An incomplete Microsoft patch handed APT28 a zero-click way to steal Windows credentials, and the real fix only landed earlier this month.