* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Sunday, November 23, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    ‘Baywatch’ returns to local beaches as part of efforts to save the entertainment industry – Santa Monica Daily Press

    Baywatch’ Makes Waves on Local Beaches in a Daring Revival of the Entertainment Industry

    Old North Festival Chorus presents Christmas concerts in Marblehead MA – Wicked Local

    Old North Festival Chorus Spreads Holiday Cheer with Magical Christmas Concerts in Marblehead

    The Surprising Studio Ghibli Film That Influenced Netflix’s Train Dreams [Exclusive] – Yahoo

    The Surprising Studio Ghibli Film That Influenced Netflix’s Train Dreams [Exclusive] – Yahoo

    Star Panel to Consider Moviegoing in an Evolving Marketplace – Noozhawk

    Star Panel to Explore the Future of Moviegoing in a Changing Marketplace

    Mattel makes another bold family-entertainment move beyond toys – TheStreet

    Mattel makes another bold family-entertainment move beyond toys – TheStreet

    Themed Entertainment Association announces 32nd annual Thea Award recipients – InPark Magazine

    Themed Entertainment Association announces 32nd annual Thea Award recipients – InPark Magazine

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Align Technology, Tandem Diabetes, Integra LifeSciences, Lantheus, and Inspire Medical Systems Shares Skyrocket, What You Need To Know – FinancialContent

    Shares of Align Technology, Tandem Diabetes, Integra LifeSciences, Lantheus, and Inspire Medical Systems Surge: Key Insights for Investors

    First Partner Jennifer Siebel Newsom leads Gender Equity Summit on technology and well-being – California State Portal | CA.gov

    First Partner Jennifer Siebel Newsom Champions Gender Equity at Technology and Well-Being Summit

    MACo’s Inaugural Information Technology Conference – Maryland Association of Counties

    Maryland’s Inaugural Information Technology Conference Sparks a New Era of County Innovation

    F&I Sentinel Recognized on the 2025 Deloitte Technology Fast 500™ for the Second Consecutive Year – PR Newswire

    F&I Sentinel Achieves Back-to-Back Honors on the 2025 Deloitte Technology Fast 500™

    Keeping up with new technology – The Clinton Chronicle

    Stay Ahead of the Curve: Master the Hottest Technology Trends Today

    How hybrid technology supports sustainable driving – AZ Big Media

    How Hybrid Technology is Powering the Future of Sustainable Transportation

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    ‘Baywatch’ returns to local beaches as part of efforts to save the entertainment industry – Santa Monica Daily Press

    Baywatch’ Makes Waves on Local Beaches in a Daring Revival of the Entertainment Industry

    Old North Festival Chorus presents Christmas concerts in Marblehead MA – Wicked Local

    Old North Festival Chorus Spreads Holiday Cheer with Magical Christmas Concerts in Marblehead

    The Surprising Studio Ghibli Film That Influenced Netflix’s Train Dreams [Exclusive] – Yahoo

    The Surprising Studio Ghibli Film That Influenced Netflix’s Train Dreams [Exclusive] – Yahoo

    Star Panel to Consider Moviegoing in an Evolving Marketplace – Noozhawk

    Star Panel to Explore the Future of Moviegoing in a Changing Marketplace

    Mattel makes another bold family-entertainment move beyond toys – TheStreet

    Mattel makes another bold family-entertainment move beyond toys – TheStreet

    Themed Entertainment Association announces 32nd annual Thea Award recipients – InPark Magazine

    Themed Entertainment Association announces 32nd annual Thea Award recipients – InPark Magazine

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Align Technology, Tandem Diabetes, Integra LifeSciences, Lantheus, and Inspire Medical Systems Shares Skyrocket, What You Need To Know – FinancialContent

    Shares of Align Technology, Tandem Diabetes, Integra LifeSciences, Lantheus, and Inspire Medical Systems Surge: Key Insights for Investors

    First Partner Jennifer Siebel Newsom leads Gender Equity Summit on technology and well-being – California State Portal | CA.gov

    First Partner Jennifer Siebel Newsom Champions Gender Equity at Technology and Well-Being Summit

    MACo’s Inaugural Information Technology Conference – Maryland Association of Counties

    Maryland’s Inaugural Information Technology Conference Sparks a New Era of County Innovation

    F&I Sentinel Recognized on the 2025 Deloitte Technology Fast 500™ for the Second Consecutive Year – PR Newswire

    F&I Sentinel Achieves Back-to-Back Honors on the 2025 Deloitte Technology Fast 500™

    Keeping up with new technology – The Clinton Chronicle

    Stay Ahead of the Curve: Master the Hottest Technology Trends Today

    How hybrid technology supports sustainable driving – AZ Big Media

    How Hybrid Technology is Powering the Future of Sustainable Transportation

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Fancy Bear targets Nato entities via critical Outlook flaw

December 8, 2023
in Technology
Fancy Bear targets Nato entities via critical Outlook flaw
Share on FacebookShare on Twitter

A vulnerability patched in March has likely been exploited by the Russian state actor Fancy Bear, for over two years, according to the latest intelligence

Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 08 Dec 2023 13:15

The Kremlin-backed advanced persistent threat (APT) actor known to the cyber community variously as APT28, Fighting Ursa, Forest Blizzard and most famously, Fancy Bear, may have been exploiting a critical elevation of privilege (EoP) zero-day in Microsoft Outlook much earlier and more widely than thought.

