China-Linked Hackers Hit NGOs With GRIMWEDGE
China-linked hackers hit NGOs by exploiting newly patched vulnerabilities in Google Chrome and Microsoft Windows, cybersecurity firm Volexity reports. The hackers, tracked under the label UTA0560, launched a spear-phishing campaign on September 1, 2026, targeting multiple non-governmental organizations. Utilizing a zero-day chain, the attackers delivered a JavaScript backdoor known as GRIMWEDGE, leveraging the recently patched security flaws. These sophisticated attacks underscore ongoing vulnerabilities even in widely-used software platforms like Chrome and Windows, particularly when updates and patches are not immediately adopted by users.
Volexity’s monitoring reveals that the Chinese threat actor meticulously planned and executed the operation, adding to the rising frequency and precision of state-sponsored cyber assaults. The campaign not only highlights persistent threats from nation-state actors but also emphasizes the necessity of timely patch management to thwart such malicious attempts. Readers interested in understanding the full scope and details of this cybersecurity breach can access the complete article through the following link:
https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html
