Actor · non-state · Transnational & Hybrid
Chinese state hackers (Salt/Volt Typhoon)
Assessed 15 September 2026
Assessment
APT31 first deployed the BlueMoon exploit kit, chaining Microsoft Windows and Google Chrome vulnerabilities, on Aug 28, and several other suspected China-nexus espionage clusters adopted it within days. Salt Typhoon's long-running telecom and critical-infrastructure compromise, active since at least 2021 and spanning hundreds of organisations in more than 80 countries, remained unresolved through Sept 15 with no new public advisory.
Recent, assessed
- 2026-09-09Proofpoint zero-day chain report. cyberscoop.com
Level history
Levels set by research reviews. A level set by hand is shown at the top of the page while it is in force and is not part of this history.
| Date | Level | Review |
|---|---|---|
| 2026-09-15 | 4 | Weekly review |
| 2026-09-14 | 4 | Weekly review |
| 2026-09-12 | 4 | Weekly review |
| 2026-09-12 | 4 | Baseline |
Latest headlines 1
Matched to this entry by keyword from the pull of 19 Sep, 11:09 UTC. Not reviewed; some may be off-topic.