{"id":220409,"date":"2026-03-02T05:36:00","date_gmt":"2026-03-02T10:36:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/03\/02\/apt28-tied-to-cve-2026-21513-mshtml-0-day-exploited-before-feb-2026-patch-tuesday\/"},"modified":"2026-03-05T19:01:37","modified_gmt":"2026-03-06T00:01:37","slug":"apt28-tied-to-cve-2026-21513-mshtml-0-day-exploited-before-feb-2026-patch-tuesday","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/03\/02\/apt28-tied-to-cve-2026-21513-mshtml-0-day-exploited-before-feb-2026-patch-tuesday\/","title":{"rendered":"APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch Tuesday"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/03\/apt28-tied-to-cve-2026-21513-mshtml-0.html\">APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch Tuesday<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/03\/apt28-tied-to-cve-2026-21513-mshtml-0.html\">https:\/\/thehackernews.com\/2026\/03\/apt28-tied-to-cve-2026-21513-mshtml-0.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-03-02 05:36:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Mar 02, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Threat Intelligence<\/span><\/p>\n<p>A recently disclosed security flaw patched by Microsoft may have been exploited by the Russia-linked state-sponsored threat actor known as APT28, according to new findings from Akamai.<\/p>\n<p>The vulnerability in question is <strong>CVE-2026-21513<\/strong> (CVSS score: 8.8), a high-severity security feature bypass affecting the MSHTML Framework.<\/p>\n<p>&#8220;Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network,&#8221; Microsoft noted in its advisory for the flaw. It was fixed by the Windows maker as part of its February 2026 Patch Tuesday update.<\/p>\n<p>However, the tech giant also noted that the vulnerability had been exploited as a zero-day in real-world attacks, crediting the Microsoft Threat Intelligence Center (MSTIC), Microsoft Security Response Center (MSRC), and Office Product Group Security Team, along with Google Threat Intelligence Group (GTIG), for reporting it.<\/p>\n<p>In a hypothetical attack scenario, a threat actor could weaponize the vulnerability by persuading a victim to open a malicious HTML file or shortcut (LNK) file delivered through a link or as an email attachment.<\/p>\n<p>Once the crafted file is opened, it manipulates browser and Windows Shell handling, causing the content to be executed by the operating system, Microsoft noted. This, in turn, allows the attacker to bypass security features and potentially achieve code execution.<\/p>\n<p>While the company has not officially shared any details about the zero-day exploitation effort, Akamai said it identified a malicious artifact that was uploaded to VirusTotal on January 30, 2026, and is associated with infrastructure linked to APT28.<\/p>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"512\" data-original-width=\"900\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhZSVDvLRSrmtPBEuEbrJ9vlVmD-Is4GdZ1l1McEKvPnQS9HuuAQ0WTAwHn8-JYM4mddUphW4tseJs-605fvxcAJImVKBP0hKA9nOysGGTgNE5j1CqPmKwm5S-8nzqS224lO02zCGxM0F5huJbkAJUq79uItXCrUcPszkXbYouq-wfnKaE91jWYd9ERWbhg\/s1600\/com.jpg\"\/><\/p>\n<p>It&#8217;s worth noting that the sample was flagged by the Computer Emergency Response Team of Ukraine (CERT-UA) early last month in connection with APT28&#8217;s attacks exploiting another security flaw in Microsoft Office (CVE-2026-21509, CVSS score: 7.8).<\/p>\n<p>The web infrastructure company said&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/03\/apt28-tied-to-cve-2026-21513-mshtml-0.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch Tuesday https:\/\/thehackernews.com\/2026\/03\/apt28-tied-to-cve-2026-21513-mshtml-0.html Publish Date:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":220410,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgGmBYExYY-MdqirvtI7-k2gWDf2rCE5AX4J246DywytJU0hWklJfAxRUKUa6AhU-VFWf2jazsAR1DkpPBHUqv2LsGckfxhVUebrMsnAccaYYmp2L9VJDz4rHaRLxKRgXaYM-UPcFS_ZoyveJxkLu1RunwaIuCBckILFDzMo1mCZtg9zaOmXrOSEEWU7RSg\/s1600\/windows.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[34,27],"class_list":["post-220409","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-threat-actor","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/220409"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=220409"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/220409\/revisions"}],"predecessor-version":[{"id":220411,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/220409\/revisions\/220411"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/220410"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=220409"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=220409"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=220409"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}