Micro Jul 01, 2019 Read time: ( words)
Save to Folio
Originalartikel von Joseph C Chen, Fraud Researcher
Nach fast zwei Jahren der teilweise eingeschränkten Aktivität startet die ShadowGate-Kampagne mit dem Platzieren von Kryptowährungs-Minern mithilfe einer aktualisierten Version des Greenflash Sundown Exploit Kits . Die Angriffe richten sich diesmal auf Unternehmen weltweit statt wie früher auf die Region Asien.
ShadowGate (auch WordsJS) wurde 2015 identifiziert und legte mit Exploit Kits Malware über die kompromittierten
Trendmicro
ShadowGate Returns With Greenflash Sundown Exploit Kit
blogs_trendmicro·2019-06-27
ShadowGate Returns With Greenflash Sundown Exploit Kit
# ShadowGate Returns With Greenflash Sundown Exploit Kit
After almost two years of sporadic restricted activity, the ShadowGate campaign has started delivering cryptocurrency miners with a newly upgraded version of the Greenflash Sundown exploit kit.
By: Joseph C Chen, Chaoying Liu, Nakaya Yoshihiro
2019/06/27
Read time: ( words)
Save to Folio
Updated July 1, 4:20PM: Updated to clarify the product of Revive/OpenX that was compromised.
After almost two years of sporadic restricted activity, the ShadowGate campaign has started delivering cryptocurrency miners with a newly upgraded version of the Greenflash Sundown exploit kit. The campaign has been spotted targeting global victims, after operating mainly in Asia.
Background of the Greenflash Sundown exploit kit
The ShadowGate (also c
Trendmicro
ShadowGate Returns With Greenflash Sundown Exploit Kit
blogs_trendmicro·2019-06-27
ShadowGate Returns With Greenflash Sundown Exploit Kit
# ShadowGate Returns With Greenflash Sundown Exploit Kit
After almost two years of sporadic restricted activity, the ShadowGate campaign has started delivering cryptocurrency miners with a newly upgraded version of the Greenflash Sundown exploit kit.
By: Joseph C Chen, Chaoying Liu, Nakaya Yoshihiro
Jun 27, 2019
Read time: ( words)
Save to Folio
Updated July 1, 4:20PM: Updated to clarify the product of Revive/OpenX that was compromised.
After almost two years of sporadic restricted activity, the ShadowGate campaign has started delivering cryptocurrency miners with a newly upgraded version of the Greenflash Sundown exploit kit. The campaign has been spotted targeting global victims, after operating mainly in Asia.
Background of the Greenflash Sundown exploit kit
The ShadowGate (also
Zscaler
Exploit Kit Activity Roundup Spring 2019 | Zscaler Blog
blogs_zscaler·2019-05-31
Exploit Kit Activity Roundup Spring 2019 | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Zscaler
Top EK Activity Roundup – Winter 2019 | Zscaler Blog
blogs_zscaler·2019-01-18
Top EK Activity Roundup – Winter 2019 | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Tenable
Underminer Exploit Kit: How Tenable Can Help
blogs_tenable·2018-07-31
Underminer Exploit Kit: How Tenable Can Help
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Underminer Exploit Kit: How Tenable Can Help
blogs_tenable·2018-07-31
Underminer Exploit Kit: How Tenable Can Help
Blog / Cyber Exposure Alerts
Subscribe
# Underminer Exploit Kit: How Tenable Can Help
Tenable Research
July 31, 2018
2 Min Read
The “Underminer” exploit kit is having widespread impact in Asian countries, particularly Japan. Thankfully, mitigation is relatively simple and involves patching and other well-known security best practices.
Contrary to popular belief, the exploit kit is not dead yet. “Underminer,” an exploit kit named and discovered by Trend Micro, is having widespread impact in Asian countries, particularly Japan. Its nefarious bootkit affects the system’s boot sectors and delivers the coin mining payload named Hidden Mellifera.
