CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Chinese espionage groups swarm to exploit triple-link chain of zero-days

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6860

As cited

Copy frozen at (site build).

threat intel

Chinese espionage groups swarm to exploit triple-link chain of zero-days

At least four Chinese state-aligned espionage groups exploited a chain of three zero-day vulnerabilities spanning Chromium-based browsers and Windows since late August 2026. The BlueMoon exploit kit targets CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to achieve remote code execution, sandbox escape, and privilege escalation. Groups including APT31 delivered the exploits via phishing emails to organizations in aerospace, mining, commodities trading, and government sectors across the United States and Southeast Asia.

Why it matters: Organizations running Chromium browsers and Windows face active exploitation by Chinese espionage groups; practitioners should prioritize patching CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 and monitor for malicious browser extensions, credential theft, and browser-based surveillance activity.

VendorsCloudflareGitHubGoogleMicrosoftOracleVMware
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary