Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
APT28 Exploits MSHTML Vulnerability Before February 2026 Patch

APT28 Exploits MSHTML Vulnerability Before February 2026 Patch

Posted on March 2, 2026 By CWS

A critical vulnerability in Microsoft’s MSHTML Framework has been reportedly exploited by the Russian-affiliated threat group APT28 before it was patched in February 2026. According to Akamai, this high-severity flaw, identified as CVE-2026-21513 with a CVSS score of 8.8, was exploited in the wild as a zero-day.

Understanding the MSHTML Vulnerability

The vulnerability in question involves a security feature bypass within the MSHTML Framework. Microsoft highlighted that this flaw allows unauthorized attackers to circumvent security mechanisms over a network. The issue was addressed during the February 2026 Patch Tuesday, with credits to Microsoft Threat Intelligence Center, Microsoft Security Response Center, Office Product Group Security Team, and Google’s Threat Intelligence Group for their collaborative efforts in identifying the flaw.

The vulnerability can be weaponized by attackers who trick victims into opening a malicious HTML or shortcut (LNK) file delivered via links or email attachments. Upon opening, it alters browser and Windows Shell operations, enabling code execution by bypassing security protections.

APT28’s Exploitation Tactics

APT28’s exploitation of this flaw was highlighted by Akamai, which discovered a malicious file uploaded to VirusTotal on January 30, 2026, linked to the group’s infrastructure. The Computer Emergency Response Team of Ukraine (CERT-UA) also flagged this activity, linking it to previous APT28 exploits involving a different Microsoft Office vulnerability (CVE-2026-21509).

The flaw is rooted in the ‘ieframe.dll’ component that handles hyperlink navigation, resulting from inadequate validation of URLs. This allows attacker-controlled data to traverse code paths that invoke ShellExecuteExW, facilitating the execution of resources outside the browser’s security context.

Technical Insights and Future Threats

Security expert Maor Dahan explained that the exploit involves a Windows Shortcut (LNK) file embedding an HTML document. This file communicates with a domain linked to APT28, known for its extensive use in multi-stage payload campaigns. The exploit manipulates nested iframes and multiple DOM contexts to breach trust boundaries.

Akamai warns that this technique can bypass security measures like Mark-of-the-Web (MotW) and Internet Explorer Enhanced Security Configuration (IE ESC), lowering security contexts and allowing malicious code execution outside of the browser sandbox through ShellExecuteExW. While the current campaign utilizes LNK files, any component embedding MSHTML could potentially trigger the vulnerable code path, suggesting a need for vigilance against diverse delivery mechanisms beyond LNK-based phishing.

The discovery of this vulnerability and its exploitation by APT28 underscores the ongoing threat posed by state-sponsored cyber actors. Organizations are urged to apply security patches promptly and remain vigilant against evolving cyber threats.

The Hacker News Tags:Akamai, APT28, CERT-UA, CVE-2026-21513, cyber attack, Cybersecurity, Exploit, malicious LNK, Microsoft, MSHTML, network security, Patch Tuesday, threat intelligence, Vulnerability, zero-day

Post navigation

Previous Post: Unencrypted TPMS in Major Cars Pose Privacy Risks
Next Post: Nick Andersen Steps Up as Acting CISA Director

Related Posts

Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails The Hacker News
The State of AI in the SOC 2025 The State of AI in the SOC 2025 The Hacker News
Iranian Hackers Launch ‘SpearSpecter’ Spy Operation on Defense & Government Targets Iranian Hackers Launch ‘SpearSpecter’ Spy Operation on Defense & Government Targets The Hacker News
Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites The Hacker News
SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release The Hacker News
SEO Poisoning Campaign Targets 8,500+ SMB Users with Malware Disguised as AI Tools SEO Poisoning Campaign Targets 8,500+ SMB Users with Malware Disguised as AI Tools The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chrome’s AI Assistant Vulnerability Patched to Prevent Risks
  • OCRFix Botnet Trojan Uses Blockchain for Stealth Operations
  • OpenClaw Flaw Could Allow AI Takeover via Malicious Sites
  • Critical SD-WAN Vulnerability and AI Threats Emerge
  • Widespread SonicWall Firewall Attacks Exploiting Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chrome’s AI Assistant Vulnerability Patched to Prevent Risks
  • OCRFix Botnet Trojan Uses Blockchain for Stealth Operations
  • OpenClaw Flaw Could Allow AI Takeover via Malicious Sites
  • Critical SD-WAN Vulnerability and AI Threats Emerge
  • Widespread SonicWall Firewall Attacks Exploiting Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News