While the continued decline of Adobe Flash has led to a reduction in the prevalence of Exploit Kits, enterprises need to remember this attack ve
Trendmicro
Bootkit, Miner Delivered by New Underminer Exploit Kit
blogs_trendmicro·2018-07-26
Bootkit, Miner Delivered by New Underminer Exploit Kit
Cyber Threats
# Bootkit, Miner Delivered by New Underminer Exploit Kit
The newly discovered Underminer exploit kit delivers a bootkit that infects the system’s boot sectors as well as a cryptocurrency-mining malware named Hidden Mellifera.
By: Jaromir Horejsi, Joseph C Chen, Chaoying Liu
2018/07/26
Read time: ( words)
Save to Folio
Updated as of July 27, 2018, 2:08 AM, PDT to include a report about Underminer in November 2017.
Updated as of July 26, 2018, 11:02 PM, PDT to include an updated visualization for Figure 1.
We discovered a new exploit kit we named Underminer that employs capabilities used by other exploit kits to deter researchers from tracking its activity or reverse engineering the payloads. Underminer delivers a bootkit that infects the system’s boot sectors as well a
Unit42
Threat Brief: Office Documents Can Be Dangerous (But We’ll Continue to Use Them Anyway)
blogs_unit42·2018-07-24
Threat Brief: Office Documents Can Be Dangerous (But We’ll Continue to Use Them Anyway)
Nearly all of us have a use for Microsoft Office documents. Whether they are work documents, e-receipts, or a lease on a new apartment – Office documents are useful to all of us, and this is part of the reason we’re very likely to open an office document we receive as an attachment in e-mail. Armed with the knowledge that many people will open nearly any document, even those from an untrusted source, adversaries commonly choose these files in attacks to compromise a system.
In this threat brief we show you five different ways that Office documents can be subverted and abused to attack and compromise a Windows endpoint, some we’ve already posted about before, and some are new.
Macros
Macros are the most straight-forward way for an attacker to weaponize Office documents. Office applicatio
Unit42
Threat Brief: Office Documents Can Be Dangerous (But We’ll Continue to Use Them Anyway)
blogs_unit42·2018-07-24
Threat Brief: Office Documents Can Be Dangerous (But We’ll Continue to Use Them Anyway)
## Threat Brief: Office Documents Can Be Dangerous (But We’ll Continue to Use Them Anyway)
Liat Hayun
Published: July 24, 2018
High Profile Threats
Malware
Embedded Flash files
HTA Handlers
Macros
Microsoft Office Documents
OLE Objects
Nearly all of us have a use for Microsoft Office documents. Whether they are work documents, e-receipts, or a lease on a new apartment – Office documents are useful to all of us, and this is part of the reason we’re very likely to open an office document we receive as an attachment in e-mail. Armed with the knowledge that many people will open nearly any document, even those from an untrusted source, adversaries commonly choose these files in attacks to compromise a system.
In this threat brief we show you five different ways that Office documents
Securelist
APT Trends Report Q2 2018
blogs_securelist·2018-07-10
APT Trends Report Q2 2018
Authors
- GReAT
In the second quarter of 2017, Kaspersky Lab’s Global Research and Analysis Team (GReAT) began publishing summaries of the quarter’s private threat intelligence reports, in an effort to make the public aware of the research we have been conducting. This report serves as the latest installment, focusing on the relevant activities that we observed during Q2 2018.
These summaries are a representative snapshot of what has been discussed in greater detail in our private reports. They aim to highlight the significant events and findings that we feel people should be aware of. For brevity’s sake, we are choosing not to publish indicators associated with the reports highlighted. However, readers who would like to learn more about our intelligence reports or request more informat
Securelist
APT Trends Report Q2 2018
blogs_securelist·2018-07-10
APT Trends Report Q2 2018
Authors
GReAT
In the second quarter of 2017, Kaspersky Lab’s Global Research and Analysis Team (GReAT) began publishing summaries of the quarter’s private threat intelligence reports, in an effort to make the public aware of the research we have been conducting. This report serves as the latest installment, focusing on the relevant activities that we observed during Q2 2018.
