At least four China-linked hacking groups used the same previously unknown Google Chrome exploit kit in real attacks starting in late August 2026. Proofpoint said the shared kit, called BlueMoon, targeted Chrome users at U.S. defense contractors, nonprofits and NGOs, and Southeast Asian government agencies, combining two browser flaws with a Windows privilege-escalation bug to take over victim systems. The underlying Chromium vulnerability had been patched in source code in early August, but a four-week delay before the stable Chrome release created a patch gap the attackers exploited.
Why it matters: This is an active espionage campaign hitting sensitive organizations, and it shows attackers can weaponize Chrome fixes before most users receive them. Organizations should update Chrome immediately, watch for follow-on malware, and treat browsers as a high-priority patching surface.
2026.09.09
95% relevant
This article appears to be a fuller report on the same underlying BlueMoon exploit-kit campaign, adding that Proofpoint saw fewer than 20 organizations targeted globally, identifies TA412/Violet Typhoon as an early user against U.S. NGOs, mining companies, and commodity traders, and names the Windows privilege-escalation bug as CVE-2026-85880 alongside Chromium bug CVE-2026-85046.
info@thehackernews.com (The Hacker News)
2026.09.09
96% relevant
This appears to cover the same underlying event: four espionage groups reusing the same Chrome and Windows exploit kit within a short time window, adding reporting detail about the coordinated or shared exploitation pattern.
2026.09.09
100% relevant
This article establishes a distinct new event: multiple separate China-linked espionage groups shared and used the same Chrome zero-day exploit kit in concurrent real-world attacks, rather than a single vendor patch or a previously tracked Chrome zero-day story.
← Back to all stories