Home / Sep 16, 2026 / Story
0
#4 The Hacker News general September 15, 2026 at 05:31 UTC

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

By [email protected] (The Hacker News)

AI Summary

Volexity attributed a September 1, 2026 spear-phishing campaign to Chinese threat actor UTA0560, which chained patched zero-days in Google Chrome and Microsoft Windows to deliver a JavaScript backdoor called GRIMWEDGE against multiple NGOs. The use of a Chrome-Windows exploit chain against civil society targets underscores the ongoing risk of nation-state actors leveraging browser-plus-OS zero-day combinations for targeted espionage.

Relevance score: 89.0/100

# More from September 16