❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 24 September 2026Main stream
Before yesterdayMain stream

Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects

22 September 2026 at 14:47

Volexity researchers spotted another state-aligned Chinese threat group exploiting a triple-link chain of zero-day vulnerabilities across multiple campaigns, the company said in a blog post Monday.

The threat group it tracks as UTA0565 exploited the vulnerabilities in Chrome and Microsoft between Sept. 3 and 4 before the defects were disclosed or patched, researchers said.

The timing of the malicious activity mirrors other spikes threat hunters observed and attributed to multiple Chinese espionage threat groups. Yet, Volexity noted UTA0565’s campaigns differed from those attacks by using multiple fake websites to deceive victims.

Volexity shared phishing emails UTA0565 sent to Asian government entities urging them to publicly support imprisoned Hong Kong activist Chow Hang-tung. The group spoofed domains impersonating the Center for American Progress and China Digital Times in other phishing emails.

While UTA0565 showcased a variance in tactics, it used the same components researchers observed in previous instances of the exploit kit across multiple Chinese threat groups.

β€œThis seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese computer network exploitation community, where the core kit was likely shared, customized, and weaponized by multiple groups,” Volexity wrote in the blog post. β€œThe activity reported so far reflects only two organizations’ observations; the full scope and impact are likely far broader.”

The vulnerabilities include: CVE-2026-85046 and CVE-2026-87491, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and CVE-2026-85880, a privilege-escalation zero-day that Microsoft disclosed Sept. 8 in Windows Advanced Local Procedure Call.Β 

Proofpoint, which previously observed multiple state-aligned threat groups chaining the vulnerabilities together in attacks since last August, said a limited group of organizations were exposed to all three vulnerabilities in a short window.Β 

Proofpoint previously attributed attacks involving the zero-days to APT31, UNK_LateNight, UNK_DoubleCheck and UNK_QuietRacket. At the time it warned that attackers of other origins and motivations could strike soon as well.

Volexity said UTA0565 used a payload from a previously undocumented malware family it tracks as β€œCLEANGULP.” Researchers also found several domains likely used by UTA0565 in similar campaigns targeting media organizations, halal restaurant search websites and corporate training organizations.Β 

β€œUTA0565’s use of the zero-day vulnerabilities shows technical and operational improvements over other campaigns observed by Volexity, both in the mechanics of the exploitation and the presentation to end users,” researchers wrote. β€œUsing real content from legitimate websites as decoy material continues to be an effective way to reduce user suspicion.”

The post Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects appeared first on CyberScoop.

Chinese espionage groups swarm to exploit triple-link chain of zero-days

9 September 2026 at 17:17

Proofpoint researchers have spotted at least four state-aligned threat groups chain a trio of zero-day vulnerabilities to conduct espionage on various targets of interest to China’s government since late August.Β 

The Chinese espionage group that Proofpoint tracks as TA412, also known as Violet Typhoon and APT31, struck first, exploiting the chain of vulnerabilities Aug. 28. At least three additional espionage threat groups followed suit, exploiting the same vulnerabilities in subsequent waves of attacks days later, researchers said.

The exploit chain Proofpoint calls BlueMoon targets Chrome, Chromium-based browsers and Microsoft Windows. It allows attackers to run code in the browser’s sandbox, escape the sandbox and gain system privileges to access a targeted machine, said Mark Kelly, staff threat researcher at Proofpoint.

β€œAll three vulnerabilities were exploited before patches were available to the public,” he said.

The vulnerabilities include: CVE-2026-85046 and CVE-2026-87491, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and CVE-2026-85880, a privilege-escalation zero-day that Microsoft disclosed Tuesday in Windows Advanced Local Procedure Call.Β 

β€œWhile the V8 vulnerabilities were known and fixed in Chromium source code, they were not yet patched in the latest publicly available browsers at the time of the activity, meaning they effectively functioned as zero-days in those products,” Kelly said.

Proofpoint said the exploit kit developer likely reverse engineered the publicly available Chromium patches to weaponize the browser exploit chain during that gap.

