Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Hackers Target Chrome-Windows with Zero-Day Exploits

Chinese Hackers Target Chrome-Windows with Zero-Day Exploits

Posted on September 23, 2026 By CWS

In a recent cybersecurity incident, a group of hackers identified as UTA0565 has been found exploiting a series of zero-day vulnerabilities in Google Chrome and Microsoft Windows. These attacks were first detected on September 3 and 4, 2026, and involve a sophisticated chain of exploits targeting high-profile applications.

Details of the Exploit Chain

The hackers utilized two specific vulnerabilities in Chrome, identified as CVE-2026-85046 and CVE-2026-87491, along with a weakness in the Windows Advanced Local Procedure Call, noted as CVE-2026-85880. This combination allowed the attackers to bypass browser security measures and execute remote code, posing significant risks to users.

According to researchers Damien Cash and Tom Lancaster from Volexity, UTA0565 employed deceptive tactics by posing as legitimate entities like media organizations and NGOs. This strategy involved creating fake websites to lure victims into their trap.

Targeted Phishing Campaigns

One notable campaign orchestrated by UTA0565 targeted government bodies in Asia. The attackers sent phishing emails in both Chinese and English, encouraging recipients to support Hong Kong activist Chow Hang-tung, who was recently sentenced to prison. The emails impersonated the Center for American Progress and directed users to fraudulent websites resembling legitimate ones.

The malicious sites loaded hidden HTML elements, deploying an exploit kit that combined the identified vulnerabilities to deliver a payload known as CLEANGULP. This malware was crafted using Microsoft’s Visual C Compiler and featured capabilities such as command execution and file manipulation.

Implications and Broader Impact

The CLEANGULP malware communicated with a hard-coded command-and-control domain, a clever imitation of a reputable media outlet’s domain, indicating a broader strategy to evade detection. Volexity suggests that this attack might be part of a larger coordinated effort within the Chinese cyber espionage community, as the toolkit appears to have been shared and adapted by multiple groups.

While the current findings are based on limited observations, the potential reach and impact of these attacks are likely extensive, emphasizing the need for heightened vigilance in cybersecurity practices.

As cybersecurity threats continue to evolve, it is crucial for individuals and organizations to stay informed and take proactive measures to protect their digital assets against such sophisticated attacks.

The Hacker News Tags:Chinese hackers, Chrome vulnerability, CLEANGULP malware, CVE-2026-85046, CVE-2026-85880, CVE-2026-87491, cyber threats, Cybersecurity, phishing attacks, Windows exploit, zero-day

Post navigation

Previous Post: Leading Decentralized Identity Solutions for 2026
Next Post: ShinyHunters Allegedly Breach FBI Systems, Demand Retraction

Related Posts

Windows Vulnerabilities: BitLocker Bypass and CTFMON Exploit Windows Vulnerabilities: BitLocker Bypass and CTFMON Exploit The Hacker News
Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time The Hacker News
China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines The Hacker News
ASUS Patches DriverHub RCE Flaws Exploitable via HTTP and Crafted .ini Files ASUS Patches DriverHub RCE Flaws Exploitable via HTTP and Crafted .ini Files The Hacker News
U.S. Arrests Key Facilitator in North Korean IT Worker Scheme, Seizes .74 Million U.S. Arrests Key Facilitator in North Korean IT Worker Scheme, Seizes $7.74 Million The Hacker News
Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SolarWinds Vulnerabilities Enable Remote Code Execution
  • Adobe Issues Patches for Critical Security Flaws
  • Malicious Streaming App Threatens Android Devices
  • Chrome 154 Secures Users with 108 Vulnerability Fixes
  • AI-Powered Cyberattacks: New Era of Fraud and Trust Misuse

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SolarWinds Vulnerabilities Enable Remote Code Execution
  • Adobe Issues Patches for Critical Security Flaws
  • Malicious Streaming App Threatens Android Devices
  • Chrome 154 Secures Users with 108 Vulnerability Fixes
  • AI-Powered Cyberattacks: New Era of Fraud and Trust Misuse

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark