{"id":903,"date":"2026-02-02T07:41:50","date_gmt":"2026-02-02T05:41:50","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=903"},"modified":"2026-02-04T07:42:36","modified_gmt":"2026-02-04T05:42:36","slug":"russia-linked-apt28-attackers-already-abusing-new-microsoft-office-zero-day","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2026\/02\/02\/russia-linked-apt28-attackers-already-abusing-new-microsoft-office-zero-day\/","title":{"rendered":"Russia-linked APT28 attackers already abusing new Microsoft Office zero-day"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Russia-linked attackers are already exploiting Microsoft&#8217;s latest Office zero-day, with Ukraine&#8217;s national cyber defense team warning that the same bug is being used to target government agencies inside the country and organizations across the EU.<a href=\"https:\/\/twitter.com\/intent\/tweet?text=Russia-linked%20APT28%20attackers%20already%20abusing%20new%20Microsoft%20Office%20zero-day&amp;url=https:\/\/www.theregister.com\/2026\/02\/02\/russialinked_apt28_microsoft_office_bug\/%3futm_medium%3dshare%26utm_content%3darticle%26utm_source%3dtwitter&amp;via=theregister\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><a href=\"https:\/\/www.facebook.com\/dialog\/feed?app_id=1404095453459035&amp;display=popup&amp;link=https:\/\/www.theregister.com\/2026\/02\/02\/russialinked_apt28_microsoft_office_bug\/%3futm_medium%3dshare%26utm_content%3darticle%26utm_source%3dfacebook\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><a href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https:\/\/www.theregister.com\/2026\/02\/02\/russialinked_apt28_microsoft_office_bug\/%3futm_medium%3dshare%26utm_content%3darticle%26utm_source%3dlinkedin&amp;title=Russia-linked%20APT28%20attackers%20already%20abusing%20new%20Microsoft%20Office%20zero-day&amp;summary=Ukraine%e2%80%99s%20CERT%20says%20the%20bug%20went%20from%20disclosure%20to%20active%20exploitation%20in%20days\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><a href=\"https:\/\/api.whatsapp.com\/send?text=https:\/\/www.theregister.com\/2026\/02\/02\/russialinked_apt28_microsoft_office_bug\/%3futm_medium%3dshare%26utm_content%3darticle%26utm_source%3dwhatsapp\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In an&nbsp;<a href=\"https:\/\/cert.gov.ua\/article\/6287250\">alert published on Sunday<\/a>, CERT-UA says the activity is being driven by UAC-0001, better known as &#8220;APT28&#8221; or &#8220;Fancy Bear&#8221;, and hinges on CVE-2026-21509, a security feature bypass bug in Microsoft Office that&nbsp;<a href=\"https:\/\/www.theregister.com\/2026\/01\/27\/office_zeroday_exploited_in_the\/\">Microsoft disclosed last week<\/a>&nbsp;alongside a warning that attackers were already exploiting it in the wild.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2026\/02\/02\/russia-linked-apt28-attackers-already-abusing-new-microsoft-office-zero-day\/\" target=\"_self\"><a href=\"https:\/\/www.theregister.com\/2026\/02\/02\/russialinked_apt28_microsoft_office_bug\/\">Russia-linked attackers abuse new Microsoft Office zero-day \u2022 The Register<\/a><span class=\"screen-reader-text\">: Russia-linked APT28 attackers already abusing new Microsoft Office zero-day<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>Russia-linked attackers are already exploiting Microsoft&#8217;s latest Office zero-day, with Ukraine&#8217;s national cyber defense team warning that the same bug is being used to target government agencies inside the country and organizations across the EU. In an&nbsp;alert published on Sunday, CERT-UA says the activity is being driven by UAC-0001, better&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17],"tags":[72,9],"class_list":["post-903","post","type-post","status-publish","format-standard","hentry","category-vulnerability","tag-72","tag-russia"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/903","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=903"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/903\/revisions"}],"predecessor-version":[{"id":904,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/903\/revisions\/904"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=903"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=903"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=903"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}