Description
Statistics
- 1 Post
Fediverse
A vulnerability can be patched and still be a zero-day for millions of users. Volexity co-founder and president Steven Adair will deliver the keynote at our upcoming Volexity Cyber Sessions in Amsterdam (October 29) on multiple cases from September 2026, when Volexity uncovered three distinct Chinese threat actors exploiting Chrome (CVE-2026-85046, CVE-2026-87491) and Windows (CVE-2026-85880) vulnerabilities. The Chrome vulnerabilities had already been fixed upstream in Chromium—but hadn't yet reached a public Chrome release—potentially allowing the threat actors to compromise fully up-to-date users. The identical exploit code reused across otherwise unrelated operations points to a shared supplier.
Steven will reconstruct these campaigns, tracing the exploit from upstream patch to active deployment and examining the evidence linking the operators despite their different infrastructure, targeting, and tooling, including a false-flag campaign designed to pin the blame on a Russian threat actor. The talk covers what this reveals about exploit supply chains, the risks created by the patch gap, and the attribution challenges posed when capabilities are shared between threat actors.
Seating is limited. Register now to secure your spot: https://luma.com/0qtkw49c
Overview
Description
Statistics
- 1 Post
Fediverse
A vulnerability can be patched and still be a zero-day for millions of users. Volexity co-founder and president Steven Adair will deliver the keynote at our upcoming Volexity Cyber Sessions in Amsterdam (October 29) on multiple cases from September 2026, when Volexity uncovered three distinct Chinese threat actors exploiting Chrome (CVE-2026-85046, CVE-2026-87491) and Windows (CVE-2026-85880) vulnerabilities. The Chrome vulnerabilities had already been fixed upstream in Chromium—but hadn't yet reached a public Chrome release—potentially allowing the threat actors to compromise fully up-to-date users. The identical exploit code reused across otherwise unrelated operations points to a shared supplier.
Steven will reconstruct these campaigns, tracing the exploit from upstream patch to active deployment and examining the evidence linking the operators despite their different infrastructure, targeting, and tooling, including a false-flag campaign designed to pin the blame on a Russian threat actor. The talk covers what this reveals about exploit supply chains, the risks created by the patch gap, and the attribution challenges posed when capabilities are shared between threat actors.
Seating is limited. Register now to secure your spot: https://luma.com/0qtkw49c