Cybersecuritynews
Fancy Bear Exploits Microsoft Zero-Day Vulnerability CVE-2026-21509
First seen 10 Feb 2026, 16:42 UTC
•

•83% similarity
•34.1
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The Russian cyber espionage group Fancy Bear, also known as APT28, has initiated Operation Neusploit, exploiting a zero-day vulnerability (CVE-2026-21509) in Microsoft RTF files. This vulnerability allows attackers to execute arbitrary code on victim systems, leading to the deployment of backdoors and email stealers, targeting various organizations.
ThreatCluster AI
Timeline
2026-01-26
CVE-2026-21509 published and added to CISA KEV
2026-01-27
First public PoC for CVE-2026-21509 released
2026-02-10
Fancy Bear launches Operation Neusploit exploiting CVE-2026-21509