Skip to content
Ars Technica·

🚨BlueMoon Exploit Kit Targets Chromium and Windows

Four hacking groups are using this new exploit kit

TL;DR

BlueMoon exploits critical vulnerabilities in Chromium and Windows, used by four hacking groups. Attacks began on August 28, targeting a wide range of organizations.

BlueMoon, a new exploit kit, targets critical vulnerabilities in Chromium-based browsers and older Windows versions, used by four hacking groups. These groups, some with ties to the Chinese government, exploit three vulnerabilities to install malware. The kit's rapid development and deployment, coupled with AI's role in vulnerability detection, highlight the evolving threat landscape. Attacks began on August 28, targeting a wide range of organizations. The first V8 vulnerability is tracked as CVE-2026-85046, and the Windows bug is CVE-2026-85880.

BlueMoon Exploit Kit Targets Chromium and Windows — Ars Technica

Key Points

1

BlueMoon targets three critical vulnerabilities: two in Chromium's V8 engine and one in Windows kernel (CVE-2026-85880).

2

The kit was developed and deployed rapidly, with attacks beginning on August 28, 2023.

3

At least four hacking groups, including TA412, are actively using BlueMoon to target a wide range of organizations.

4

AI's role in vulnerability detection likely contributed to the rapid development and deployment of BlueMoon.

5

The kit's ease of adoption and high detection signals suggest it may continue to be used and proliferate further.

Why It Matters

BlueMoon targets critical vulnerabilities in Chromium and Windows, exploited by four hacking groups. Organizations running outdated systems are at risk, emphasizing the importance of timely patching and security updates. The rapid development and deployment of such tools highlight the evolving threat landscape, necessitating proactive security measures.

BlueMoonChromiumWindowsVulnerabilitiesExploit Kit

Frequently Asked Questions

Why does this matter?

BlueMoon targets critical vulnerabilities in Chromium and Windows, exploited by four hacking groups. Organizations running outdated systems are at risk, emphasizing the importance of timely patching and security updates. The rapid development and deployment of such tools highlight the evolving threat landscape, necessitating proactive security measures.

What happened?

BlueMoon exploits critical vulnerabilities in Chromium and Windows, used by four hacking groups. Attacks began on August 28, targeting a wide range of organizations.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,472 builders reading daily.

Also get