Live data from Hacker News

iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

isightpartners.com

1–10 of 78 posts

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#4
> An attacker can exploit this vulnerability to execute arbitrary code but will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it

So, it's a remote exploit, but requires the user to open a document.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#6
Is it me or is the linked article remarkably content free given the about of security babble it contains? The nice aspect of the Heartbleed branding was its simple and clear message, not having opaque sentences such as "Visibility into this campaign indicates targeting across the following domains" and self serving platitudes such as "As part of our normal cyber threat intelligence operations, iSIGHT Partners is tracking a growing drum beat of cyber espionage activity out of Russia."

edit: The meat of the vulnerability is in the "Working with Microsoft, we discovered the following" section, over halfway down the page.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#7
How does

> When exploited, the vulnerability allows an attacker to remotely execute arbitrary code

go along with

> [...] will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it [...]

Is this a fucking joke? Looks like some company just want to push their name out there and get some free media exposure.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#8
post #4

> An attacker can exploit this vulnerability to execute arbitrary code but will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it So, it's a remote exploit, but requires the user to open a document.

[deleted]

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#10
post #3

Can't believe they designed a logo especially for this worm (and gave a fancy name). There's apparently a marketing campaign in vulnerability discoveries too.

This is brand new. After Heartbleed, people realized that branding vulnerabilities is great for driving business. A year ago, this was unheard of.
Post reply on HN