These summaries are a representative snapshot of what has been discussed in greater detail in our private reports. They aim to highlight the significant events and findings that we feel people should be aware of. For brevity’s sake, we are choosing not to publish indicators associated with the reports highlighted. However, readers who would like to learn more about our intelligence reports or request more informatio
Trendmicro
Down but Not Out: Recent Exploit Kit Activities
blogs_trendmicro·2018-07-02·CVSS 7.5
[HIGH] Down but Not Out: Recent Exploit Kit Activities
Exploits & Vulnerabilities
# Down but Not Out: Recent Exploit Kit Activities
Based on the exploit kits’ latest activities, it appears they and their users are shifting tactics by joining the bandwagon, like capitalizing on cryptocurrency’s popularity or using off-the-rack malware.
By: Martin Co, Joseph C Chen
2018/07/02
Read time: ( words)
Save to Folio
Exploit kits may be down, but they’re not out. While they're still using the same techniques that involve malvertisements or embedding links in spam and malicious or compromised websites, their latest activities are making them significant factors in the threat landscape again. This is the case with Rig and GrandSoft, as well as the private exploit kit Magnitude — exploit kits we found roping in relatively recent vulnerabilities to de
Trendmicro
Rig Abuses CVE-2018-8174 to Deliver Monero Miner
blogs_trendmicro·2018-05-31·CVSS 8.8
CVE-2018-8174 [HIGH] Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Exploits & Vulnerabilities
# Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Sometime around February to March last year, we saw the Rig exploit kit’s Seamless campaign adding another gate before the actual landing page.
By: Miguel Carlo Ang, Martin Co, Michael Villanueva
2018/05/31
Read time: ( words)
Save to Folio
An exploit kit such as Rig usually starts off with a threat actor compromising a website to inject a malicious script/code that eventually redirects would-be victims to the exploit kit’s landing page. Sometime around February to March last year, however, we saw Rig’s Seamless campaign adding another layer or gate before the actual landing page.
Along with updates in code, we also observed Rig integrating a cryptocurrency-mining malware as its final payload. Based on the
Securelist
IT threat evolution Q1 2018. Statistics
blogs_securelist·2018-05-14
IT threat evolution Q1 2018. Statistics
Table of Contents
Q1 figures
Mobile threats
Q1 events
Mobile threat statistics
Distribution of detected mobile apps by type
TOP 20 mobile malware
Geography of mobile threats
Mobile banking Trojans
Mobile ransomware Trojans
Vulnerable apps used by cybercriminals
Malicious programs online (attacks via web resources)
Online threats in the financial sector
Q1 events
Financial threat statistics
Geography of attacks
TOP 10 banking malware families
Cryptoware programs
Q1 events
Number of new modifications
Number of users attacked by Trojan cryptors
Geography of attacks
Countries that are sources of web-based attacks: TOP 10
Countries where users faced the greatest risk of online infection
Local threats
Authors
Victor Chebyshev
Fedor Sinitsyn
Denis Parinov
Alexander Li
Securelist
IT threat evolution Q1 2018. Statistics
blogs_securelist·2018-05-14
IT threat evolution Q1 2018. Statistics
Table of Contents
- Q1 figures
- Mobile threats
- Vulnerable apps used by cybercriminals
- Malicious programs online (attacks via web resources)
- Local threats
Authors
- Victor Chebyshev
- Fedor Sinitsyn
- Denis Parinov
- Alexander Liskin
- Oleg Kupreev
## Q1 figures
According to KSN:
- Kaspersky Lab solutions blocked 796,806,112 attacks launched from online resources located in 194 countries across the globe.
- 282,807,433 unique URLs were recognized as malicious by Web Anti-Virus components.
- Attempted infections by malware designed to steal money via online access to bank accounts were logged on the computers of 204,448 users.
- Ransomware attacks were registered on the computers of 179,934 unique users.
