Cybersecuritynews Fancy Bear Exploits Microsoft Zero-Day Vulnerability CVE-2026-21509
Article Content
Browse articles
The Russian cyber espionage group Fancy Bear, also known as APT28, has initiated Operation Neusploit, exploiting a zero-day vulnerability (CVE-2026-21509) in Microsoft RTF files. This vulnerability allows attackers to execute arbitrary code on victim systems, leading to the deployment of backdoors and email stealers, targeting various organizations.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
Timeline
2026-01-26
CVE-2026-21509 published and added to CISA KEV
2026-01-27
First public PoC for CVE-2026-21509 released
2026-02-10
Fancy Bear launches Operation Neusploit exploiting CVE-2026-21509
More articles in this cluster (3)
Following this threat?
Track Apt28, Microsoft and CVE-2026-21509 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical RCE Vulnerability in Zimbra Exploited by Attackers A critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite is being actively exploited by attackers. The flaw, which affects versions prior to 10.1.20, allows unauthenticated attackers to execute arbitrary commands as the Zimbra user through improper input sanitization in SNMP…
Russia's Hybrid Warfare Threatens UK with Cyberattacks and Sabotage Russia has escalated threats against the UK following its support for Ukraine, warning of 'consequences' for British involvement. Concurrently, Russian-linked cyberattacks, including a ransomware attack on the pathology lab Synnovis, have severely disrupted NHS services in London, affecting over 800 operations and 700…