Russia is hacking zero-days again

Russia is hacking zero-days again

🎙 John Hammond 👥 2.2M 📅 February 19, 2026 ⏱ 16 min 👁 66K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

CVE-2026-21509APT28Microsoft Officezero-daymalware analysis

Summary

In this video, John Hammond discusses the recent Microsoft Office zero-day vulnerability CVE-2026-21509, which was actively exploited by Russian state-sponsored hackers (APT28). He provides a timeline of events, starting with Microsoft’s emergency out-of-band patch on January 26, 2026, and the subsequent discovery of malicious .doc files targeting Ukrainian government entities. The video includes a technical analysis of one such malicious file (bulletin_h.doc), demonstrating how it exploits the vulnerability via OLE objects and WebDAV to download and execute malicious payloads. Hammond also highlights the use of Flare’s threat intelligence platform to monitor discussions about the vulnerability on the dark web and Telegram. He walks through the process of extracting indicators of compromise (IOCs) and using tools like VirusTotal and a Python script by Didier Stevens to confirm the exploit. The video concludes with practical advice on patching and mitigating the vulnerability, emphasizing the importance of staying updated. Throughout, Hammond maintains an educational tone, making complex cybersecurity concepts accessible to a broad audience.

161 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into a real-world zero-day exploit, offering both high-level context and technical details. Hammond effectively explains the attack chain, from the initial malicious document to the final payload execution, using a combination of official reports and hands-on analysis. His argumentation is solid, as he supports his claims with references to credible sources such as CERT-UA, Microsoft, and Bleeping Computer. The demonstration of the exploitation process adds practical value, helping viewers understand the mechanics behind the vulnerability. However, the video occasionally relies on speculation (e.g., the exact role of the Covenant C2 framework) and lacks a thorough discussion of the broader geopolitical implications, which could have strengthened the overall argument.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates strong scientific rigor by citing multiple authoritative sources, including the Microsoft Security Response Center (MSRC), CERT-UA, and Bleeping Computer. The presenter also references a blog post from Flare and a Python script by Didier Stevens, adding depth to the analysis. The title accurately reflects the content, focusing on Russian hacking activities. However, the video does not critically evaluate the sources or discuss potential biases, and the reliance on third-party tools (e.g., Flare) could be seen as promotional. The adéquation between the title and content is good, though the title could be more specific about the technical nature of the video.

231 words

Title / Content Match

The title accurately reflects the content, which focuses on Russian hacking activities involving zero-day vulnerabilities.

Quality & Reliability

8/10

The video provides a detailed analysis of a recent Microsoft Office zero-day (CVE-2026-21509) exploited by APT28, referencing official sources (MSRC, CERT-UA, Bleeping Computer) and demonstrating hands-on malware analysis. The information is accurate and well-sourced, though the presenter's informal style and reliance on third-party tools slightly reduce the overall rigor.

Key Moments

Cited Sources

  • CERT-UA Article on CVE-2026-21509 — Original report from Ukraine's Computer Emergency Response Team detailing the active exploitation of the vulnerability.
  • Flare Blog Post on January 2026 Patch Tuesday — Flare's analysis of the vulnerabilities and exploits discussed after the January 2026 Patch Tuesday.
  • Didier Stevens' OLE Check Script — Python script to scan Microsoft Office files for OLE objects matching CVE-2026-21509.
  • Microsoft Security Response Center - CVE-2026-21509 — Official Microsoft advisory for the vulnerability, including mitigation steps.
  • Bleeping Computer - Microsoft Patches Actively Exploited Office Zero-Day — News article covering the initial patch and details of the zero-day.
  • Bleeping Computer - Russian Hackers Exploit Recently Patched Microsoft Office Bug — Follow-up article attributing the exploitation to Russian hackers.
  • VirusTotal - Malicious File Hash — VirusTotal page for the malicious file bulletin_h.doc, used for analysis.

Concurring Sources

External References

Contribution & Novelties

The video provides a practical, hands-on analysis of a recent zero-day exploit, bridging the gap between news reports and technical understanding. It offers a clear walkthrough of the exploitation chain, from the malicious document to the final payload, and demonstrates the use of open-source tools for detection. The inclusion of Flare’s threat intelligence adds a unique perspective on how such vulnerabilities are discussed in underground forums.

Pour aller plus loin :

104 words

Radar Profile

The radar profile shows a balanced performance across all dimensions, with slightly higher scores in information quantity and quality, reflecting the video's comprehensive coverage and technical depth. The lower score in technical level suggests the content is accessible to a broader audience, while the high reliability score indicates strong sourcing.

Reliability 8/10

💬 Positif. Sur les 30 commentaires analysés, la majorité exprime un intérêt et une appréciation pour le contenu, avec des discussions techniques et des remerciements, bien que quelques commentaires critiques sur le style ou des préoccupations de sécurité soient présents.