feedzop-word-mark-logo
searchLogin
Feedzop
homeFor YouIndiaIndia
You
bookmarksYour BookmarkshashtagYour Topics
Trending
Terms of UsePrivacy PolicyAboutJobsPartner With Us

© 2026 Advergame Technologies Pvt. Ltd. ("ATPL"). Gamezop ® & Quizzop ® are registered trademarks of ATPL.

Gamezop is a plug-and-play gaming platform that any app or website can integrate to bring casual gaming for its users. Gamezop also operates Quizzop, a quizzing platform, that digital products can add as a trivia section.

Over 5,000 products from more than 70 countries have integrated Gamezop and Quizzop. These include Amazon, Samsung Internet, Snap, Tata Play, AccuWeather, Paytm, Gulf News, and Branch.

Games and trivia increase user engagement significantly within all kinds of apps and websites, besides opening a new stream of advertising revenue. Gamezop and Quizzop take 30 minutes to integrate and can be used for free: both by the products integrating them and end users

Increase ad revenue and engagement on your app / website with games, quizzes, astrology, and cricket content. Visit: business.gamezop.com

Property Code: 5571

Home / Technology / Russian Hackers Exploit New MS Office Flaw in Ukraine

Russian Hackers Exploit New MS Office Flaw in Ukraine

3 Feb

•

Summary

  • Russian hackers targeted Ukrainian government agencies with a new flaw.
  • Microsoft released an emergency patch for CVE-2026-21509 on January 26, 2026.
  • APT28, linked to Russian intelligence, is identified as the threat actor.
Russian Hackers Exploit New MS Office Flaw in Ukraine

Russian state-sponsored hackers, identified as APT28, have targeted Ukrainian government entities using a critical Microsoft Office vulnerability. This exploitation occurred mere days after Microsoft issued an emergency patch for CVE-2026-21509 on January 26, 2026. The vulnerability, which allows unauthorized attackers to bypass security features, had a severity score of 7.6/10 and was reportedly exploited in the wild as a zero-day.

Cybercriminals sent malicious DOC files to dozens of government-related addresses, with some lures referencing EU COREPER consultations and others impersonating Ukraine's Hydrometeorological Center. CERT-UA, Ukraine's Computer Emergency Response Team, identified the attack vector as malware loader previously used by APT28 in a June 2025 attack on Ukrainian government employees. The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-21509 to its catalog of known exploited vulnerabilities, urging immediate patching.

Disclaimer: This story has been auto-aggregated and auto-summarised by a computer program. This story has not been edited or created by the Feedzop team.
Russian hackers exploited the CVE-2026-21509 vulnerability in Microsoft Office, which allows bypassing security features.
The attacks are attributed to APT28, a Russian state-sponsored threat actor linked to the GRU.
CISA added CVE-2026-21509 to its catalog of known exploited vulnerabilities (KEV) and urges immediate patching.

Read more news on

Technologyside-arrow
trending

Tanker stalls Mumbai-Pune expressway

trending

ChatGPT outage reported today

trending

IT index plummets

trending

Anthropic AI triggers 'SaaSpocalypse'

trending

HAL out of stealth jet

trending

India U19 World Cup Semi

trending

India vs South Africa warm-up

trending

Lakers beat Nets, 112-100

trending

HDFC Bank share price target

You may also like

AI Revolutionizes SOCs: Faster, Smarter Defense

28 Jan • 41 reads

article image

Olympics Drone Threat: US Steps Up Security Planning

27 Jan • 57 reads

article image

Microsoft Hands Over Encryption Keys to FBI

25 Jan • 55 reads

article image

HPE OneView Under Siege: Critical Flaw Exploited

20 Jan • 97 reads

article image

China Bans US & Israeli Cybersecurity Software

14 Jan • 154 reads

article image