LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
vulnerability

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]

zeroday.news ·

Multiple cyber-espionage groups have deployed an exploit kit dubbed BlueMoon, which leverages zero-day vulnerabilities in Microsoft Windows and Google Chrome. The kit combines two security issues in Chromium-based browsers that enable remote code execution and sandbox escape, with a kernel local privilege escalation flaw in Windows.

Researchers at Proofpoint observed BlueMoon in use since August 28, 2026, in spearphishing operations attributed to the China-linked threat actor JungleBamboo, also known as APT31, Violet Typhoon, or Tide Castle. Separately, Volexity observed similar activity on September 1, 2026, in campaigns from another actor it tracks as UTA0560, which targeted customers at multiple non-governmental organizations (NGOs).

The BlueMoon exploit kit chains three specific vulnerabilities. The first two are in Chrome's V8 JavaScript engine: CVE-2026-85046, a type-confusion flaw that provides arbitrary memory access within the V8 sandbox, and CVE-2026-87491, a V8 sandbox escape that corrupts WebAssembly metadata to execute embedded shellcode. The third vulnerability, CVE-2026-85880, is a heap-based buffer overflow in Windows ALPC that allows for local privilege escalation.

Proofpoint suggests that CVE-2026-85880 was exploited as a classic zero-day, potentially since 2025, and later repackaged into BlueMoon. Evidence supporting this includes a 2025 compilation timestamp on the Local Privilege Escalation (LPE) DLL, which did not appear to be forged, and the exploit's targeting of older Windows builds. This indicates that the exploit creator likely integrated an existing capability into the BlueMoon kit.

The exploit operates within a Web Worker, retrying up to five times. It first fingerprints the system, then exploits the Windows privilege elevation flaw to elevate the Chrome renderer's privileges. Subsequently, it injects into Chrome's parent process to execute an operator-selected command. The default final command uses `curl` to save an executable, typically a malware loader, to the `%TEMP%` directory and then runs it.

Analysis by Proofpoint and Volexity has identified four distinct activity clusters associated with BlueMoon deployments, with three of these described as Chinese or China-aligned. JungleBamboo, a Chinese state-sponsored actor, is known for targeting NGOs in the US, mining companies, and high-value individuals, often using the Longtale/GemStone credential stealer disguised as Google Gemini.

The second group, UTA0560, targeted NGOs using donation-themed lures. Their infection chain delivered Grimwedge, an in-memory JScript backdoor used for reconnaissance, file and process management, command execution, and payload uploads. A third cluster, tracked as UNK_LateNight, has been observed deploying the ShadowPad backdoor on systems belonging to U.S. aerospace and defense-industrial-base companies.

A fourth group, UNK_DoubleCheck, targeted Vietnamese manufacturing firms with an in-memory Rust loader. However, the final payload in these attacks could not be retrieved for analysis.

Researchers note that the BlueMoon developers exploit the delay between public Chromium fixes and stable Chrome releases. They reverse-engineer public code changes to create exploits that target users of downstream browsers.

Proofpoint anticipates an increase in BlueMoon's adoption and deployment, potentially extending to financially motivated attackers in the future. Defenders are advised to utilize the provided indicators of compromise from both reports to proactively block this activity.

vulnerabilityzero-daycloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.