The Zero-Click Vulnerability: Akamai Uncovers Incomplete Patch for APT28 Exploit
ID: 81456a2a-eb26-5e96-ad14-5ad2b287c1c1
STIX ID: report--81456a2a-eb26-5e96-ad14-5ad2b287c1c1
Feed Name: securityonline.info
Threat Score
**Executive summary:** Akamai found that an incomplete patch left a zero-click vulnerability (CVE-2026-32202) in Windows that allows weaponized LNK files to trigger automatic UNC resolution when Explorer renders a folder, causing an SMB authentication handshake that exposes Net-NTLMv2 hashes; APT28 has used this in campaigns against Ukraine and EU targets, and administrators are advised to monitor for unusual external SMB connections and enforce NTLM protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
