Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
APT28 Exploits MSHTML Vulnerability Before February 2026 Patch

APT28 Exploits MSHTML Vulnerability Before February 2026 Patch

Posted on March 2, 2026 By CWS

A critical vulnerability in Microsoft’s MSHTML Framework has been reportedly exploited by the Russian-affiliated threat group APT28 before it was patched in February 2026. According to Akamai, this high-severity flaw, identified as CVE-2026-21513 with a CVSS score of 8.8, was exploited in the wild as a zero-day.

Understanding the MSHTML Vulnerability

The vulnerability in question involves a security feature bypass within the MSHTML Framework. Microsoft highlighted that this flaw allows unauthorized attackers to circumvent security mechanisms over a network. The issue was addressed during the February 2026 Patch Tuesday, with credits to Microsoft Threat Intelligence Center, Microsoft Security Response Center, Office Product Group Security Team, and Google’s Threat Intelligence Group for their collaborative efforts in identifying the flaw.

The vulnerability can be weaponized by attackers who trick victims into opening a malicious HTML or shortcut (LNK) file delivered via links or email attachments. Upon opening, it alters browser and Windows Shell operations, enabling code execution by bypassing security protections.

APT28’s Exploitation Tactics

APT28’s exploitation of this flaw was highlighted by Akamai, which discovered a malicious file uploaded to VirusTotal on January 30, 2026, linked to the group’s infrastructure. The Computer Emergency Response Team of Ukraine (CERT-UA) also flagged this activity, linking it to previous APT28 exploits involving a different Microsoft Office vulnerability (CVE-2026-21509).

The flaw is rooted in the ‘ieframe.dll’ component that handles hyperlink navigation, resulting from inadequate validation of URLs. This allows attacker-controlled data to traverse code paths that invoke ShellExecuteExW, facilitating the execution of resources outside the browser’s security context.

Technical Insights and Future Threats

Security expert Maor Dahan explained that the exploit involves a Windows Shortcut (LNK) file embedding an HTML document. This file communicates with a domain linked to APT28, known for its extensive use in multi-stage payload campaigns. The exploit manipulates nested iframes and multiple DOM contexts to breach trust boundaries.

Akamai warns that this technique can bypass security measures like Mark-of-the-Web (MotW) and Internet Explorer Enhanced Security Configuration (IE ESC), lowering security contexts and allowing malicious code execution outside of the browser sandbox through ShellExecuteExW. While the current campaign utilizes LNK files, any component embedding MSHTML could potentially trigger the vulnerable code path, suggesting a need for vigilance against diverse delivery mechanisms beyond LNK-based phishing.

The discovery of this vulnerability and its exploitation by APT28 underscores the ongoing threat posed by state-sponsored cyber actors. Organizations are urged to apply security patches promptly and remain vigilant against evolving cyber threats.

The Hacker News Tags:Akamai, APT28, CERT-UA, CVE-2026-21513, cyber attack, Cybersecurity, Exploit, malicious LNK, Microsoft, MSHTML, network security, Patch Tuesday, threat intelligence, Vulnerability, zero-day

Post navigation

Previous Post: Unencrypted TPMS in Major Cars Pose Privacy Risks
Next Post: Nick Andersen Steps Up as Acting CISA Director

Related Posts

Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud The Hacker News
Researcher Found Flaw to Discover Phone Numbers Linked to Any Google Account Researcher Found Flaw to Discover Phone Numbers Linked to Any Google Account The Hacker News
Microsoft Fixes 78 Flaws, 5 Zero-Days Exploited; CVSS 10 Bug Impacts Azure DevOps Server Microsoft Fixes 78 Flaws, 5 Zero-Days Exploited; CVSS 10 Bug Impacts Azure DevOps Server The Hacker News
[Webinar] Shadow AI Agents Multiply Fast — Learn How to Detect and Control Them [Webinar] Shadow AI Agents Multiply Fast — Learn How to Detect and Control Them The Hacker News
Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates Released Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates Released The Hacker News
Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Launches Expanded Cyber Defense with GPT-5.4-Cyber
  • AI-Powered Exploit Reveals Chrome Vulnerability Risks
  • Apple Aims to Fix iPhone Bug Removing Czech Character
  • Emerging Nexcorium Botnet Exploits DVR Vulnerability
  • Tycoon 2FA Loses Ground Amid Rising Phishing Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Launches Expanded Cyber Defense with GPT-5.4-Cyber
  • AI-Powered Exploit Reveals Chrome Vulnerability Risks
  • Apple Aims to Fix iPhone Bug Removing Czech Character
  • Emerging Nexcorium Botnet Exploits DVR Vulnerability
  • Tycoon 2FA Loses Ground Amid Rising Phishing Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark