ܛܔܔܔܛܔܛܔܛ[verified]@skocherhanGeneral
The content lists several CVE identifiers along with unrelated IP addresses and a domain, but provides no additional context, exploitation details, or mitigation information.
ThreatCluster[verified]@threatclusterActive Exploitation
The post highlights that APT28 is actively exploiting Microsoft Office CVE‑2012‑0158 and CVE‑2017‑11882, achieving remote code execution through malicious documents.
The Daily Tech Feed[verified]@dailytechonxActive Exploitation
CVE-2017-11882 remains actively exploited by cybercriminals using Agent Tesla; users are urged to patch and remain vigilant.
ThreatSynop[verified]@ThreatSynopActive Exploitation
The article reports a new malware campaign that weaponizes CVE-2017-11882 via a weaponized XLS attachment, using an HTA → PowerShell chain to download a Base64‑encoded .NET payload hidden in a PNG file, and advises tracking via VT similarity and YARA.
Karsten Hahn@struppigelDisclosure
The tweet links to a blog post that details how the Equation Editor CVE-2017-11882 works, likely including a PoC, but it provides no evidence of active exploitation, patches, or debunking.
Umid Mammadov@umidcybersDisclosure
Lab analysis of CVE‑2017‑11882 shows in‑memory unpacking, UAC bypass via slui.exe, and hidden C2 traffic on port 8836, but no active exploitation or patch information is provided.
CVETrends@CVEShieldGeneral
A brief tweet listing five trending CVEs without providing any technical details, fixes, or exploit information.
Felix Kiprop@KipropFelix48General
The post references a document containing an exploit for CVE‑2017‑11882 but lacks evidence of active attacks, detailed technical info, or patching guidance.