Russian state hackers exploit new Microsoft Office flaw in attacks on Ukraine, EU
ID: 7cc20bc3-0821-5a3d-9714-b26c30b05057
STIX ID: report--7cc20bc3-0821-5a3d-9714-b26c30b05057
Feed Name: The Record from Recorded Future News
Threat Score
Researchers and CERT-UA attribute active exploitation of Microsoft Office vulnerability CVE-2026-21509 to APT28 (Fancy Bear), where malicious Office documents delivered loaders and backdoors (PixyNetLoader, MiniDoor, Covenant) to targets in Ukraine, Slovakia, Romania and other European government entities; Microsoft has released a patch and the vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