With a limited group of organizations exposed to all three vulnerabilities, attackers moved quickly and likely rushed development to target a narrow pool of potential targets. β€œIn all observed cases, the infrastructure used for exploit delivery was created on the same day as β€” or in the days immediately preceding β€” the associated campaigns,” Proofpoint wrote in a threat intelligence report.

APT31, a group that’s committed espionage on behalf of China’s Ministry of State Security, including seven Chinese nationals indicted by the Justice Department in 2024, dropped various lures containing the exploit chain loader in phishing emails targeting non-governmental organizations, mining companies and commodity trading firms in the United States.Β 

The phishing link installed a malicious browser extension disguised as Google Gemini on targeted machines, enabling attackers to surveil browser activity, steal credentials and execute commands, according to Proofpoint.Β 

Other distinct threat groups have also used the BlueMoon exploit chain with some slight technical changes and variances in targeting.Β 

β€œProofpoint observed BlueMoon usage as recently as Sept. 8,” Kelly said. β€œThe activity peaked Sept. 2-3 immediately prior to the Chrome patch being released and has continued intermittently since then.”

A China-aligned espionage threat group Proofpoint tracks as UNK_LateNight targeted multiple U.S. aerospace companies Sept. 2. Researchers also that day observed UNK_DoubleCheck, a suspected espionage-motivated threat group targeting Vietnamese manufacturing organizations with emails from a compromised Southeast Asian government account.Β 

Researchers said UNK_QuietRacket, another espionage group aligned with China, targeted government, consulting and financial sector organizations in Indonesia and Singapore Sept. 3.

Proofpoint has directly observed fewer than 20 organizations targeted globally thus far, but Kelly said the true number of impacted organizations is likely much higher.Β 

While Proofpoint attributes most of the observed attacks to Chinese espionage groups, attackers of other origins and motivations could strike soon as well.Β 

β€œGiven its ease of adoption, we expect the exploit kit is likely to proliferate further and be adopted by additional espionage-motivated and financially motivated threat actors as patched versions are fully rolled out across all Chromium-based browsers,” Kelly said.

The post Chinese espionage groups swarm to exploit triple-link chain of zero-days appeared first on CyberScoop.

Google Should Still Be Forced To Shed Chrome, Advocacy Group Argues

8 August 2026 at 23:52
"Google should be required to divest the Chrome browser, and prohibited from paying Apple to distribute Google's search engine, the nonprofit advocacy group Public Knowledge argues in a new court filing," MediaPost reports, citing a friend-of-the-court brief filed Tuesday in the D.C. Circuit Court of Appeals: The group adds that "independent ownership" of Chrome "would open the distribution channel Google controls and allow Chrome to serve browser users when it makes privacy decisions and determines how to integrate search and (artificial intelligence)..." In September 2025, [U.S. District Court Judge] Mehta issued a remedies order that requires Google to share some data about users' searches with "qualified" competitors and to provide syndicated search results and ads to those competitors. The order also prohibits Google from entering into exclusive distribution contracts for Google Search, Chrome, Google Assistant and the Gemini app for six years, but allows the company to continue to make payments for search-ad revenue or distribution to Apple, Mozilla and others... Google recently appealed Mehta's order. The company argued in its written brief that it "prevailed in the marketplace fair and square," adding that Apple and Mozilla "sensibly chose" Google as the default search engine "because it gave their users the best experience," and because Apple and Mozilla would earn the most ad revenue through the deals. The [U.S.] Justice Department and states countered to the appellate court last week that the liability finding should stand, and also argued that Google should have been banned from paying Apple and Mozilla for placement as the default search engine on their browsers. [Antitrust enforcers had originally asked the judge to order Google to divest Chrome, but he's already rejected that request.] The government did not argue in its appellate papers that Google should be forced to sell Chrome. But Public Knowledge independently contends in its friend-of-the-court brief that divestiture would benefit consumers... "Divestiture would place those decisions with an institution whose success depends on serving browser users primarily...." The group is calling the appellate court's attention to Google's April 2025 decision to preserve tracking cookies β€” a reversal from its earlier plans to block third-party cookies by default. "Google is in the position of both deciding Chrome's tracking rules while running the advertising business affected by them," Public Knowledge writes. "An independent Chrome could make those decisions on behalf of users alone." But Firefox developer Mozilla filed its own friend-of-the-court brief Thursday warning Firefox could be forced to "exit the browser and browser engine markets" if it can't receive payment from Google for distributing its search engine, according to a later report from MediaPost: Federal and state antitrust enforcers recently asked the appellate court to reverse the portion of Mehta's order that allows those payments to continue. But Mozilla counters in its new friend-of-the-court brief that Mehta's decision regarding those payments was supported by the evidence --including a study it conducted concluding that its revenue would "decline dramatically" if forced to replace Google with Bing as Firefox's default search engine... Google is expected to file new arguments with the appellate court next month.

