Act
active
UTA0560 Exploits Chrome-Windows Zero-Day Chain to Drop GRIMWEDGE
- Engineer — Act: Actively exploited Chrome and Windows flaws (now patched) are being chained to deliver a JavaScript backdoor; verify that Chrome and Windows September 2026 security patches are fully deployed across your fleet immediately.
- SOC/IR — Act: Active UTA0560 spear-phishing campaign delivering the GRIMWEDGE JavaScript backdoor since September 1; hunt for associated IOCs from Volexity’s reporting and tune email gateway and endpoint detections for this campaign’s delivery patterns.
- Leader — Learn: A China-linked threat actor is running targeted spear-phishing against NGOs using a patched browser/OS exploit chain — notable for sector threat-awareness but not a systemic event requiring board action unless your organization is in the NGO space.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.