OS Dev[verified]@OSdev_Disclose
The passage announces a high‑severity elevation‑of‑privilege flaw in Outlook, provides technical details and a GitHub link to a PoC, but contains no indication of active exploitation or patches.
XINTRA[verified]@XintraOrgGeneral
This text describes a lab that emulates APT28 targeting Ukrainian logistics, referencing CVE-2023-23397 and other techniques, but it does not provide evidence of a PoC, exploitation, or patches.
OS Dev[verified]@OSdev_Disclosure
The post announces key details about CVE-2023-23397, explaining how a specially crafted Outlook message triggers NTLM authentication to allow credential relay, but it does not mention PoC code, active exploitation, or patches.
Inferlume[verified]@inferlume_hqActive Exploitation
APT28 is actively exploiting CVE-2023-23397 in Outlook, confirmed by CISA KEV and corroborated by Microsoft MSTIC and FortiGuard, with a federal patch deadline set for May 12.
Justin Elze[verified]@HackingLZGeneral
The tweet only references CVE‑2023‑23397 in relation to Russia, with no further details or actionable information.
JTCrawford[verified]@JtCrawfordActive Exploitation
The tweet reports that APT28 exploited CVE-2023-23397 in Outlook, affecting over 30 Ukrainian critical infrastructure targets via NTLM hash theft without user interaction, and urges immediate patching.
ThreatCluster[verified]@threatclusterActive Exploitation
Rapid7 reports active exploitation of CVE-2020-16875 and CVE-2023-23397, enabling authenticated RCE and NTLM relay attacks on affected organizations, with no mention of mitigation or PoC code.
Audn AI[verified]@audn_aiGeneral
The post provides a general pen‑testing tip to practice exploitation of CVE‑2023‑23397, mentioning the vulnerability type but not offering PoC, exploit code, or patch details.