Good news ! Hackbusters community is waiting for you !  https://discuss.hackbusters.com
KnowBe4 has been running the HackBusters site for a few years now, providing you with trending IT security news. We are expanding it and have launched a new exciting online community! The forum is divided into four main topics or categories: Social Engineering, Ransomware, Phishing and Security Awareness Training. You are invited to be one of the first to join us at: https://discuss.hackbusters.com.

APT Group Uses Windows Zero-Day in Middle East Attacks

A Windows zero-day vulnerability addressed this week by Microsoft with its November 2018 Patch Tuesday updates has been exploited by an advanced persistent threat (APT) group in attacks aimed at entities in the Middle East.

Microsoft learned about the vulnerability on October 17 from Kaspersky Labs. The security firm came across the flaw after one of its products detected an exploitation attempt against a Windows system. Further analysis revealed that it was a zero-day vulnerability related to the Win32k component in Windows.

The security hole, tracked as CVE-2018-8589, allows an attacker to elevate privileges on a compromised Windows 7 or Windows Server 2008 system. In the attacks observed by Kaspersky, threat actors had been executing the exploit through the first stage of a malware installer, but it’s unclear how the malware had been delivered.

According to Kaspersky, the vulnerability has only been used in a “very limited number of attacks,” with all the victims located...(continued)

View All Trending Stories