<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Spear-Phishing on CuraSec</title><link>https://curasec.metacog.co.kr/tags/spear-phishing/</link><description>Recent content in Spear-Phishing on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 15 Sep 2026 15:32:56 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/spear-phishing/index.xml" rel="self" type="application/rss+xml"/><item><title>UTA0560 Exploits Chrome-Windows Zero-Day Chain to Drop GRIMWEDGE</title><link>https://curasec.metacog.co.kr/insights/2026-09-15-china-linked-hackers-exploit-chrome-windows-zero-day-chain-t/</link><pubDate>Tue, 15 Sep 2026 15:32:56 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-15-china-linked-hackers-exploit-chrome-windows-zero-day-chain-t/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Actively exploited Chrome and Windows flaws (now patched) are being chained to deliver a JavaScript backdoor; verify that Chrome and Windows September 2026 security patches are fully deployed across your fleet immediately.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active UTA0560 spear-phishing campaign delivering the GRIMWEDGE JavaScript backdoor since September 1; hunt for associated IOCs from Volexity&amp;rsquo;s reporting and tune email gateway and endpoint detections for this campaign&amp;rsquo;s delivery patterns.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A China-linked threat actor is running targeted spear-phishing against NGOs using a patched browser/OS exploit chain — notable for sector threat-awareness but not a systemic event requiring board action unless your organization is in the NGO space.&lt;/li>
&lt;/ul></description></item></channel></rss>