One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several […]
Pierluigi Paganini
September 15, 2026

Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail.
Related breach coverage
- Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days2026-09-10
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use. Google’s Threat Intelligence Group, Microsoft’s MSTIC, and Volexity all contributed to […]
- Multiple Chinese hacking groups seen using identical Chrome zero-day exploit2026-09-09
A Google Chrome bug identified in August was exploited by at least four China-linked cyber-espionage groups, according to researchers.
- BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days2026-09-12
Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek.
- Anthropic caught Russia-linked spies using Claude in hacking operations2026-09-11
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations.