China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
Reported exploitedChromeUTA0560WindowsOur summary
Chinese state-sponsored groups including UTA0560 and APT31 have been observed exploiting a multi-stage attack chain targeting recent vulnerabilities in Google Chrome and Microsoft Windows. The campaign leverages CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to breach non-governmental organizations and deploy backdoors such as GRIMWEDGE and LONGTALE. This incident highlights significant risks associated with patch gaps where fixes exist in upstream sources but have not yet propagated to stable consumer releases.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.