home.social

#cve202685046 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cve202685046, aggregated by home.social.

fetched live
  1. China-Aligned Group Exploits Chrome, Microsoft Zero-Days

    A China-aligned threat group has been exploiting a chain of three zero-day vulnerabilities in Google Chrome and Microsoft Windows, highlighting a coordinated effort within the Chinese computer network exploitation community. This alarming discovery reveals the group's ability to rapidly weaponize and customize exploits across multiple…

    osintsights.com/china-aligned-

    #ChinaalignedGroup #ZeroDay #Cve202685046 #Cve202687491 #Cve202685880

  2. China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain

    Meet the sneaky hackers who just pulled off a triple threat: exploiting not one, not two, but three zero-day vulnerabilities to break free from Chrome's sandbox and wreak havoc on Windows hosts. Their latest move? A targeted spear-phish attack on NGOs via a cleverly crafted link.

    osintsights.com/china-linked-h

    #China #ZeroDay #Chrome #Windows #Cve202685046

  3. China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain

    Meet the sneaky hackers who just pulled off a triple threat: exploiting not one, not two, but three zero-day vulnerabilities to break free from Chrome's sandbox and wreak havoc on Windows hosts. Their latest move? A targeted spear-phish attack on NGOs via a cleverly crafted link.

    osintsights.com/china-linked-h

    #China #ZeroDay #Chrome #Windows #Cve202685046

  4. China-linked groups exploit BlueMoon kit to breach US and Southeast Asia targets

    China-linked groups are leveraging the BlueMoon exploit kit to launch targeted attacks on organizations in the US and Southeast Asia, with a surprisingly small number of groups behind a large-scale intrusion campaign that quickly evolved from testing to widespread reuse. Fewer than 20 organizations globally were hit, but experts warn…

    osintsights.com/china-linked-g

    #China #Bluemoon #ExploitKit #Cve202685046 #Chromium

  5. China-linked groups exploit BlueMoon kit to breach US and Southeast Asia targets

    China-linked groups are leveraging the BlueMoon exploit kit to launch targeted attacks on organizations in the US and Southeast Asia, with a surprisingly small number of groups behind a large-scale intrusion campaign that quickly evolved from testing to widespread reuse. Fewer than 20 organizations globally were hit, but experts warn…

    osintsights.com/china-linked-g

    #China #Bluemoon #ExploitKit #Cve202685046 #Chromium

  6. Multiple Spy Groups Exploit Chrome, Windows Flaws with BlueMoon Kit

    Multiple spy groups are rapidly adopting the BlueMoon exploit kit, leveraging vulnerabilities in Google Chrome and Microsoft Windows to carry out espionage operations, with a suspected China nexus. This kit chains together flaws in Chrome's V8 JavaScript engine and Windows, including several zero-day exploits.

    osintsights.com/multiple-spy-g

    #Bluemoon #ExploitKit #GoogleChrome #MicrosoftWindows #Cve202685046

  7. Google Discloses Chrome 0-Day Under Active Exploitation

    Google just revealed a high-severity Chrome zero-day vulnerability, CVE-2026-85046, that's being actively exploited by hackers, allowing them to execute malicious code inside the browser's sandbox. This type confusion bug in Chrome's V8 engine was reported by researcher Salvatore Gulizia on August 4, 2026.

    osintsights.com/google-disclos

    #ZeroDay #GoogleChrome #Cve202685046 #V8 #EmergingThreats

  8. Google Discloses Chrome 0-Day Under Active Exploitation

    Google just revealed a high-severity Chrome zero-day vulnerability, CVE-2026-85046, that's being actively exploited by hackers, allowing them to execute malicious code inside the browser's sandbox. This type confusion bug in Chrome's V8 engine was reported by researcher Salvatore Gulizia on August 4, 2026.

    osintsights.com/google-disclos

    #ZeroDay #GoogleChrome #Cve202685046 #V8 #EmergingThreats

  9. 🚨 [CISA-2026:0904] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

    ⚠️ CVE-2026-85046 (secdb.nttzen.cloud/cve/detail/)
    - Name: Google Chromium V8 Type Confusion Vulnerability
    - Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
    - Known To Be Used in Ransomware Campaigns? Unknown
    - Vendor: Google
    - Product: Chromium V8
    - Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

    #ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260904 #cisa20260904 #cve_2026_85046 #cve202685046

  10. 🚨 [CISA-2026:0904] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

    ⚠️ CVE-2026-85046 (secdb.nttzen.cloud/cve/detail/)
    - Name: Google Chromium V8 Type Confusion Vulnerability
    - Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
    - Known To Be Used in Ransomware Campaigns? Unknown
    - Vendor: Google
    - Product: Chromium V8
    - Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

    #ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260904 #cisa20260904 #cve_2026_85046 #cve202685046

  11. Google Patches Actively Exploited Chrome V8 Zero-Day Flaw

    Google just patched a high-severity Chrome zero-day flaw that's being actively exploited - a type confusion vulnerability in V8 that could let hackers run malicious code inside the browser's sandbox. This critical update brings Chrome's version up to 152.0.7977.82, so make sure you've got the latest version installed!

    osintsights.com/google-patches

    #ZeroDay #GoogleChrome #V8 #Cve202685046 #TypeConfusion