Russian Hackers Exploit Fresh Office Flaw Hours After Patch

1 min read
Source: Ars Technica
Russian Hackers Exploit Fresh Office Flaw Hours After Patch
Photo: Ars Technica
TL;DR Summary

Within 48 hours of Microsoft issuing an urgent Office patch for CVE-2026-21509, the Russian-state group APT28 launched a fast, in-memory, fileless campaign that installed new backdoors (BeardShell and NotDoor) via staged spear-phishing across nine countries, targeting defense ministries, transportation operators, and diplomatic entities, with command-and-control hosted on legitimate cloud services to evade detection.

Share this article

Reading Insights

Total Reads

1

Unique Readers

13

Time Saved

4 min

vs 4 min read

Condensed

93%

75853 words

Want the full story? Read the original article

Read on Ars Technica