Thursday , August 6 2026
Microsoft Office

Hackers Exploiting Microsoft Office 0-day Vuln to Deploy Malware: CERT warn

The Russia-linked group UAC-0001, or APT28, is exploiting a zero-day vulnerability in Microsoft Office. The group exploits this flaw to install advanced malware targeting Ukrainian government and EU organizations.

The vulnerability, identified as CVE-2026-21509, was disclosed by Microsoft on January 26, 2026, with warnings about active exploitation in the wild.

Greatness PhaaS Evades Email Security and MFA to Take Over Microsoft 365 Accounts

Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume...
Read More
Greatness PhaaS Evades Email Security and MFA to Take Over Microsoft 365 Accounts

Pillar 4: Total 131 Indicators Set
How Bangladeshi’s Ogrs Be Evaluated By Newly Launched NRS & CIRS

Bangladesh's National Cyber Security Agency (NCSA) has launched two cybersecurity initiatives: the Cyber Incident Reporting System (CIRS) and the National...
Read More
Pillar 4: Total 131 Indicators Set  How Bangladeshi’s Ogrs Be Evaluated By Newly Launched NRS & CIRS

Brazilian health surveillance platform breach exposes 100K+ sensitive documents

Cybersecurity Researcher Jeremiah Fowler uncovered and reported to Express VPN a publicly exposed database that was neither password-protected nor encrypted....
Read More
Brazilian health surveillance platform breach exposes 100K+ sensitive documents

Thousands of data centers are at risk of compromise due to a 22-year-old flaw

Thousands of data centers are in danger because of a 22-year-old problem in Baseboard Management Controller (BMC) processors, says the...
Read More
Thousands of data centers are at risk of compromise due to a 22-year-old flaw

Bangladesh Launches (CIRS) and National ICT & Cyber Security Rating System (NRS)

In an important move to boost the country's cybersecurity, Bangladesh started the Cyber Incident Reporting System (CIRS) and the National...
Read More
Bangladesh Launches (CIRS) and National ICT & Cyber Security Rating System (NRS)

CVE-2026-18574
Check Point Authentication Bypass Hits Management Server

Check Point fixed a flaw that allowed bypassing authentication on its Security Management and Multi-Domain Security Management servers. This issue...
Read More
CVE-2026-18574  Check Point Authentication Bypass Hits Management Server

TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

TP-Link has shared a security warning about a serious problem with its TL-WR940N V6 wireless router. This problem, known as...
Read More
TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

ExfilSquad releases info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has put the contact information of over 100,000 police officers...
Read More
ExfilSquad releases info of over 100,000 UK police officers, staff

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

Rapid Exploitation After Disclosure:

On January 27, 2026, security researchers discovered a malicious DOC file titled “Consultation_Topics_Ukraine(Final).doc” containing an exploit for CVE-2026-21509.

chain of damage ( source : CERT-UA )

The document focused on COREPER consultations about Ukraine, showcasing how attackers used social engineering tactics linked to geopolitics.

On January 29, 2026, CERT-UA discovered a large phishing campaign distributing fake weather bulletins from the Ukrhydrometeorological Center. The campaign targeted over 60 email addresses, primarily belonging to Ukrainian central executive bodies.

The attack uses COM hijacking by altering Windows registry entries and sets up a scheduled task called “OneDriveHealth” to remain persistent.

The final payload, COVENANT, is an advanced post-exploitation framework that utilizes Filen cloud storage (filen.io) for communication.

The content of documents with the exploit ( source :CERT-UA )

This method avoids detection by mixing harmful traffic with normal cloud service use. More malicious documents aimed at EU countries were found in late January 2026.

Attackers registered domain names for their attack infrastructure on the same day as the attack, showing their quick operational skills.

CERT-UA security experts warn that exploitation attempts are likely to rise because of slow patching and users not updating Microsoft Office quickly.

Organizations should promptly apply Microsoft’s recommended registry mitigations, monitor connections to FileCloud storage, and block known threats.

Check Also

Cursor

Cursor, SonicWall, SharePoint 0-day exploited to the wild

A serious security flaw in Cursor, a popular AI code editor used by more than …