Multiple Chinese hacking groups seen using identical Chrome zero-day exploit

Image: The Record
ad slot · in-content video 16:9
Coverage
Coverage
- A Google Chrome bug identified in August was exploited by at least four China-linked cyber-espionage groups, according to researchers.
- A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors.
- The exploit provides full System privileges on Windows machines running the September 2026 patches. The post New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender appeared first on SecurityWeek .
More coverage
- The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher…
- Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned…