CuraSec

Act active

UTA0560 Exploits Chrome-Windows Zero-Day Chain to Drop GRIMWEDGE

2026-09-15 15:32 UTC · The Hacker News · read the source ↗ #zero-day#china-apt#spear-phishing
  • Engineer — Act: Actively exploited Chrome and Windows flaws (now patched) are being chained to deliver a JavaScript backdoor; verify that Chrome and Windows September 2026 security patches are fully deployed across your fleet immediately.
  • SOC/IR — Act: Active UTA0560 spear-phishing campaign delivering the GRIMWEDGE JavaScript backdoor since September 1; hunt for associated IOCs from Volexity’s reporting and tune email gateway and endpoint detections for this campaign’s delivery patterns.
  • Leader — Learn: A China-linked threat actor is running targeted spear-phishing against NGOs using a patched browser/OS exploit chain — notable for sector threat-awareness but not a systemic event requiring board action unless your organization is in the NGO space.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.