kokumօtօ[verified]@__kokumotoActive Exploitation
CISA reports confirmed ransomware exploitation across 10 CVEs, indicating active attacks in the wild.
Misbar | مسبار[verified]@MisbarSecActive Exploitation
A new phishing campaign employs malicious Excel files to deliver the XWorm RAT, exploiting CVE‑2018‑0802 and other vulnerabilities, underscoring active exploitation and urging Office updates and advanced AV protections.
ܛܔܔܔܛܔܛܔܛ[verified]@skocherhanActive Exploitation
The post describes an active phishing campaign that exploits CVE-2018-0802 via malicious Excel attachments to deliver XWorm RAT, outlining the attack chain and techniques.
TechNadu[verified]@TechNaduActive Exploitation
The tweet reports that Cloud Atlas APT is actively exploiting CVE-2018-0802 against Russian and Belarusian targets, but provides no technical details, patch info, or PoC.
Zeeshan Khan ⚡🜏 | InfoSec & Chaos[verified]@zeeshankghouriPatch
The post advises patching the legacy Office CVE-2018-0802 and outlines general defensive measures, indicating the vulnerability remains a concern but no active exploitation is reported.
Machina Record[verified]@MachinaRecordActive Exploitation
The text reports that CVE-2026-1731 and CVE-2025-49113 are being actively exploited in ransomware and other attacks, but provides no PoC, patch, or technical details.
Machina Record[verified]@MachinaRecordActive Exploitation
The post reports that CVE‑2018‑0802 was actively exploited by hackers to embed XWorm 7.2 in JPEG files and hijack PCs, with no PoC, exploit code, patch, or technical details provided.
Dr.Philippe Vynckier, CISSP - Influencer[verified]@PVynckierActive Exploitation
The post reports a new XWorm RAT campaign that exploits CVE-2018-0802 via Excel to bypass detection, indicating ongoing real‑world attacks.