Skip to main content
Volexity Inc.

Volexity Inc.

Company

Search complete. 5 mentions across 3 episodes found for "Volexity Inc.".

Sep 11, 2026

Claire AirdHOST
8:33
The kit was spotted in late August.
Claire AirdHOST
8:35
According to Proofpoint and Volexity, at least two of the four groups using the kit have a Chinese state nexus.
Claire AirdHOST
8:43
Google has released patches for an actively exploited Chrome zero-day.
Claire AirdHOST
8:48
The zero-day is a memory corruption bug in Chrome's V8 JavaScript engine, and was discovered by a student at the Seoul National University.
Ryan NaraineHOST
127:39
Um, BlueMoon, Costin.
Ryan NaraineHOST
127:40
We got, uh, parallel reports from our friends at Proofpoint and our friends at Volexity showing multiple espionage actors, including, oh Lord, TA412, APT31, UTA0560, chaining Chromium, uh, type confusion bugs, a V8 sandbox escape on a Windows LPE, uh, in live attacks.
Ryan NaraineHOST
128:03
Google said it was aware of this CVE being exploited in the wild.
Ryan NaraineHOST
128:06
We just... we got a new Chrome bug.
Ryan NaraineHOST
128:26
Uh-
Costin RaiuHOST
128:26
Mm
Ryan NaraineHOST
128:26
... quick thoughts, Costin, on the Proofpoint and Volexity reporting here?
Costin RaiuHOST
128:29
here?Um, it's obviously is very interesting.
David ShipleyHOST
1:50
It's a link-following flaw that lets an authorized attacker elevate privileges locally.
David ShipleyHOST
1:56
The second, CVE-2026-85880, is a heap-based buffer overflow in the Windows Advanced Local Procedure Call, or ALPC, credited to researchers at Volexity and Proofpoint.
David ShipleyHOST
2:11
Microsoft hasn't shared details on how either flaw was exploited.
David ShipleyHOST
2:16
For defenders, the math here is pretty brutal.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.