Tag

Patch Gap

All articles tagged with #patch gap

China-Linked Hackers Deploy GRIMWEDGE via Chrome-Windows Zero-Day Chain
security25 days ago

China-Linked Hackers Deploy GRIMWEDGE via Chrome-Windows Zero-Day Chain

A China-nexus group (UTA0560) targeted NGOs with a spear-phishing campaign delivering a three-CVE Chrome/Windows zero-day chain (BlueMoon) to install the GRIMWEDGE backdoor. The chain uses CVE-2026-85046 and CVE-2026-87491 to escape the Chrome sandbox and CVE-2026-85880 for code execution, culminating in a loader (msgbox.exe) that fetches a malicious DLL (wsc.dll) via DLL sideloading and establishes a persistent command loop to execute C2 instructions from ocr.opusaccel.top. The backdoor supports system discovery, file and process management, and in-memory execution, with a payload rollout that includes an MSI-based obfuscated JavaScript backdoor. A second actor, JungleBamboo (APT31), used the same chain to deploy LONGTALE/GemStone, a credential-stealing Chrome extension. The campaign underscored a patch-gap risk between Chromium fixes and Chrome releases, creating an exploitation window before official patches arrived.

BlueMoon Exploit Kit Exploits Patch Gap Across Four Groups
technology1 month ago

BlueMoon Exploit Kit Exploits Patch Gap Across Four Groups

Proofpoint researchers identify BlueMoon, a near-identical exploit kit chaining two Chromium V8 flaws and a Windows kernel vulnerability to drop malware, used by at least four groups (TA412 and three other China-aligned actors) against NGOs, mining firms, traders, and aerospace targets. The campaign leveraged a Chromium patch gap and AI-assisted vulnerability discovery, exploiting CVE-2026-85046 and CVE-2026-85880 with patches issued within 24 hours, and may continue to spread as Chromium-based browsers are updated.

"Google's Weekly Chrome Security Updates: A Stronger Defense Against Hackers"
technology3 years ago

"Google's Weekly Chrome Security Updates: A Stronger Defense Against Hackers"

Google is increasing the frequency of security updates for Chrome, with weekly updates now being released alongside the regular stable channel updates. This move aims to address the "patch gap" between vulnerable users and the release of fixes, which could be exploited by bad actors. The new weekly updates will not change how Chrome is used or updated, and milestone releases will still arrive at the expected timing. Apple has also adopted a similar approach to address increasing security threats. Users will see more updates in general, and Google is testing a new update notification experience for a small percentage of users.

"Google Urges Android Manufacturers to Swiftly Address Security Issues, Closing Patch Gap"
technology3 years ago

"Google Urges Android Manufacturers to Swiftly Address Security Issues, Closing Patch Gap"

Google's Year in Review report highlights the patch gap issue in the Android ecosystem, where downstream manufacturers take too long to release security fixes provided by upstream vendors. This delay allows publicly known vulnerabilities to function as zero-days, leaving users vulnerable. Google cited examples of delayed patches, including an ARM Mali GPU vulnerability that took 6 months to fix and a Samsung Internet vulnerability caused by using an outdated version of Chromium. The report emphasizes the need for faster distribution of fixes to protect users and highlights the prevalence of variant vulnerabilities that require deeper analysis and thorough fixes.