Tools

News

Notícias

Classificados

Cursos

Broker

IPv4:

IPv6:

 

UpOrDown
Ping
MTR
Smokeping
MTU Detect
Portscan
DNS
HTTP/SSL
My IP
IP Calc
IP Extractor
Uptime Monitor

Office Patch Exploited by Russian Hackers

Image © Arstechnica
A critical Microsoft Office vulnerability patch CVE-2026-21509 was rapidly weaponized by Russian-state hackers, compromising devices in diplomatic, maritime, and transport networks across nine countries.

The Russian-state threat group behind APT28, Fancy Bear, Sednit, Forest Blizzard, and Sofacy wasted no time exploiting CVE-2026-21509, targeting diplomatic, maritime, and transportation organizations in nine countries. The attack unfolded within 48 hours of Microsoft releasing an urgent security update.

Researchers from Trellix say the attackers developed an advanced in-memory exploit that deployed two new backdoors, BeardShell and NotDoor, after reverse-engineering the patch. The campaign was designed to be stealthy: payloads were encrypted and executed in memory, avoiding disk writes.

The infection chain began with compromised government accounts, likely used by trusted email holders, and progressed through legitimate cloud-based command-and-control channels to avoid standard network controls.

Trellix notes the spear-phishing wave delivered at least 29 lures, targeting 40 percent defense ministries, 35 percent transport/logistics operators, and 25 percent diplomatic entities. The victims were concentrated in Eastern Europe and nearby regions.

Experts warn that CVE-2026-21509 demonstrates how quickly state-backed actors can weaponize new flaws, shrinking the window for defenders to patch critical systems. The campaign’s modular approach—phish, in-memory backdoors, and cloud-based C2—highlights the growing use of trusted channels to mask malicious activity.

“The campaign’s rapid execution and cloud-based C2 show how defenders must act fast to patch critical systems,” Trellix researchers said.

 

Arstechnica

Related News

Anthropic keeps Claude ad-free, cites integrity
IQ Fiber Names Guthrie as COO
Salt Typhoon Docs Delayed, Cantwell Alleges
Vibe-Coded Log Colorizer Reflections
Nvidia-OpenAI $100B Deal Fizzles
TempGenius expands wireless humidity and temperature monitoring

ISP.Tools survives thanks to ads.

Consider disabling your ad blocker.
We promise not to be intrusive.

Cookie Consent

We use cookies to improve your experience on our site.

By using our site you consent to cookies. Learn more