Russian state hackers exploit Microsoft Office vulnerability, targeting global organizations

arstechnica.com

Russian-state hackers exploited a critical Microsoft Office vulnerability within 48 hours of a patch release, compromising organizations in multiple countries. The APT28 group used an advanced exploit for CVE-2026-21509, installing novel, encrypted backdoors that ran in memory to evade detection. Targets included diplomatic, maritime, and transport entities. The campaign, designed for stealth and speed, utilized compromised accounts and legitimate cloud services, demonstrating the rapid weaponization of vulnerabilities by advanced adversaries.


With a significance score of 4.8, this news ranks in the top 2.3% of today's 32488 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers: