Microsoft releases urgent Office patch. Russian-state hackers pounce.
Russian-state hackers weaponized Microsoft Office vulnerability CVE-2026-21509 within 48 hours to deploy encrypted, fileless in-memory backdoors against diplomatic, maritime, and transport organizations.
APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks
Russia-linked UAC-0001 exploited CVE-2026-21509 in malicious Office RTFs to deliver MiniDoor and PixyNetLoader targeting users in Ukraine, Slovakia, and Romania.