APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks

Attacks using a recently revealed Microsoft Office security vulnerability have been linked to the Russia-affiliated state-sponsored threat actor APT28 (also known as UAC-0001) as part of a campaign called Operation Neusploit.

Three days after Microsoft made the bug public, on January 29, 2026, Zscaler ThreatLabz reported that it saw the hacker organization using the vulnerability as a weapon in assaults against people in Romania, Slovakia, and Ukraine.

CVE-2026-21509 (CVSS score: 7.8) is a Microsoft Office security feature bypass vulnerability that could enable an unauthorized attacker to deliver a specially designed Office file and cause it to activate.

According to security experts Sudeep Singh and Roy Tay, social engineering lures were created in both English and localized languages (Romanian, Slovak, and Ukrainian) to target individuals in the corresponding nations read more about APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *