Russia-linked APT28 exploited MSHTML zero-day CVE-2026-21513 before patch

2026-03-04T21:47:19Z9e35c1c0dd2bc5cd144badd3cde4bdc6f3e0a9bb50482ed67236654cc0645166
CVE-2025-64328CVE-2026-1731CVE-2026-21513AI ID fraudAPT28APT37AnthropicBeyondTrustClaude CodeClawJackedEuropol Project CompassMSHTMLOdido data leakOnlyFakeOpenClawRuby JumperSangoma FreePBXScarCruftShinyHuntersUSB implantZoho WorkDriveair-gapped breachchild exploitationdata exfiltrationzero-day

What happened

Multiple high-impact security developments: Russia-linked APT28 exploited an MSHTML zero-day (CVE-2026-21513, CVSS 8.8) in the wild prior to Microsoft’s February 2026 patch. North Korea-linked APT37 (ScarCruft) ran the “Ruby Jumper” campaign using Zoho WorkDrive for C2 and a USB-based implant to bridge air-gapped systems. A large Dutch data leak by ShinyHunters exposed the full Odido dataset, while attackers abused Anthropic’s Claude Code to build exploits and exfiltrate ~150GB from Mexican government systems. Hundreds of Sangoma FreePBX instances remain infected after exploitation of CVE-2025

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
9e35c1c0dd2bc5cd144badd3cde4bdc6f3e0a9bb50482ed67236654cc0645166
Enrichment time
2026-03-04T21:47:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Russia-linked APT28 exploited MSHTML zero-day CVE-2026-21513 before patch · Baitaphish