Act
active
Chinese Hackers Chain Chrome-Windows Zero-Days to Deploy CLEANGULP
- Engineer — Act: All three CVEs are CISA KEV-listed with public PoCs and confirmed active exploitation: patch Chrome for CVE-2026-85046 and CVE-2026-87491, and apply the Windows ALPC patch for CVE-2026-85880 immediately — every endpoint running Chrome on Windows is in scope.
- SOC/IR — Act: Nation-state actor UTA0565 is actively deploying CLEANGULP via drive-by fake websites; hunt for CLEANGULP IOCs across endpoints, review proxy/DNS logs for suspicious domains active around September 3–4, and tune detections for anomalous Windows ALPC activity triggered from browser processes.
- Leader — Act: A Chinese nation-state actor is weaponizing a three-CVE chain against Chrome and Windows — software present on virtually every enterprise endpoint — with all three CVEs CISA KEV-listed; confirm with engineering that the patch cycle is complete and brief leadership if your sector is a known UTA0565 target.
- Signals: CVE-2026-85046 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub · CVE-2026-85880 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub · CVE-2026-87491 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.