CuraSec

Act active

Chinese Hackers Chain Chrome-Windows Zero-Days to Deploy CLEANGULP

2026-09-23 15:27 UTC · The Hacker News · read the source ↗ #zero-day#apt#endpoint
  • Engineer — Act: All three CVEs are CISA KEV-listed with public PoCs and confirmed active exploitation: patch Chrome for CVE-2026-85046 and CVE-2026-87491, and apply the Windows ALPC patch for CVE-2026-85880 immediately — every endpoint running Chrome on Windows is in scope.
  • SOC/IR — Act: Nation-state actor UTA0565 is actively deploying CLEANGULP via drive-by fake websites; hunt for CLEANGULP IOCs across endpoints, review proxy/DNS logs for suspicious domains active around September 3–4, and tune detections for anomalous Windows ALPC activity triggered from browser processes.
  • Leader — Act: A Chinese nation-state actor is weaponizing a three-CVE chain against Chrome and Windows — software present on virtually every enterprise endpoint — with all three CVEs CISA KEV-listed; confirm with engineering that the patch cycle is complete and brief leadership if your sector is a known UTA0565 target.
  • Signals: CVE-2026-85046 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub · CVE-2026-85880 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub · CVE-2026-87491 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.