- Our File Anti-Virus logged 187,597,494 unique malicious and potentially
Zscaler
Top Exploit Kit Activity Roundup, Spring 2018| Zscaler Blog
blogs_zscaler·2018-05-11
Top Exploit Kit Activity Roundup, Spring 2018| Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Securelist
APT Trends report Q1 2018
blogs_securelist·2018-04-12
APT Trends report Q1 2018
Authors
- GReAT
In the second quarter of 2017, Kaspersky’s Global Research and Analysis Team (GReAT) began publishing summaries of the quarter’s private threat intelligence reports in an effort to make the public aware of the research we have been conducting. This report serves as the next installment, focusing on the relevant activities that we observed during Q1 2018.
These summaries serve as a representative snapshot of what has been discussed in greater detail in our private reports, in order to highlight the significant events and findings that we feel people should be aware of. For brevity’s sake, we are choosing not to publish indicators associated with the reports highlighted. However, if you would like to learn more about our intelligence reports or request more information on
Securelist
APT Trends report Q1 2018
blogs_securelist·2018-04-12
APT Trends report Q1 2018
Authors
GReAT
In the second quarter of 2017, Kaspersky’s Global Research and Analysis Team (GReAT) began publishing summaries of the quarter’s private threat intelligence reports in an effort to make the public aware of the research we have been conducting. This report serves as the next installment, focusing on the relevant activities that we observed during Q1 2018.
These summaries serve as a representative snapshot of what has been discussed in greater detail in our private reports, in order to highlight the significant events and findings that we feel people should be aware of. For brevity’s sake, we are choosing not to publish indicators associated with the reports highlighted. However, if you would like to learn more about our intelligence reports or request more information on a
Trendmicro
February Patch Tuesday Fixes Privilege Escalation Bugs
blogs_trendmicro·2018-02-14·CVSS 8.8
[HIGH] February Patch Tuesday Fixes Privilege Escalation Bugs
Exploits & Vulnerabilities
## February Patch Tuesday Fixes Privilege Escalation Bugs
Microsoft’s Patch Tuesday has fixes addressing 50 security issues in Windows, Office, SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities.
By: Trend Micro 2018/02/14 Read time: ( words)
Save to Folio
Microsoft’s Patch Tuesday for February has a bevy of fixes addressing 50 security issues in Windows, Office (including Office Services and Web Apps), SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities. Of these, 14 were rated critical. Eight of these security flaws were disclosed through Trend Micro’
Trendmicro
February Patch Tuesday Fixes Privilege Escalation Bugs
blogs_trendmicro·2018-02-14·CVSS 8.8
[HIGH] February Patch Tuesday Fixes Privilege Escalation Bugs
Ausnutzung von Schwachstellen
## February Patch Tuesday Fixes Privilege Escalation Bugs
Microsoft’s Patch Tuesday has fixes addressing 50 security issues in Windows, Office, SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities.
By: Trend Micro Feb 14, 2018 Read time: ( words)
Save to Folio
Microsoft’s Patch Tuesday for February has a bevy of fixes addressing 50 security issues in Windows, Office (including Office Services and Web Apps), SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities. Of these, 14 were rated critical. Eight of these security flaws were disclosed through Trend M
Trendmicro
February Patch Tuesday Fixes Privilege Escalation Bugs
blogs_trendmicro·2018-02-14·CVSS 8.8
[HIGH] February Patch Tuesday Fixes Privilege Escalation Bugs
Exploits & Vulnerabilities
## February Patch Tuesday Fixes Privilege Escalation Bugs
Microsoft’s Patch Tuesday has fixes addressing 50 security issues in Windows, Office, SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities.
By: Trend Micro Feb 14, 2018 Read time: ( words)
Save to Folio
Microsoft’s Patch Tuesday for February has a bevy of fixes addressing 50 security issues in Windows, Office (including Office Services and Web Apps), SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities. Of these, 14 were rated critical. Eight of these security flaws were disclosed through Trend Micr
Trendmicro
February Patch Tuesday Fixes Privilege Escalation Bugs
blogs_trendmicro·2018-02-14·CVSS 8.8
[HIGH] February Patch Tuesday Fixes Privilege Escalation Bugs
Exploits & Vulnerabilities
# February Patch Tuesday Fixes Privilege Escalation Bugs
Microsoft’s Patch Tuesday has fixes addressing 50 security issues in Windows, Office, SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities.
