Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days

released on 2026-09-09 @ 11:12:35 AM
Four espionage-motivated threat actors have been observed deploying the BlueMoon exploit kit, which chains Chrome browser and Microsoft Windows vulnerabilities. The initial adopter was China-aligned TA412 on 28 August 2026, followed by several other suspected China-nexus groups within days. The exploit chain targets CVE-2026-85046 (Chromium V8 type-confusion), a V8 sandbox escape, and CVE-2026-85880 (Windows kernel LPE affecting older builds). Both V8 vulnerabilities were patch-gap zero-days, with fixes available in upstream Chromium but not yet deployed in stable releases. The rapid adoption by multiple actors and low operational security suggest rushed deployment ahead of anticipated patches. Evidence including extensive logging, verbose comments, and markdown references indicate potential AI-assisted development. BlueMoon's ease of adoption suggests further proliferation among espionage and financially motivated actors is likely.