# Shared Chrome and Windows Exploit Kit Exposed in Global Cyberattacks

> Four hacking groups exploited open-source patch delays and AI tools to deploy a potent browser exploit kit.
- Title: Shared Chrome and Windows Exploit Kit Exposed in Global…
- Summary: Four hacking groups exploited open-source patch delays and AI tools to deploy a potent browser exploit kit. Update Chromium browsers and Windows immediately…
- Keywords: cybersecurity, chromium, zero-day, malware, hacking, technology, science, Shared, Chrome, Windows, Exploit, Kit
- Source: Ars Technica — https://arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit
- Published: 2026-09-09T20:55:02+00:00
- Read time: 1 min
- Topics: cybersecurity, chromium, zero-day, malware, hacking, technology, science
## Four hacking groups share one kit
Security researchers uncovered a shared exploit kit named BlueMoon that targets Chrome and Windows, used by at least four distinct threat actors.

> A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used...
## Chaining three zero-days together
BlueMoon combines two V8 JavaScript engine bugs in Chromium with a Windows kernel flaw, letting attackers run malicious code with full system rights.
## Exploiting the open-source patch gap
Hackers exploited the time window between when fixes were committed to upstream Chromium code and when stable browser updates reached end users.
## AI speeds up exploit creation
Attackers likely used AI tools to rapidly analyze public code fixes and weaponize browser exploits faster than human researchers typically could.

> This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development.
## Global targets across key industries
Campaigns struck US defense, aerospace, mining, and commodity trading entities, as well as organizations in Vietnam, Singapore, and Indonesia.
## Threat remains for unpatched devices
Although vendor patches are available now, experts warn the exploit kit will continue spreading to financial cybercriminals and state-sponsored groups.

> Given its ease of adoption, it is likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors...
## Key takeaway

Update Chromium browsers and Windows immediately to close vulnerability windows created by open-source patch gaps.