By: Trend Micro
2018/02/14
Read time: ( words)
Save to Folio
Microsoft’s Patch Tuesday for February has a bevy of fixes addressing 50 security issues in Windows, Office (including Office Services and Web Apps), SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities. Of these, 14 were rated critical. Eight of these security flaws were disclosed through Trend Micro’
Trendmicro
February Patch Tuesday Fixes Privilege Escalation Bugs
blogs_trendmicro·2018-02-14·CVSS 8.8
[HIGH] February Patch Tuesday Fixes Privilege Escalation Bugs
Exploits y vulnerabilidades
## February Patch Tuesday Fixes Privilege Escalation Bugs
Microsoft’s Patch Tuesday has fixes addressing 50 security issues in Windows, Office, SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities.
By: Trend Micro Feb 14, 2018 Read time: ( words)
Save to Folio
Microsoft’s Patch Tuesday for February has a bevy of fixes addressing 50 security issues in Windows, Office (including Office Services and Web Apps), SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities. Of these, 14 were rated critical. Eight of these security flaws were disclosed through Trend Mic
Unit42
Unit 42 Vulnerability Research February 2018 Disclosures - Adobe
blogs_unit42·2018-02-13·CVSS 7.8
CVE-2018-4878 [HIGH] Unit 42 Vulnerability Research February 2018 Disclosures - Adobe
## Unit 42 Vulnerability Research February 2018 Disclosures - Adobe
Unit 42
Published: February 13, 2018
Malware
Threat Research
Vulnerabilities
Adobe
CVE-2018-4878
DogCall
As part of Unit 42’s ongoing threat research, we can now disclose that Palo Alto Networks Unit 42 researchers have discovered a vulnerability addressed by the Adobe Product Security Incident Response Team (PSIRT) as part of their February 2018 security update release .
CVE
Vulnerability Name
Affected Products
Maximum Severity Rating
Impact
Researcher(s)
CVE-2018-4900
Out-of-bounds read
Adobe Acrobat
Important
Remote Code Execution
Gal De Leon
Palo Alto Networks customers who deploy our Next-Generation Security Platform are protected from zero-day vulnerabilities such as these. Weaponized exploits
Qualys
Intel Makes Spectre Patch Progress, while Adobe Grapples with Latest Flash Bug
blogs_qualys·2018-02-09
Intel Makes Spectre Patch Progress, while Adobe Grapples with Latest Flash Bug
It’s been a busy week in InfoSec land, as Intel released a new Spectre patch, iOS source code was leaked online, and a zero-day Flash bug got exploited in the wild.
Also making noise these past few days: A major security hole in the Grammarly web app, WordPress updates tripping over each other, and a data breach at a Swiss telecom company.
As has been the case these past few weeks, we’ll lead off with the latest on Meltdown and Spectre, the hardware vulnerabilities whose disclosure on Jan. 3 sent shockwaves through the IT industry due to their scope and severity, and which are expected to remain an issue for years.
## Intel mitigates Spectre vulnerability with Skylake update
For a change, the latest Meltdown / Spectre development is encouraging: On Wednesday, Intel announced some progr
Qualys
Intel Makes Spectre Patch Progress, while Adobe Grapples with Latest Flash Bug | Qualys
blogs_qualys·2018-02-09
Intel Makes Spectre Patch Progress, while Adobe Grapples with Latest Flash Bug | Qualys
It’s been a busy week in InfoSec land, as Intel released a new Spectre patch, iOS source code was leaked online, and a zero-day Flash bug got exploited in the wild.
Also making noise these past few days: A major security hole in the Grammarly web app, WordPress updates tripping over each other, and a data breach at a Swiss telecom company.
As has been the case these past few weeks, we’ll lead off with the latest on Meltdown and Spectre, the hardware vulnerabilities whose disclosure on Jan. 3 sent shockwaves through the IT industry due to their scope and severity, and which are expected to remain an issue for years.
