CYBERSECURITY & PRIVACY — 2026-03-17

APT28 Exploited MSHTML Zero-Day (CVE-2026-21513) Before February Patch

Russia-linked APT28 exploited CVE-2026-21513 (CVSS 8.8), an MSHTML security feature bypass, using crafted LNK files to evade Mark-of-the-Web protections and execute code. The exploit communicated with wellnesscaremed[.]com for multistage payload delivery. The vulnerability was patched in February 2026 but had been exploited as a zero-day since at least January 30. APT28 also deployed BEARDSHELL and COVENANT implants for long-term surveillance of Ukrainian military personnel.

View in full brief →

UNCLASSIFIED // OPEN SOURCE