Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
APT28 Exploits MSHTML Vulnerability Before February 2026 Patch

APT28 Exploits MSHTML Vulnerability Before February 2026 Patch

Posted on March 2, 2026 By CWS

A critical vulnerability in Microsoft’s MSHTML Framework has been reportedly exploited by the Russian-affiliated threat group APT28 before it was patched in February 2026. According to Akamai, this high-severity flaw, identified as CVE-2026-21513 with a CVSS score of 8.8, was exploited in the wild as a zero-day.

Understanding the MSHTML Vulnerability

The vulnerability in question involves a security feature bypass within the MSHTML Framework. Microsoft highlighted that this flaw allows unauthorized attackers to circumvent security mechanisms over a network. The issue was addressed during the February 2026 Patch Tuesday, with credits to Microsoft Threat Intelligence Center, Microsoft Security Response Center, Office Product Group Security Team, and Google’s Threat Intelligence Group for their collaborative efforts in identifying the flaw.

The vulnerability can be weaponized by attackers who trick victims into opening a malicious HTML or shortcut (LNK) file delivered via links or email attachments. Upon opening, it alters browser and Windows Shell operations, enabling code execution by bypassing security protections.

APT28’s Exploitation Tactics

APT28’s exploitation of this flaw was highlighted by Akamai, which discovered a malicious file uploaded to VirusTotal on January 30, 2026, linked to the group’s infrastructure. The Computer Emergency Response Team of Ukraine (CERT-UA) also flagged this activity, linking it to previous APT28 exploits involving a different Microsoft Office vulnerability (CVE-2026-21509).

The flaw is rooted in the ‘ieframe.dll’ component that handles hyperlink navigation, resulting from inadequate validation of URLs. This allows attacker-controlled data to traverse code paths that invoke ShellExecuteExW, facilitating the execution of resources outside the browser’s security context.

Technical Insights and Future Threats

Security expert Maor Dahan explained that the exploit involves a Windows Shortcut (LNK) file embedding an HTML document. This file communicates with a domain linked to APT28, known for its extensive use in multi-stage payload campaigns. The exploit manipulates nested iframes and multiple DOM contexts to breach trust boundaries.

Akamai warns that this technique can bypass security measures like Mark-of-the-Web (MotW) and Internet Explorer Enhanced Security Configuration (IE ESC), lowering security contexts and allowing malicious code execution outside of the browser sandbox through ShellExecuteExW. While the current campaign utilizes LNK files, any component embedding MSHTML could potentially trigger the vulnerable code path, suggesting a need for vigilance against diverse delivery mechanisms beyond LNK-based phishing.

The discovery of this vulnerability and its exploitation by APT28 underscores the ongoing threat posed by state-sponsored cyber actors. Organizations are urged to apply security patches promptly and remain vigilant against evolving cyber threats.

The Hacker News Tags:Akamai, APT28, CERT-UA, CVE-2026-21513, cyber attack, Cybersecurity, Exploit, malicious LNK, Microsoft, MSHTML, network security, Patch Tuesday, threat intelligence, Vulnerability, zero-day

Post navigation

Previous Post: Unencrypted TPMS in Major Cars Pose Privacy Risks
Next Post: Nick Andersen Steps Up as Acting CISA Director

Related Posts

Researchers Find VS Code Flaw Allowing Attackers to Republish Deleted Extensions Under Same Names Researchers Find VS Code Flaw Allowing Attackers to Republish Deleted Extensions Under Same Names The Hacker News
OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps The Hacker News
Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine The Hacker News
Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication The Hacker News
Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access The Hacker News
APT Intrusions, AI Malware, Zero-Click Exploits, Browser Hijacks and More APT Intrusions, AI Malware, Zero-Click Exploits, Browser Hijacks and More The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical SD-WAN Vulnerability and AI Threats Emerge
  • Widespread SonicWall Firewall Attacks Exploiting Vulnerabilities
  • Madison Square Garden Confirms Major Data Breach
  • Shield Your SaaS from Bot Threats with SafeLine WAF
  • CISA Alerts on RESURGE Malware Threat to Ivanti Devices

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical SD-WAN Vulnerability and AI Threats Emerge
  • Widespread SonicWall Firewall Attacks Exploiting Vulnerabilities
  • Madison Square Garden Confirms Major Data Breach
  • Shield Your SaaS from Bot Threats with SafeLine WAF
  • CISA Alerts on RESURGE Malware Threat to Ivanti Devices

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News