This is the scariest part... An unpatched, unidentified Chrome 0-day on Windows being actively exploited against security researchers. Unidentified meaning nobody even knows what it is, so no fix is coming until that gets figured out. 😬
In addition to targeting users via social engineering, we have also observed several cases where researchers have been compromised after visiting the actors’ blog.
The victim systems were running fully patched and up-to-date Windows 10 and Chrome