China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
High · The Hacker News ·
Exploited
What happened
China-linked group UTA0560 used spear-phishing to exploit recently patched Chrome and Windows flaws, delivering the GRIMWEDGE JavaScript backdoor to NGOs from September 1, 2026.
What to do now
Patch Chrome and Windows immediately and enforce auto-updates. Block suspicious attachments and links, require phishing-resistant MFA, and hunt endpoints for GRIMWEDGE indicators. Verify CVE details and IOCs with the vendor advisory.
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.