BlueMoon and WeChat show complete delivery-to-execution paths demonstrated in the field or on physical devices.
Proofpoint recovered deployed samples associated with four espionage clusters.
Google Chrome on Microsoft Windows desktops and servers targeted by the BlueMoon espionage exploit kit.
Web-delivered command execution outside the Chrome renderer sandbox
What changed is composition and use: three primitives now form an observed click-to-broker execution chain.
After the recipient opens a link in affected Chrome on Windows, the chain uses V8 read/write, replaces WebAssembly code and then uses an ALPC/WNF kernel exploit.
The final stage enables SeDebugPrivilege, injects into Chrome’s broker and runs an operator-selected executable outside the renderer sandbox.
Google confirms that Chrome 153 fixes CVE-2026-87491. The operational evidence makes stale affected Windows browser builds an immediate update target.
Attacker-controlled VoIP data reaches the vulnerable path while the phone is still ringing.
WeChat, Tencent's mobile messaging and calling application on iOS and Android.
Zero-click cross-platform code execution, account takeover, and wormable propagation
The chain turns an existing contact relationship into a no-interaction propagation path across iOS and Android.
A compromised friend account places the crafted call; pre-answer processing triggers memory corruption, code execution and account control.
Researchers demonstrated the full chain across three physical devices, including onward calls from a newly compromised account.
Updated clients and Tencent’s server-side block are the documented mitigations. We do not know whether every underlying root cause was removed.
This establishes deployment of a server-side block against the demonstrated exploit, not removal of the underlying client-side memory-corruption flaw.
SonicWall SMA1000, an enterprise VPN and secure-access appliance deployed physically or virtually at the network edge.
The public proxy reaches localhost Erlang; its hard-coded cookie yields appliance commands, stored LDAP credentials and access to internal directory services.
Campaign artifacts show SAM and LSA extraction and DCSync, while working public code covers the initial unauthenticated entry chain.
After appliance compromise, containment has to include the directory credentials and systems reached from the appliance.
Windows DNS Server on supported Windows Server releases and the DNS implementation in Windows 10 1607 and 1809.
The packet triggers a use-after-free in DNS processing and reaches the service context without authentication.
Fixed builds are identified, but the claim has no public exploit or independent reproduction behind it.
Check Point Security Gateway, Spark appliances and, for CVE-2026-85103, Security Management Server installations processing VPN certificates.
Malformed certificate data can reach either improper validation or an ASN.1-decoding heap overflow in deployments using Remote Access or Site-to-Site VPN.
Check Point has published fixes; no public exploit or independent reproduction was established.
Certain GIGABYTE motherboards whose BIOS includes the affected AMI Aptio UEFI BDS module.
Redundant boot entries survive vulnerable cleanup, letting the shell alter Secure Boot policy in memory and load unverified pre-OS code.
The prerequisite remains administrative or root control; today’s addition is the GIGABYTE-specific root cause and scope, not a new initial foothold.
GVfs, the GNOME virtual-filesystem service and its privileged admin backend on Linux desktops.
The race swaps a private socket pathname for a symlink before a privileged chown, allowing ownership of a security-sensitive root file to pass to the user.
CISA marks proof-of-concept exploitation, but we could not retrieve the upstream fix and do not know the corrected versions.
AWS Systems Manager Agent, endpoint-management software on EC2 instances, on-premises servers and other managed machines.
A permitted principal uses an equivalent link-local address representation to bypass the destination check, reach instance metadata and retrieve temporary role credentials.
The fixed agent canonicalizes addresses and expands the denylist for credential endpoints.
Android phones, tablets, and other devices using Android's wpa_supplicant-derived Wi-Fi stack.
Malformed EHT-operation data reaches an incorrect bounds check without user interaction; Google has published a fix.
We do not know which frame role reaches the parser or how the transmitter observes the out-of-bounds bytes.
Nintendo Switch, Switch Lite, and OLED-model game consoles running Nintendo's embedded system software.
The vulnerable function must be active and its temporary network information exposed; crafted traffic then turns a stack overflow into a ROP chain.
The resulting execution privilege and directly recoverable console data remain undisclosed.
Self-hosted LiteLLM AI gateways, commonly deployed as containers in cloud environments to proxy model-provider traffic.
The documented sk-1234 key, or no master key, exposes administrative custom-code guardrails that run uploaded Python in the root proxy process and can expose cloud credentials.
A partial fix is published, but its complete effect was not assessed for this brief.
The preinstalled OnePlus Account application on OnePlus 13R Android phones, which brokers authentication to OnePlus Cloud services.
The provider’s custom permission lacks signature-level protection, and September retesting confirmed that the returned token was accepted by the regional API.
The flaw remains unresolved, but end-to-end profile modification was not reproduced on current US or EMEA test accounts.
AOMEI Backupper, Windows backup and disk-cloning software that installs the amwrtdrv.sys kernel driver.
Its world-accessible driver performs unrestricted physical-disk operations without checking the caller’s token.
Published code demonstrates a GPT and UEFI-payload chain to pre-OS execution when Secure Boot is disabled; no corrected AOMEI release was established.
Zephyr, an embedded real-time operating system used in connected devices
While a dynamic channel is still half-open, Zephyr can resolve its destination CID and dispatch attacker-controlled data without requiring the CONNECTED state.
A fix is published, but its effect was not assessed here and no public proof or independent reproduction was located.
TP-Link Deco BE11000 v2, an embedded tri-band Wi-Fi 7 whole-home mesh router.
A crafted UDP packet reaches the TDDP module and triggers operating-system command injection with root privileges.
TP-Link has published a fix, but its effect was not assessed for this brief.
Skullcandy Dime 3 model S2DCW, consumer Bluetooth wireless earbuds.
NoInputNoOutput pairing succeeds outside pairing mode without owner approval, after which the attacker reconnects as trusted and reaches the headset microphone.
A consumer update path for already deployed firmware 1.0.0.28 units was not established.
Apple PDFKit, the PDF renderer used by Preview and applications on iPhone, iPad, and Mac.
Researchers placed an ordinary JPEG beneath a JPEG 2000 image in a JPX container. Apple PDFKit exposed the lower image, while independent renderers displayed the JPX layer.
That gives a sender one authenticated artifact whose visible meaning depends on the reviewer’s software.
While this divergence remains, high-consequence PDF reviews should compare a trusted rasterization or use the same controlled renderer on every side.
No additional findings today.
AOMEI adds an ordinary-user-to-UEFI chain when Secure Boot is disabled; GIGABYTE’s update clarifies an already privileged embedded-shell path.
AOMEI converts an ordinary Windows foothold into raw-disk and demonstrated pre-OS control; exact recent BitLocker triggers remain unresolved.
Operational BlueMoon use and SMA1000-hosted DCSync changed exploitation evidence; Check Point’s VPN execution scope also widened.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.