Microsoft releases urgent Office patch. Russian-state hackers pounce.

submitted by

arstechnica.com/security/2026/02/russian-state-…

13
160

Log in to comment

13 Comments

Rather impressive how quickly the hackers reverse-engineered Microsoft’s patch and used the vulnerability whilst the opportunity was still available:

The threat group, tracked under names including APT28, Fancy Bear, Sednit, Forest Blizzard, and Sofacy, pounced on the vulnerability, tracked as CVE-2026-21509, less than 48 hours after Microsoft released an urgent, unscheduled security update late last month, the researchers said. After reverse-engineering the patch, group members wrote an advanced exploit that installed one of two never-before-seen backdoor implants.

And this is why quickly applying security updates is important.

Who needs a maintenance window or to test updates? Just roll the dice constantly.


Yeah if your OS is a fucking sieve




no worries copilot has screenshots

That’s so fucking on target


and onedrive has all your documents too in original form



Slopper companies like MS, Google, and Spotify are all having massive vulnerabilities. I wonder why.

It sounds like they’ve gotten fat, rich, and complacent. Just like some societies I know!


Obviously the problem is that office was not written in a safe language. rewrite office in rust!

I genuinely wonder if rust helps guarding against slop coding vulnerabilities, at least statistically.

the compiler stops you from compiling most of incorrect code. unless AI learns to use unsafe blocks liberally, it will still prevent memory corruption bugs and such




Don’t forget Linux.

(XZ not technically Linux)



Insert image