Read more of this story at Slashdot.

Chrome Is Using AI To Fix Hundreds of Bugs, Eliminate Full Browser Restarts

By: BeauHD
31 July 2026 at 12:00
Google says AI-assisted workflows helped Chrome fix 1,072 security bugs across versions 149 and 150, more than the previous 23 releases combined. The company is also testing twice-weekly security updates and "dynamic patching," which could apply most fixes without requiring users to restart the entire browser. "By leveraging Chrome's multi-process architecture, dynamic patching sequentially replaces background child processes (like the Renderer and GPU) with updated binaries on the fly," says Google in a blog post. PiunikaWeb reports: Alongside dynamic patching, Google is rolling out smarter background updates during periods of minimal user disruption. Starting with Chrome 150 on macOS, the browser takes advantage of the operating system's windowless state. If all Chrome windows are closed but the app remains running in the background, the browser will quietly auto-restart to apply pending updates. For enterprise environments, IT admins can continue to manage fleet-wide deployments through Chrome Enterprise Core or enforce update prompts using the RelaunchNotification policy. Google's long-term vision is a browser that remains continuously protected in the background without interrupting your daily browsing session. In the meantime, you can manually trigger pending updates by clicking the update prompt in the top-right corner of Chrome.

Read more of this story at Slashdot.

Security researchers find stalkers abusing Chrome’s sync feature

15 July 2026 at 16:42

Cyberstalkers are increasingly exploiting a feature in Google Chrome meant for mobile phone user convenience, but can give intruders broad access to a device owner’s private information, according to researchers.

Certo Software said in a blog post Tuesday that stalkers are making use of Chrome’s sync capability β€” meant to make it so signing into Chrome on one device makes it easier to do so on other devices, too β€” to spy on a phone owner’s browsing history and gain access to their stored passwords.

As an illustration, Certo used the case of a pseudonymous victim, Emma, who had searched for a family lawyer and visited a domestic violence support website while her partner was sleeping, only for him to bring up to her two days later.

β€œEmma had been careful to only ever use her own device, and she hadn’t noticed any new apps appear on her phone,” wrote Certo co-founder Russell Kent-Payne. β€œWhat she didn’t know was that weeks earlier, during a few unattended minutes with her phone, he had opened the Chrome app and quietly signed it into a Google account of his own. From that moment on, every site she visited was being copied straight to his account, viewable from any device, anywhere in the world.”

The surveillance is as easy as that: brief access to a phone, signing into a Google account and making sure sync is turned on for that account.

Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, said on the Bluesky social media app that Certo’s research serves as β€œan important reminder that tech-enabled abuse isn’t just limited to stalkerware.”

Certo said that Google could do a couple things, such as providing a temporary notification whenever a new account is added or sync is turned on or offering a regular marker to indicate when sync is active and which account it’s syncing to, to protect users.

Google did not respond to multiple requests for comment about Certo’s findings.

But the uptick in usage of that stalking method could be a byproduct of security successes elsewhere in the fight against spyware, Certo said.

β€œModern smartphones are harder to compromise than ever. Regular security updates, stricter app store rules, and on-device threat detection have made traditional spyware a much riskier bet for a cyberstalker than it used to be,” Kent-Payne wrote. β€œAs a result, we’re increasingly seeing abusers turn to something far simpler: the legitimate apps already sitting on their victim’s phone. No installation, no suspicious permissions, no telltale battery drain β€” just a quiet misuse of a feature the victim never knew existed.”

