Russian hackers target EU countries through a simple security flaw in Microsoft Outlook

We now know how APT28, a known Russian state-sponsored threat actor, managed to compromise multiple email accounts of the Executive Committee of the German Social Democratic Party in 2022 – via a security flaw in Microsoft Outlook.

The German federal government said APT28 exploited a vulnerability in Microsoft Outlook, tracked as CVE-2023-23397, to compromise the accounts.