A cyberespionage group operating out of Russia has launched malware attacks against the Ukrainian government and at least one U.S.-based organization through a previously unknown vulnerability that affects most versions of Windows. The group, dubbed the Sandworm team, has been actively attacking organizations like the NATO alliance, energy firms and telecommunication companies since 2013. The attack used spear-phishing emails containing a malicious PowerPoint document that was created to exploit the new vulnerability. Microsoft plans to release a patch for the vulnerability later in the day.”]

