Tag: Microsoft Office

APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks
News

APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks

Attacks using a recently revealed Microsoft Office security vulnerability have been linked to the Russia-affiliated state-sponsored threat actor APT28 (also known as UAC-0001) as part of a campaign called Operation Neusploit. Three days after Microsoft made the bug public, on January 29, 2026, Zscaler ThreatLabz reported that it saw the hacker organization using the vulnerability as a weapon in assaults against people in Romania, Slovakia, and Ukraine. CVE-2026-21509 (CVSS score: 7.8) is a Microsoft Office security feature bypass vulnerability that could enable an unauthorized attacker to deliver a specially designed Office file and cause it to activate. According to security experts Sudeep Singh and Roy Tay, social engineering lures were created in both English and localized lan...
Fake Microsoft Office add-in tools push malware via SourceForge
News

Fake Microsoft Office add-in tools push malware via SourceForge

By distributing phony Microsoft add-ins that infect users' machines with malware, threat actors are leveraging SourceForge to mine and steal cryptocurrency. Many open-source project communities use SourceForge.net because it is a reliable platform for hosting and distributing software and offers features like bug tracking, version control, and specialized forums and wikis. Malware is rarely disseminated using it, despite the fact that its open project submission methodology allows for a lot of abuse. Over 4,604 systems, the most of which are in Russia, have been affected by the latest campaign that Kaspersky discovered. According to Kaspersky, the malicious project was indexed by search engines, generating traffic from users looking for read more about Fake Microsoft Office ad...
New Phishing Attack Uses Clever Microsoft Office Trick to Deploy NetSupport RAT
News

New Phishing Attack Uses Clever Microsoft Office Trick to Deploy NetSupport RAT

The goal of a recent phishing attempt is to infect American companies with the remote access malware known as NetSupport RAT. Operation PhantomBlu is the name given to the activities that is being tracked by the Israeli cybersecurity company Perception Point. Security researcher Ariel Davidpur stated, "The PhantomBlu operation introduces a nuanced exploitation method that deviates from the standard delivery mechanism of NetSupport RAT by leveraging OLE (Object Linking and Embedding) template manipulation, exploiting Microsoft Office document templates to execute malicious code while evading detection." A malicious branch of the legitimate remote desktop program NetSupport Manager read more New Phishing Attack Uses Clever Microsoft Office Trick to Deploy NetSupport RAT. Get up ...