CVE-2023-23397 was officially disclosed and patched back in March 2023. It is a particularly nasty bug, exploited by sending a specially crafted email to the victim, but because it can be triggered server-side, they do not actually need to open or view it to become compromised.

A few days after that, Mandiant’s John Hultquist warned that the vulnerability had likely been exploited by Moscow against Ukrainian targets for well over 12 months. Then, earlier in December, Microsoft and Polish Cyber Command warned that exploitation of the bug was ongoing.

Now, new evidence published by the Unit 42 team at Palo Alto Networks has revealed that Fancy Bear has been using the zero-day liberally over the past 20 months, in three distinct campaigns dating from March to December of 2022 – in March of 2023, and most recently between September and October of this year, targeting least 30 organisations in 14 nations, the majority of them Nato members.

Victimology extends across multiple sectors, including energy production and distribution; pipeline operations; materiel, personal and air transport; and various government defence, foreign and internal affairs and economic ministries.

The targeted countries were Bulgaria, Czechia, Italy, Jordan, Lithuania, Luxembourg, Montenegro, Poland, Romania, Slovakia, Türkiye, Ukraine, the United Arab Emirates and the United States, as well as the Nato High Readiness Force Headquarters, which are dispersed across Europe in the UK, France, Germany, Greece, Poland and Türkiye.

Unit 42 said its discovery offered valuable insight into Russian state targeting priorities during the ongoing war in Ukraine. “Delving into more than 50 observed samples in which Fighting Ursa targeted victims with CVE-2023-23397 provides unique and informative insights into Russian military priorities during a time of international conflict for them,” the team wrote.

“Zero-day exploits by their nature are valuable commodities for APTs. Threat actors only use these exploits when the rewards associated with the access and intelligence gained outweigh the risk of public discovery of the exploit.

“Using a zero-day exploit against a target indicates it is of significant value. It also suggests that existing access and intelligence for that target were insufficient at the time.

“In the second and third campaigns, Fighting Ursa continued to use a publicly known exploit that was already attributed to them, without changing their techniques. This suggests that the access and intelligence generated by these operations outweighed the ramifications of public outing and discovery,” they said.

“For these reasons, the organisations targeted in all three campaigns were most likely a higher than normal priority for Russian intelligence.”

How CVE-2023-23397 works

CVE-2023-23397 targets Windows NT LAN Manager (NTLM), a challenge-response authentication protocol that is known to be prone to what are known as relay attacks, as a result of with Microsoft has used Kerberos as its default protocol sine Windows 2000.

Unfortunately for Microsoft users, many Microsoft systems, including Outlook, will default back to NTLM as a failsafe if Kerberos is not feasible.

In the exploitation chain, a vulnerable or misconfigured Outlook instance receives a specially crafted email and sends NTLM authentication message to a remote file share controlled by Fancy Bear. It receives back an NTLMv2 hash which the APT then uses to impersonate the victim and gain access to their network.

Kennet Harpsøe, Logpoint senior cyber analyst, commented: “Given the overall political situation the described attack should not come as a surprise for anyone…NTLM is ancient and depreciated. The modern replacement is Kerberos [which] is standard even in Windows networks, but NTLM is used as a fall back and is thus still widely used despites its numerous and well-known security flaws. 

“If you can, disable NTLM in your AD, and if you cannot, make sure to monitor the NTLM traffic on your network. Are new users all of a sudden using NTLM authentication all the time? NTLM authentication requests should normally not be leaving your network. If they do, it should be thoroughly investigated. Track all NTLM replay attempts in your network from your AD log,” he said. 

“Enforce Signing (SMB/LDAP) and Extended Protection for Authentication (EPA) for all relevant servers, like domain controllers and email servers, to defeat most replay attacks. 

Added Harpsøe: “Finally, one wonders why it is still not standard to encrypt emails at rest, with keys private to the recipients. PGP has been around for a long time. It’s not much fun stealing emails if you can’t read them!”

Busy bears

Unit 42’s latest disclosure about the extent of malicious Russian cyber activity comes in the wake of major new intelligence published yesterday by the UK’s National Cyber Security Centre (NCSC) and partner agencies in which a campaign of cyber attacks on the British political process was firmly attributed to a Federal Security Service (FSB) group called Star Blizzard, but also tracked as Cold River and Seaborgium among other names.

The government judges this campaign to be so serious in its nature that it yesterday summoned the Russian ambassador to account for it, and placed two named individuals, including an FSB agent, on the UK’s financial sanctions list over their involvement in an attack on a prominent thinktank.

