HackerFeeds

CyberSecurity News

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

The Hacker News
· September 23, 2026

AI summary

A Chinese threat actor, UTA0565, has been exploiting a zero-day chain in Google Chrome and Microsoft Windows. The exploitation involves two Chrome vulnerabilities and one Windows vulnerability, which are chained together to bypass security measures. This exploit chain is being used to deploy CLEANGULP malware through fake websites. The attacks were detected on September 3 and 4, 2026. The specific vulnerabilities being exploited are in Chrome and Windows Advanced Local Procedure Call. The threat actor is using this exploit chain to successfully break through security defenses.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.