Microsoft releases urgent Office patch. Russian-state hackers pounce.

https://arstechnica.com/security/2026/02/russian-state-hackers-exploit-office-vulnerability-to-infect-computers/

161 points · 15 comments · view on lemmy.world

15 Comments

m3t00@piefed.world · 47 pts · 228d (2 replies)

no worries copilot has screenshots

Tramort@programming.dev · 13 pts · 228d

That's so fucking on target

WhyJiffie@sh.itjust.works · 7 pts · 227d

and onedrive has all your documents too in original form

FiniteBanjo@feddit.online · 45 pts · 228d (7 replies)

Slopper companies like MS, Google, and Spotify are all having massive vulnerabilities. I wonder why.

Zink@programming.dev · 15 pts · 228d

It sounds like they've gotten fat, rich, and complacent. Just like some societies I know!

timewarp@lemmy.world · 7 pts · 228d (1 reply)

Vibe coding. Overuse of H-1B visas. Microsoft specifically seems to rely a lot on foreign workers because a lot of them will do whatever their employer asks without question because their employer has a lot of control over whether they are even allowed in the US. Even if they are natural citizens it seems a lot of them don't have the same privileges & a bad review by an employer has more potential to ruin their career. Also, the caste system exists here even in the US.

very_well_lost@lemmy.world · 9 pts · 228d

Overuse of H-1B visas.

It's literally a system of indentured servitude and corpos are just free to abuse it with impunity.

WhyJiffie@sh.itjust.works · 6 pts · 227d (2 replies)

Obviously the problem is that office was not written in a safe language. rewrite office in rust!

dejpivo@lemmings.world · 5 pts · 227d (1 reply)

I genuinely wonder if rust helps guarding against slop coding vulnerabilities, at least statistically.

WhyJiffie@sh.itjust.works · 3 pts · 227d

the compiler stops you from compiling most of incorrect code. unless AI learns to use unsafe blocks liberally, it will still prevent memory corruption bugs and such

ILikeBoobies@lemmy.ca · 2 pts · 227d

Don't forget Linux.

(XZ not technically Linux)

Australis13@fedia.io · 25 pts · 228d (3 replies)

Rather impressive how quickly the hackers reverse-engineered Microsoft's patch and used the vulnerability whilst the opportunity was still available:

The threat group, tracked under names including APT28, Fancy Bear, Sednit, Forest Blizzard, and Sofacy, pounced on the vulnerability, tracked as CVE-2026-21509, less than 48 hours after Microsoft released an urgent, unscheduled security update late last month, the researchers said. After reverse-engineering the patch, group members wrote an advanced exploit that installed one of two never-before-seen backdoor implants.

frongt@lemmy.zip · 22 pts · 228d (2 replies)

And this is why quickly applying security updates is important.

Prove_your_argument@piefed.social · 6 pts · 227d

Who needs a maintenance window or to test updates? Just roll the dice constantly.

Damage@feddit.it · 1 pts · 226d

Yeah if your OS is a fucking sieve