Star Blizzard is known to be run by the FSB’s Centre 18 unit, whereas Fancy Bear is more likely controlled by the General Staff Main Intelligence Directorate (GRU) 85th special Service Centre’s (GTsSS) Unit 26165 unit.

While both the FSB and GRU are successor units to the Soviet-era KGB beloved by generations of spy fiction writers, the FSB is responsible for counter-intelligence, state security and intelligence gathering outside Russia’s borders, and reports directly to Vladimir Putin.

The GRU, meanwhile, is the primary intelligence service of the Russian Armed Services, and unlike the FSB is ultimately subordinate to Moscow’s military command structure. The GRU is considered to be Russia’s largest intelligence service, and it also controls the country’s infamous Spetsnaz special forces.

Formed during the Cold War, the Spetsnaz saw action during the Prague Spring of 1968 and the Soviet invasion of Afghanistan. More recently they were the so-called Little Green Men seen in Crimea prior to its illegal annexation from Ukraine in 2014, and have participated in various actions on Ukrainian soil since February 2022, including sabotage against key targets, and potentially assassination attempts against Ukrainian president Volodymyr Zelensky.

Read more on Hackers and cybercrime prevention


Fancy Bear hackers still exploiting Microsoft Exchange flaw

ArielleWaldman

By: Arielle Waldman


Patch Tuesday: Microsoft fixes zero-days in Word and Streaming Service

AlexScroxton

By: Alex Scroxton


Akamai bypasses mitigation for critical Microsoft Outlook flaw

ArielleWaldman

By: Arielle Waldman


Mandiant: Dangerous MS Outlook zero-day widely used against Ukraine

AlexScroxton

By: Alex Scroxton

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366562615/Fancy-Bear-targets-Nato-entities-via-critical-Outlook-flaw

Tags: Fancytargetstechnology
Previous Post

AMD goes after Nvidia with AI accelerator and software library

Next Post

Former Post Office investigator called subpostmaster campaigners ‘crooks’

49ers reportedly nearing ‘divorce’ with Brandon Aiyuk, void WR’s 2026 guarantees – Yahoo Sports

49ers on the Brink of Parting Ways with Brandon Aiyuk, Set to Void His 2026 Contract Guarantees

November 23, 2025
2025/26 World Cup Ski jumping season opens with dominant wins by Murayama and Tschofenig – Olympics.com

2025/26 World Cup Ski jumping season opens with dominant wins by Murayama and Tschofenig – Olympics.com

November 23, 2025
The A.I. Boom Is Driving the Economy. What Happens if It Falters? – The New York Times

The A.I. Boom Fuels Economic Growth-But What If It Starts to Slow?

November 23, 2025
‘Baywatch’ returns to local beaches as part of efforts to save the entertainment industry – Santa Monica Daily Press

Baywatch’ Makes Waves on Local Beaches in a Daring Revival of the Entertainment Industry

November 23, 2025
West Coast Health Alliance protests new language on CDC webpage falsely linking vaccines and autism – KGW

West Coast Health Alliance Pushes Back Against False Claims Linking Vaccines to Autism on CDC Website

November 23, 2025
Swalwell tells CNN why he’s running for governor of California – CNN

Swalwell tells CNN why he’s running for governor of California – CNN

November 23, 2025
SCV News | CSUN Grad Students Publish Landmark Study on Coral Reef Population Declining – SCVNews.com

SCV News | CSUN Grad Students Publish Landmark Study on Coral Reef Population Declining – SCVNews.com

November 22, 2025
RFK Jr. says he ordered CDC language change on vaccines, autism: ‘not supported by science’ – New York Post

RFK Jr. says he ordered CDC language change on vaccines, autism: ‘not supported by science’ – New York Post

November 22, 2025
Scientists discover new type of lion roar – Live Science

Scientists Uncover a Brand-New Type of Lion Roar

November 22, 2025
The Dunkin’ Breakfast Dupe You Can Find In Sam’s Club’s Frozen Section – Yahoo

Uncover the Ultimate Dunkin’ Breakfast Hack Lurking in Sam’s Club’s Frozen Aisle!

November 22, 2025

Categories

Archives

November 2025
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
« Oct    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (932)
  • Economy (952)
  • Entertainment (21,827)
  • General (18,334)
  • Health (9,992)
  • Lifestyle (962)
  • News (22,149)
  • People (956)
  • Politics (965)
  • Science (16,165)
  • Sports (21,453)
  • Technology (15,932)
  • World (939)

Recent News

49ers reportedly nearing ‘divorce’ with Brandon Aiyuk, void WR’s 2026 guarantees – Yahoo Sports

49ers on the Brink of Parting Ways with Brandon Aiyuk, Set to Void His 2026 Contract Guarantees

November 23, 2025
2025/26 World Cup Ski jumping season opens with dominant wins by Murayama and Tschofenig – Olympics.com

2025/26 World Cup Ski jumping season opens with dominant wins by Murayama and Tschofenig – Olympics.com

November 23, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version