- Engineer — Act: Actively exploited Chrome and Windows flaws (now patched) are being chained to deliver a JavaScript backdoor; verify that Chrome and Windows September 2026 security patches are fully deployed across your fleet immediately.
- SOC/IR — Act: Active UTA0560 spear-phishing campaign delivering the GRIMWEDGE JavaScript backdoor since September 1; hunt for associated IOCs from Volexity’s reporting and tune email gateway and endpoint detections for this campaign’s delivery patterns.
- Leader — Learn: A China-linked threat actor is running targeted spear-phishing against NGOs using a patched browser/OS exploit chain — notable for sector threat-awareness but not a systemic event requiring board action unless your organization is in the NGO space.