In May 2018, our Advanced Threat Response Team detected an APT attack exploiting a zero-day vulnerability and captured the world’s first malicious office sample that uses a browser zero-day vulnerability.The sample exploited a use-after-free vulnerability in the VBScript engine fixed by Microsoft as CVE-2018-8174.