Four spy groups exploit same Chrome, Windows zero-days

13 sources
  • Proofpoint said Wednesday that a kit called BlueMoon chains Chrome and Windows flaws to give attackers full system control via phishing emails.
  • The first confirmed use came from China-aligned APT31 on Aug. 28, targeting U.S. NGOs and commodity firms; three more clusters adopted it within days.
  • Researchers flagged signs of AI-assisted exploit development, warning the barrier to weaponizing browser vulnerabilities may be falling.
Sources (13)
  1. 1 Once in a BlueMoon: Multiple State-Aligned Threat Actors ... www.proofpoint.com
  2. 2 Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week thehackernews.com
  3. 3 Multiple Chinese hacking groups seen using identical Chrome zero ... therecord.media
  4. 4 Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks cybersecuritynews.com
  5. 5 Novel Blue Moon kit targeting Chrome and Windows reflects new ... www.theregister.com
  6. 6 Chinese espionage groups swarm to exploit triple-link chain of zero ... cyberscoop.com
  7. 7 4 groups caught using the same Chrome and Windows exploit kit arstechnica.com
  8. 8 Chinese state-linked hackers exploit Chrome vulnerability - SC Media www.scworld.com
  9. 9 AI is collapsing the patch-gap window from weeks to days - Indoneo www.indoneo.com
  10. 10 New BlueMoon Exploit Kit Targets Chrome and Windows cyberwebspider.com
  11. 11 Cybersecurity Intelligence, News & Insights | Proofpoint US www.proofpoint.com
  12. 12 BlueMoon Exploit Kit Chains Chrome and Windows Flaws letsdatascience.com
  13. 13 RST Cloud (@rst_cloud) on X x.com