Targeted Attacks Against South Korean Entities May Have Been as Early as November 2017

2018-02-02 Flashpoint-intel

https://www.flashpoint-intel.com/blog/targeted-attacks-south-korean-entities/

Thumbnail for Targeted Attacks Against South Korean Entities May Have Been as Early as November 2017

Flashpoint’s excerpt is a vulnerability prioritization briefing for the week of December 20–26, 2025, focused on remotely exploitable issues with public exploits and available fixes. The highlighted items include NVIDIA Isaac Launchable hardcoded credentials and improper execution privileges issues, n8n workflow expression evaluation remote code execution, and MongoDB Zlib compressed protocol header handling that can disclose uninitialized heap memory. The report explains Flashpoint scoring inputs such as analyst-adjusted CVSS, social risk, ransomware-likelihood similarity, exploit references, affected products, solution data, and exposure metrics. No North Korea, Lazarus, Kimsuky, Andariel, APT37, or APT38 activity is supported by the provided excerpt, so it should be treated as general vulnerability intelligence rather than DPRK-attributed CTI.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 28.0.0.137 2018-02-02 2018-03-14
YARA crime_ole_loadswf_cve_2018_4878 2018-02-02 2018-02-02
HASH 9593d277b42947ef28217325bcc1fe50 2018-02-02 2018-02-02
HASH 4c1533cbfb693da14e54e5a92ce6faba 2018-02-02 2018-02-02
HASH 5f97c5ea28c0401abc093069a50aa1f8 2018-02-02 2018-02-02
HASH 1f93c09eed6bb17ec46e63f00bd40ebb 2018-02-02 2018-02-02
URL http://www.1588-2040.co.kr/desi… 2018-02-02 2018-02-02
URL http://www.dylboiler.co.kr/admi… 2018-02-02 2018-02-02

Related Reports

« Back