ZeroHour

Search: “stealth”

390 stories

Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day

Lazarus used a post-quantum key exchange to shield delivery of a Windows zero-day exploit, adding stealth to its campaign.

North Korean Lazarus Group malware used a post-quantum key exchange to protect the delivery of a Windows zero-day exploit. The technique adds a layer of stealth to the campaign's initial access, complicating detection and traffic inspection. It signals growing APT adoption of post-quantum cryptography in offensive operations.

Infosecurity Magazine · Aug 12, 2026Threat actor in the wild

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

Volexity reports China-linked UTA0560 and JungleBamboo chained Chrome zero-day CVE-2026-85046 with kernel flaws to spy on NGOs.

Volexity documented campaigns detected on September 1, 2026, in which China-linked actors UTA0560 and JungleBamboo (APT31) chained CVE-2026-85046 (V8 type confusion), CVE-2026-87491 (WebAssembly sandbox escape), and CVE-2026-85880 (Windows kernel privilege escalation in RtlpCreateServerAcl). Victims were lured via links on legitimate U.S. university sites vulnerable to reflected XSS, then served hidden exploit iframes behind a donation-form image. Although a V8 fix had landed in Chromium's source after private August reporting, Chrome had not yet shipped it, creating a patch gap the actors exploited. The two groups installed distinct payloads: UTA0560 delivered the GRIMWEDGE JScript backdoor via DLL side-loading, while JungleBamboo used the SUPERSTOMP loader to install the LONGTALE credential-stealing Chrome extension disguised as Google Gemini.

GBHackersupdated · 15h agofirst · 4d agoExploit / PoC in the wild 11 sourcesCVE-2026-85046CVE-2026-87491CVE-2026-858802· 1 read

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

Anthropic disrupted APT29-linked GTG-20006, which used Claude to autonomously rebuild malware, hijack hotel Wi-Fi DNS, and target 20-plus Ukrainian, European, and US-linked organizations.

Anthropic attributed the campaign to GTG-20006, aligned with Midnight Blizzard (APT29/Cozy Bear), which developed an AI-driven process that monitors its implants against security products and autonomously rebuilds and redeploys detected malware. Targets included military intelligence, diplomatic, and defense organizations in Ukraine and Europe, plus Middle East and Asian maritime agencies; the actor compromised at least three hotel Wi-Fi vendors via DNS hijacking and served ClickFix lures delivering Windows, Android, and iOS malware such as PowerChrome, GiftDrop, and DarkSword. Operations also included a North African breach exfiltrating over 300,000 national identity records and 500,000-plus company registry entries, an Embassy Kit device-code phishing campaign stealing Microsoft 365 tokens from at least eight organizations, and WhatsApp account takeover using headless browsers. The campaign overlaps with CaptiveCrunch reporting from ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs.

The Hacker Newsupdated · 13h agofirst · 5d agoThreat actor in the wild 20 sources2

Four groups caught using the same Chrome and Windows exploit kit

Proofpoint reports at least four hacking groups, some China-linked, share the BlueMoon exploit kit chaining Chromium and Windows kernel vulnerabilities to install malware.

Proofpoint named the nearly identical kit BlueMoon; it chains two Chromium vulnerabilities with one Windows kernel privilege-escalation flaw affecting Windows 10 (October 2018 Update and 2004), Windows Server 2019 and 2022, and the initial Windows 11 release. All three vulnerabilities received patches within 24 hours of the activity. The kit is being actively used by at least four hacking groups, some with Chinese government ties. Proofpoint links the rapid, visible sharing of a historically rare full browser exploit chain to the Chromium supply-chain patch gap and AI-assisted exploit development.

Proofpoint Threat Insight · 7d agoExploit / PoC in the wild 3 sources1

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

Microsoft warns of Teams IT-impersonation intrusions deploying Node.js implants; Spring Ring vishing hit 150+ employees across 10 companies; The Gentlemen ransomware claims 683 victims.

Microsoft warned of a human-operated campaign abusing Teams external collaboration to impersonate IT help desk staff, deploy malicious MSI packages staging Node.js runtimes and obfuscated JavaScript implants, then pivot to domain controllers over WinRM. Unit 42 documented the Spring Ring vishing operation targeting over 150 employees across at least 10 companies using 26 attacker identities, including an NTLM relay variant against domain controllers. Sophos reported The Gentlemen ransomware (Gold Sherwood) reached 683 total victims by end of July 2026, adding 169 in July, with a playbook using BYOVD-based EDR killers and backup tampering. Group-IB found the Outsider phishing-as-a-service platform created 700+ new phishing pages within a month despite law enforcement takedowns.

The Hacker News · 13d agoThreat actor in the wild1

Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure

US and Korean agencies warn Gunra ransomware actors exploit Fortinet flaws and stealthily exfiltrate large data volumes, targeting critical infrastructure.

US and Korean authorities warned that Gunra ransomware actors exploit Fortinet vulnerabilities to gain access and use stealthy techniques to exfiltrate vast volumes of data, including from Microsoft services. The group is targeting critical infrastructure organizations. Defenders should prioritize Fortinet patching and watch for large, quiet data egress.

Infosecurity Magazine · Aug 12, 2026Ransomware in the wild

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

A Security researchers disclosed three Zoom annotation flaws enabling zero-click client hijacking; Zoom shipped fixes in June and July with no exploitation reported.

Researchers at A Security found three flaws in Zoom's annotation feature: CVE-2026-53413 (CVSS 8.3, buffer over-write), CVE-2026-53414 (CVSS 6.5, buffer over-read), and CVE-2026-53415 (CVSS 8.3, use-after-free). A crafted drawing object sent over the wrong message channel can overwrite adjacent memory and hijack another attendee's client with no user interaction. Fixes shipped in Zoom Workplace 7.1.5/7.0.6, VDI Client 7.0.11/6.6.16, and Zoom Rooms/Meeting SDK 7.1.0+ during June and July. No exploitation has been reported and the flaws are absent from CISA's Known Exploited Vulnerabilities catalog.