APT28 exploited CVE-2026-21513, an MSHTML zero-day (CVSS 8.8), using malicious LNK files to bypass security controls and execute code.
To understand why this matters, it helps to know how current web security actually works. When you visit a website, your browser checks a digital certificate ...