Malware News Shadowy Hackers Accidentally Reveal Two Zero-Days to Security Researchers

Solarquest

Moderator
Thread author
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
An unidentified hacker group appears to have accidentally exposed two fully-working zero-days when they've uploaded a weaponized PDF file to a public malware scanning engine.
The zero-days where spotted by security researchers from Slovak antivirus vendor ESET, who reported the issues to Adobe and Microsoft, which in turn, had them patched within two months.

Zero-days caught while still under development
...


Cherepanov spotted two suspicious PDF samples [1, 2] at the end of March. Both zero-days are now patched. Microsoft patched CVE-2018-8120 last week, in the May 2018 Patch Tuesday, and Adobe patched CVE-2018-4990 yesterday in APSB18-09.



VirusTotal

VirusTotal
 

RoboMan

Level 35
Verified
Top Poster
Content Creator
Well-known
Jun 24, 2016
2,400
maxresdefault.jpg
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top