Tools

News

Notícias

Classificados

Cursos

Broker

IPv4:

IPv6:

 

UpOrDown
Ping
MTR
Smokeping
MTU Detect
Portscan
DNS
HTTP/SSL
My IP
IP Calc
IP Extractor
Uptime Monitor

Office Patch Exploited by Russian Hackers

Image © Arstechnica
A critical Microsoft Office vulnerability patch CVE-2026-21509 was rapidly weaponized by Russian-state hackers, compromising devices in diplomatic, maritime, and transport networks across nine countries.

The Russian-state threat group behind APT28, Fancy Bear, Sednit, Forest Blizzard, and Sofacy wasted no time exploiting CVE-2026-21509, targeting diplomatic, maritime, and transportation organizations in nine countries. The attack unfolded within 48 hours of Microsoft releasing an urgent security update.

Researchers from Trellix say the attackers developed an advanced in-memory exploit that deployed two new backdoors, BeardShell and NotDoor, after reverse-engineering the patch. The campaign was designed to be stealthy: payloads were encrypted and executed in memory, avoiding disk writes.

The infection chain began with compromised government accounts, likely used by trusted email holders, and progressed through legitimate cloud-based command-and-control channels to avoid standard network controls.

Trellix notes the spear-phishing wave delivered at least 29 lures, targeting 40 percent defense ministries, 35 percent transport/logistics operators, and 25 percent diplomatic entities. The victims were concentrated in Eastern Europe and nearby regions.

Experts warn that CVE-2026-21509 demonstrates how quickly state-backed actors can weaponize new flaws, shrinking the window for defenders to patch critical systems. The campaign’s modular approach—phish, in-memory backdoors, and cloud-based C2—highlights the growing use of trusted channels to mask malicious activity.

“The campaign’s rapid execution and cloud-based C2 show how defenders must act fast to patch critical systems,” Trellix researchers said.

 

Arstechnica

Notícias relacionadas

S&P rebaixa rating da Oi para default
IA Offline: Segurança e Privacidade em 2026
AT&T e AWS: nuvem, IA, fibra e satélites
STJ valida assinatura Gov.br e afasta firma
Anatel Aprova Plano Vivo para Regularizar Ofertas
Mercado PCM: licenciamento IA pela Microsoft

O ISP.Tools sobrevive graças aos anúncios.

Considere desativar seu bloqueador de anúncios.
Prometemos não ser intrusivos.

Consentimento para cookies

Utilizamos cookies para melhorar a sua experiência no nosso site.

Ao utilizar o nosso site, você concorda com o uso de cookies. Saiba mais