At the same time, Chrome is the world’s most popular browser, and this isn’t the first time security concerns have popped up about its sync feature, among other worries.

The post Security researchers find stalkers abusing Chrome’s sync feature appeared first on CyberScoop.

New update for Chrome

25 June 2026 at 04:00
Well, Chrome 149.0.7827.197 is out with 18 security fixes as noted by Google.Β  The June 15 release had 33 CVEs or security fixes. If you have Chrome on other devices such as your phone, your tablet, or your Linux computer, remember to make sure to click on Help, About, and check to trigger it to […]

Patch Tuesday, April 2026 Edition

14 April 2026 at 17:47

Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software, including a SharePoint Server zero-day and a publicly disclosed weakness in Windows Defender dubbed β€œBlueHammer.” Separately, Google Chrome fixed its fourth zero-day of 2026, and an emergency update for Adobe Reader nixes an actively exploited flaw that can lead to remote code execution.

A picture of a windows laptop in its updating stage, saying do not turn off the computer.

Redmond warns that attackers are already targeting CVE-2026-32201, a vulnerability in Microsoft SharePoint Server that allows attackers to spoof trusted content or interfaces over a network.

Mike Walters, president and co-founder of Action1, said CVE-2026-32201 can be used to deceive employees, partners, or customers by presenting falsified information within trusted SharePoint environments.

β€œThis CVE can enable phishing attacks, unauthorized data manipulation, or social engineering campaigns that lead to further compromise,” Walters said. β€œThe presence of active exploitation significantly increases organizational risk.”

Microsoft also addressed BlueHammer (CVE-2026-33825), a privilege escalation bug in Windows Defender. According to BleepingComputer, the researcher who discovered the flaw published exploit code for it after notifying Microsoft and growing exasperated with their response. Will Dormann, senior principal vulnerability analyst at Tharros, says he confirmed that the public BlueHammer exploit code no longer works after installing today’s patches.

Satnam Narang, senior staff research engineer at Tenable, said April marks the second-biggest Patch Tuesday ever for Microsoft. Narang also said there are indications that a zero-day flaw Adobe patched in an emergency update on April 11 β€” CVE-2026-34621 β€” has seen active exploitation since at least November 2025.

Adam Barnett, lead software engineer at Rapid7, called the patch total from Microsoft today β€œa new record in that category” because it includes nearly 60 browser vulnerabilities. Barnett said it might be tempting to imagine that this sudden spike was tied to the buzz around the announcement a week ago today of Project Glasswing β€” a much-hyped but still unreleased new AI capability from Anthropic that is reportedly quite good at finding bugs in a vast array of software.

But he notes that Microsoft Edge is based on the Chromium engine, and the Chromium maintainers acknowledge a wide range of researchers for the vulnerabilities which Microsoft republished last Friday.

β€œA safe conclusion is that this increase in volume is driven by ever-expanding AI capabilities,” Barnett said. β€œWe should expect to see further increases in vulnerability reporting volume as the impact of AI models extend further, both in terms of capability and availability.”

Finally, no matter what browser you use to surf the web, it’s important to completely close out and restart the browser periodically. This is really easy to put off (especially if you have a bajillion tabs open at any time) but it’s the only way to ensure that any available updates get installed. For example, a Google Chrome update released earlier this month fixed 21 security holes, including the high-severity zero-day flaw CVE-2026-5281.

For a clickable, per-patch breakdown, check out the SANS Internet Storm Center Patch Tuesday roundup. Running into problems applying any of these updates? Leave a note about it in the comments below and there’s a decent chance someone here will pipe in with a solution.

Certificate Transparency Means What, Again?

By: BHIS
28 October 2016 at 11:06

Brian King // News from Google this week says that Chrome will start enforcing Certificate Transparency a year from now. https://groups.google.com/a/chromium.org/forum/#!topic/ct-policy/78N3SMcqUGw This means that when Chrome contacts a website, if […]

The post Certificate Transparency Means What, Again? appeared first on Black Hills Information Security, Inc..

❌
❌