### Intel mitigates Spectre vulnerability with Skylake update
For a change, the latest Meltdown / Spectre development is encouraging: On Wednesday, Intel announced some prog
Unit42
Traps Prevents Adobe Flash Player Zero-Day
blogs_unit42·2018-02-09·CVSS 7.8
CVE-2018-4878 [HIGH] Traps Prevents Adobe Flash Player Zero-Day
On January 31 the Korean CERT published a security advisory regarding a new Adobe Flash Player zero-day vulnerability (CVE-2018-4878) which was observed being exploited in the wild. Adobe released a patch and security bulletin on February 6th to address this vulnerability. The vulnerability is a Use-After-Free (UAF) bug in Adobe tvsdk. The final goal is allegedly to download and execute a malware known as DogCall (aka ROKRAT) – an information stealing backdoor. DogCall is often delivered via malicious Hangul Word Processor (HWP) files, which is a popular application used in South Korea.
Figure 1 – The attack flow as observed in the malicious sample
In Figure 1 we show the attack flow as observed in the malicious sample. First, the malicious XLS spreadsheet file is opened by the victim. T
Unit42
Traps Prevents Adobe Flash Player Zero-Day
blogs_unit42·2018-02-09·CVSS 7.8
CVE-2018-4878 [HIGH] Traps Prevents Adobe Flash Player Zero-Day
Threat Research Center
High Profile Threats
Malware
## Traps Prevents Adobe Flash Player Zero-Day
Gal De Leon
Dor Hadad
Maor Dokhanian
Published: February 9, 2018
Cybercrime
High Profile Threats
Malware
Threat Research
Hancitor
On January 31 the Korean CERT published a security advisory regarding a new Adobe Flash Player zero-day vulnerability (CVE-2018-4878) which was observed being exploited in the wild. Adobe released a patch and security bulletin on February 6 th to address this vulnerability. The vulnerability is a Use-After-Free (UAF) bug in Adobe tvsdk . The final goal is allegedly to download and execute a malware known as DogCall (aka ROKRAT ) – an information stealing backdoor. DogCall is often delivered via malicious Hangul Word Processor (HWP) files, which is a p
Talos
Flash 0-Day In The Wild: Group 123 At The Controls
blogs_talos·2018-02-02·CVSS 7.8
CVE-2018-4878 [HIGH] Flash 0-Day In The Wild: Group 123 At The Controls
This blog post is authored by Warren Mercer and Paul Rascagneres.
## Executive SummaryThe 1st of February, Adobe published an advisory concerning a Flash vulnerability (CVE-2018-4878). This vulnerability is a use after free that allows Remote Code Execute through a malformed Flash object. Additionally KISA (Korean CERT) published anadvisoryabout a Flash 0-day used in the wild. Talos identified that an attacker exploited this vulnerability with a Flash object embedded in a Microsoft Excel document. By opening the document, the exploit was executed in order to download an additional payload from a compromised website.
We identified that the downloaded payload is the well-known Remote Administration Tool named ROKRAT. We already extensively spoke about this RAT on several articles in this b
Krebs
Attackers Exploiting Unpatched Flaw in Flash
blogs_krebs·2018-02-02·CVSS 7.8
CVE-2018-4878 [HIGH] Attackers Exploiting Unpatched Flaw in Flash
Adobe warned on Thursday that attackers are exploiting a previously unknown security hole in its Flash Player software to break into Microsoft Windows computers. Adobe said it plans to issue a fix for the flaw in the next few days, but now might be a good time to check your exposure to this still-ubiquitous program and harden your defenses.
Adobe said a critical vulnerability ( CVE-2018-4878 ) exists in Adobe Flash Player 28.0.0.137 and earlier versions. Successful exploitation could allow an attacker to take control of the affected system.
