AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 16 Sept, 07:37

Two China-linked hacking groups chain three Chrome and Windows zero-days to breach non-profits, Volexity says

Volexity says two China-linked hacking groups chained three unpatched Chrome and Windows bugs to break into non-profit organizations, deploying a backdoor called Grimwedge and a fake Google Gemini browser extension.

Volexity, in a report also covered by The Hacker News, says two separate China-linked hacking clusters exploited a chain of three vulnerabilities - two in Google Chrome $GOOGL and one in Microsoft Windows $MSFT's ALPC component - to compromise multiple non-profit organizations starting around September 1, 2026. Victims were reached through phishing emails containing a link to a legitimate university website carrying a cross-site scripting flaw, which redirected them to attacker infrastructure. One cluster, tracked as UTA0560, installed a JavaScript backdoor called Grimwedge. A second cluster, JungleBamboo (also known as APT31), installed a credential-stealing Chrome extension disguised as Google Gemini. Volexity says the Chrome flaws had already been fixed in the open-source Chromium codebase but had not yet reached the released Chrome version, letting the attackers exploit that gap. Sources: Volexity, The Hacker News.

#cyber
Published on