From Ars Technica · · 1 min
Shared Chrome and Windows Exploit Kit Exposed in Global Cyberattacks
Four hacking groups exploited open-source patch delays and AI tools to deploy a potent browser exploit kit.
In brief
Four hacking groups exploited open-source patch delays and AI tools to deploy a potent browser exploit kit. Update Chromium browsers and Windows immediately to close vulnerability windows created by open-source patch gaps. Originally reported by Ars Technica.
Four hacking groups share one kit
Security researchers uncovered a shared exploit kit named BlueMoon that targets Chrome and Windows, used by at least four distinct threat actors.
“A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used...”
Chaining three zero-days together
BlueMoon combines two V8 JavaScript engine bugs in Chromium with a Windows kernel flaw, letting attackers run malicious code with full system rights.
Exploiting the open-source patch gap

Hackers exploited the time window between when fixes were committed to upstream Chromium code and when stable browser updates reached end users.
AI speeds up exploit creation
Attackers likely used AI tools to rapidly analyze public code fixes and weaponize browser exploits faster than human researchers typically could.
“This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development.”
Global targets across key industries
Campaigns struck US defense, aerospace, mining, and commodity trading entities, as well as organizations in Vietnam, Singapore, and Indonesia.
Threat remains for unpatched devices

Although vendor patches are available now, experts warn the exploit kit will continue spreading to financial cybercriminals and state-sponsored groups.
“Given its ease of adoption, it is likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors...”
What matters most
Update Chromium browsers and Windows immediately to close vulnerability windows created by open-source patch gaps.