The software company warns that an exploit for the flaw is being used in the wild, and that so far the attacks leverage Microsoft Office documents with embedded malicious Flash content. Adobe said it plans to address this vulnerability in a release pl
Zscaler
Zscaler found new vulnerabilities in Adobe Flash |02-07-2018
blogs_zscaler
Zscaler found new vulnerabilities in Adobe Flash |02-07-2018
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Threat Intel
Lazarus Group (Lazarus Group, Labyrinth Chollima, HIDDEN COBRA)
threat_intel
Lazarus Group (Lazarus Group, Labyrinth Chollima, HIDDEN COBRA)
# Threat Actor Profile: Lazarus Group
ATT&CK ID: G0032
Also known as: Lazarus Group, Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet
Suspected origin: North Korea
## Overview
Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). (Citation: US-CERT HIDDEN COBRA June 2017) (Citation: Treasury North Korean Cyber Groups September 2019) Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeo
Zscaler
Zscaler protects against 22 new vulnerabilities for Adobe Fl
blogs_zscaler
Zscaler protects against 22 new vulnerabilities for Adobe Fl
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Recorded Future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018 | Recorded Future
blogs_recorded_future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018 | Recorded Future
## Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
Click here to download the complete analysis as a PDF.
This analysis focuses on an exploit kit, phishing attack, or remote access trojan co-occurrence with a vulnerability from January 1, 2018 to December 31, 2018. We analyzed thousands of sources, including code repositories, deep web forum postings, and dark web sites. This is a follow-up to our 2017 report , and the intended audience includes information security practitioners, especially those supporting vulnerability risk assessments.
## Executive Summary
Many vulnerability management practitioners face the daunting task of prioritizing vulnerabilities without adequate insight into which vulnerabilities are actively exploited by cybercriminals. Here, we’ll attempt to she
Recorded Future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
blogs_recorded_future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
# Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
Click here to download the complete analysis as a PDF.
This analysis focuses on an exploit kit, phishing attack, or remote access trojan co-occurrence with a vulnerability from January 1, 2018 to December 31, 2018. We analyzed thousands of sources, including code repositories, deep web forum postings, and dark web sites. This is a follow-up to our 2017 report, and the intended audience includes information security practitioners, especially those supporting vulnerability risk assessments.
### Executive Summary
Many vulnerability management practitioners face the daunting task of prioritizing vulnerabilities without adequate insight into which vulnerabilities are actively exploited by cybercriminals. Here, we’ll attempt to shed
Threat Intel
APT37 (APT37, InkySquid, ScarCruft)
threat_intel
APT37 (APT37, InkySquid, ScarCruft)
# Threat Actor Profile: APT37
ATT&CK ID: G0067
Also known as: APT37, InkySquid, ScarCruft, Reaper, Group123, TEMP.Reaper, Ricochet Chollima
Suspected origin: China
## Overview
APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.(Citation: FireEye APT37 Feb 2018)(Citation: Securelist ScarCruft Jun 2016)(Citation: Talos Group123)
North Korean group definitions are
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
arxiv_fulltext·2025-02-12
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Almuthanna Alageel
and
Sergio Maffeis
Department of Computing
Imperial College London
London, United Kingdom
plain
plain
## Abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques.
To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to
arXiv
Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting
arxiv_fulltext·2021-02-10·CVSS 8.8
CVE-2017-11882 [HIGH] Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting
Top 10 Most Exploited Vulnerabilities 2016-2019
(https://us-cert.cisa.gov/ncas/alerts/aa20-133a)
.83fcdec8a329824466f140a2e6cdfeec473a9ee2 .0
longtable[]@lllllll@
& CVSS Score & Number of Tactics & Number of Techniques &
Number of CAPECs & Number of CWEs & Number of CPEs
CVE-2017-11882 & 8.55 & 0 & 0 & 12 & 1 & 4
CVE-2017-0199 & 8.55 & 0 & 0 & 0 & 0 & 9
CVE-2017-5638 & 10.0 & 1 & 3 & 51 & 1 & 53
CVE-2012-0158 & 9.3 & 0 & 0 & 3 & 1 & 29
CVE-2019-0604 & 8.65 & 1 & 3 & 51 & 1 & 4
CVE-2017-0143 & 0.0 (not listed in BRON but NVD says high severity)
& 0 & 0 & 0 & 0 & 0
CVE-2018-4878 & 8.65 & 0 & 0 & 0 & 1 & 3
CVE-2017-8759 & 8.55 & 1 & 3 & 51 & 1 & 8
CVE-2015-1641 & 9.3 & 0 & 0 & 0 & 1 & 11
CVE-2018-7600 & 8.65 & 1 & 3 & 51 & 1 & 4
longtable
4 out of Top 10 Vulnerabilities share the follow
Bugzilla
CVE-2018-4877 CVE-2018-4878 flash-plugin: use-after-free causing remote code execution (APSB18-03)
bugzilla·2018-02-05·CVSS 9.8
CVE-2018-4877 [CRITICAL] CVE-2018-4877 CVE-2018-4878 flash-plugin: use-after-free causing remote code execution (APSB18-03)
CVE-2018-4877 CVE-2018-4878 flash-plugin: use-after-free causing remote code execution (APSB18-03)
Adobe Security Advisory APSA18-01 for Adobe Flash Player describes an use-after-free flaw that can possibly lead to code exeucution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSA18-01:
Use-after-free Remote Code Execution Critical CVE-2018-4878
Reference:
https://helpx.adobe.com/security/products/flash-player/apsa18-01.html
Discussion:
Fixed Flash Player version is not yet available. Quoting from the Adobe Security Bulletin:
Adobe will address this vulnerability in a release planned for the week of February 5.
