Microsoft releases urgent Office patch. Russian-state hackers pounce.

https://lemmy.world/post/42683050

Microsoft releases urgent Office patch. Russian-state hackers pounce. - Lemmy.World

Lemmy

Rather impressive how quickly the hackers reverse-engineered Microsoft's patch and used the vulnerability whilst the opportunity was still available:

The threat group, tracked under names including APT28, Fancy Bear, Sednit, Forest Blizzard, and Sofacy, pounced on the vulnerability, tracked as CVE-2026-21509, less than 48 hours after Microsoft released an urgent, unscheduled security update late last month, the researchers said. After reverse-engineering the patch, group members wrote an advanced exploit that installed one of two never-before-seen backdoor implants.

And this is why quickly applying security updates is important.
Who needs a maintenance window or to test updates? Just roll the dice constantly.
Yeah if your OS is a fucking sieve