Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects

2026-09-22T20:51:36Z•4b33cb399aa76a28359184e6f51d3ee9fc4f9602385a05011e6fce24b10fd4f5
CVE-2026-76460AI-assisted cybercrimeChina-aligned threat actorsChromeCisco Identity Services EngineEvilTokensMicrosoft vulnerabilitiesNorth KoreaScattered SpiderUTA0565WaterPlumaccount takeoveractive exploitationbusiness email compromisecryptocurrency theftexploit chainsinfostealersphishing-as-a-serviceremote code executionsocial engineeringsoftware decoder vulnerabilitywater utilitieszero-day

What happened

CyberScoop coverage highlights active exploitation of Chrome, Microsoft, and Cisco vulnerabilities by China-aligned and other threat actors; AI-assisted phishing and cybercrime services; infostealer exposure affecting water utilities; North Korean social-engineering campaigns targeting job seekers; and a high-severity decoder flaw enabling remote code execution. The most urgent item is the actively exploited Cisco Identity Services Engine zero-day, identified as CVE-2026-76460.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
4b33cb399aa76a28359184e6f51d3ee9fc4f9602385a05011e6fce24b10fd4f5
Enrichment time
2026-09-22T20:51:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.