logo

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

ID: a53aa4fb-c609-5018-bbe9-e18e3c686fe7

STIX ID: report--a53aa4fb-c609-5018-bbe9-e18e3c686fe7

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-09-10

Date Updated: 2026-09-10

Author: Bill Toulas

...
...

**BlueMoon exploit kit:** A modular exploit kit observed in active spearphishing campaigns chains two Chromium/V8 sandbox bypasses with a Windows ALPC local privilege escalation (three CVEs) to elevate Chrome renderer privileges and deploy loaders/backdoors; multiple state-aligned and other clusters (including JungleBamboo/APT31 and UTA0560) used it against NGOs, aerospace/defense suppliers, and manufacturing targets, and Proofpoint and Volexity published indicators and analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.