Thursday, 10 September 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 10 September 2026 at 03:15

Four hacking groups caught sharing the same Chrome and Windows exploit kit

Security firm Proofpoint has uncovered an exploit kit named BlueMoon that chains three critical Chromium and Windows vulnerabilities and is being used by at least four hacking groups, some tied to the Chinese government. All three flaws have already been patched.

Foto: Ars Technica

Researchers at security firm Proofpoint reported Wednesday that at least four separate hacking groups, some with ties to the Chinese government, are using an identical exploit kit dubbed BlueMoon.

The kit chains together three vulnerabilities: two affecting Chromium-based browsers such as Chrome and Edge, and one in the kernel of older Windows versions, including Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. By combining these three flaws, attackers can install malware of their choosing on a target's system. All three vulnerabilities have received patches within the past 24 hours.

Rapid, widely shared deployment

Unlike many campaigns where hackers try to exploit newly discovered flaws quietly to extend their usefulness, BlueMoon's use has been unusually visible, spreading quickly across multiple threat groups within days.

Proofpoint suggested one reason may be a "patch gap" in the Chromium supply chain — the interval between when developers release a fix and when that fix is actually incorporated into downstream browsers like Chrome and Edge. Because Chromium is open source, patches become publicly visible before they reach end-user browsers, giving attackers a window to reverse-engineer the fix and build a working exploit ahead of stable releases.

A second likely factor, according to the researchers, is the use of artificial intelligence, which can often identify vulnerabilities faster than human-only research. Both factors likely pushed the attackers to move fast before their opportunity closed.

Proofpoint noted that a fully weaponized Chrome exploit chain has historically been a rare, high-value capability, yet BlueMoon was developed, deployed, and shared across multiple threat actors within days — a pattern that suggests the cost and barrier to entry for building such tools is dropping as AI agents increasingly assist threat actors with exploit development, particularly against open source codebases like Chromium.

The four groups have targeted a wide range of organizations and companies.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category