DISCARDED: Tales From the Threat Research Trenches
DISCARDED: Tales From the Threat Research Trenches · Sep 16, 2026 · 56:22
Listen in the Podli app 🎧
Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.
Hello to all our cybernauts!
This week Selena is joined by not one, not two, but three guests — Mark Kelly, Julia Paluch, and Dave Galazin — to unpack Proofpoint's latest research. Mark walks through how it started: on August 28, the China-aligned actor TA412 (aka Violet Typhoon), previously known mostly for device registration phishing, suddenly began delivering a Chrome exploit — kicking off a frantic cross-team investigation involving partners at Google and Microsoft. Within days, three more state-sponsored clusters adopted the same exploit chain, dubbed BlueMoon; by the time the blog published, that number had grown to seven distinct clusters, plus an eCrime actor and a brand-new espionage group picking it up since.
Julia breaks down the Chrome half of the chain — a type confusion bug in the V8 engine chained with a sandbox escape — and introduces the concept of the "patch gap": the roughly four-week window between when a fix is committed to the public Chromium codebase and when it's fully rolled out to stable Chrome releases. During that window, the regression test accompanying the fix effectively doubles as a roadmap for building an exploit, especially with an LLM doing the heavy lifting of interpreting it.
Dave then covers the Windows half: a kernel heap bug that lets an attacker escalate from Chrome's heavily sandboxed, untrusted-integrity renderer process straight to full privileges — without needing any file system access first. He and Mark also make the case that this particular Windows exploit had likely been sitting unused for over a year, based on consistent compilation timestamps across the payload's debug information.
Selena, Mark, Julia, and Dave also dig into:
Plus: a very enthusiastic Chrome-tab-hoarding discussion, Julia's advice to enable Chrome crash reporting, and a well-earned round of "you need a vacation, Mark."
Resources Mentioned:
Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Dayshttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
For more information about Proofpoint, check out our website.
Episodes: DISCARDED: Tales From the Threat Research Trenches