---
Updated Flash Player version 28.0.0.161 was released today to correct this issue. The update is documented in the Adobe Security Bul
http://blog.talosintelligence.com/2018/02/group-123-goes-wild.htmlhttp://www.securityfocus.com/bid/102893http://www.securitytracker.com/id/1040318https://access.redhat.com/errata/RHSA-2018:0285https://blog.morphisec.com/flash-exploit-cve-2018-4878-spotted-in-the-wild-massive-malspam-campaignhttps://github.com/InQuest/malware-samples/tree/master/CVE-2018-4878-Adobe-Flash-DRM-UAF-0dayhttps://github.com/vysec/CVE-2018-4878https://helpx.adobe.com/security/products/flash-player/apsb18-03.htmlhttps://securingtomorrow.mcafee.com/mcafee-labs/hackers-bypassed-adobe-flash-protection-mechanism/https://threatpost.com/adobe-flash-player-zero-day-spotted-in-the-wild/129742/https://www.darkreading.com/threat-intelligence/adobe-flash-vulnerability-reappears-in-malicious-word-files/d/d-id/1331139https://www.exploit-db.com/exploits/44412/https://www.fireeye.com/blog/threat-research/2018/02/attacks-leveraging-adobe-zero-day.htmlhttps://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/north-korean-hackers-allegedly-exploit-adobe-flash-player-vulnerability-cve-2018-4878-against-south-korean-targetshttp://blog.talosintelligence.com/2018/02/group-123-goes-wild.htmlhttp://www.securityfocus.com/bid/102893http://www.securitytracker.com/id/1040318https://access.redhat.com/errata/RHSA-2018:0285https://blog.morphisec.com/flash-exploit-cve-2018-4878-spotted-in-the-wild-massive-malspam-campaignhttps://github.com/InQuest/malware-samples/tree/master/CVE-2018-4878-Adobe-Flash-DRM-UAF-0dayhttps://github.com/vysec/CVE-2018-4878https://helpx.adobe.com/security/products/flash-player/apsb18-03.htmlhttps://securingtomorrow.mcafee.com/mcafee-labs/hackers-bypassed-adobe-flash-protection-mechanism/https://threatpost.com/adobe-flash-player-zero-day-spotted-in-the-wild/129742/https://www.darkreading.com/threat-intelligence/adobe-flash-vulnerability-reappears-in-malicious-word-files/d/d-id/1331139https://www.exploit-db.com/exploits/44412/https://www.fireeye.com/blog/threat-research/2018/02/attacks-leveraging-adobe-zero-day.htmlhttps://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/north-korean-hackers-allegedly-exploit-adobe-flash-player-vulnerability-cve-2018-4878-against-south-korean-targetshttps://github.com/cisagov/vulnrichment/issues/196https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-4878
2018-02-06
Published
2021-11-03
Added to CISA KEV
Exploited in the wild