A hole in Microsoft Office is being exploited by bad actors, including Russian hackers targeting Ukraine's government.
Ukraine's Computer Emergency Response Team (CERT) says that Russian hackers are exploiting CVE-2026-21509, a recently patched vulnerability in multiple versions of Microsoft Office.
APT28's attacks use specially crafted Microsoft Rich Text Format (RTF) documents to kick off a multistage infection chain to deliver malicious payloads.
APT28 exploited a Microsoft Office flaw to deliver MiniDoor and Covenant Grunt malware in targeted attacks across Ukraine and Eastern Europe.
Ukraine’s CERT says the bug went from disclosure to active exploitation in days Russia-linked attackers are already ...
The hosting provider's compromise allowed attackers to deliver malware through tainted software updates for six months.
It's believed that, between June and November 10/December 2, 2025 (independent security experts and its hosting provider ...