Updated
Updated · Ars Technica · Sep 4
Four Hacking Groups Deploy 3-Flaw BlueMoon Kit Against Chromium and Windows
Updated
Updated · Ars Technica · Sep 4

Four Hacking Groups Deploy 3-Flaw BlueMoon Kit Against Chromium and Windows

3 articles · Updated · Ars Technica · Sep 4

Summary

  • Proofpoint said at least four hacking groups are actively using BlueMoon, a near-identical exploit kit that chains three flaws to install malware on targeted systems.
  • Two vulnerabilities hit Chromium-based browsers and one hits the Windows kernel, affecting Windows 10 versions including 1809 and 2004, Windows Server 2019 and 2022, and the initial Windows 11 release.
  • All three flaws were patched within the past 24 hours, but researchers said attackers moved fast to exploit a supply-chain patch gap before fixes reached downstream browsers such as Chrome and Edge.
  • Proofpoint said the kit was developed, deployed and shared across multiple actors within days, with some groups tied to the Chinese government and AI likely lowering the cost of building such exploit chains.
  • The campaign targeted a broad range of organizations, underscoring how publicly visible upstream patches in open-source codebases can quickly become mass exploitation opportunities.

Insights

How are hackers using AI to turn public browser fixes into devastating cyber weapons before you can even update your system?
What makes the patch gap in Chromium browsers a ticking time bomb for global aerospace and defense networks?