Cover art for Shared Chrome and Windows Exploit Kit Exposed in Global Cyberattacks

Shared Chrome and Windows Exploit Kit Exposed in Global Cyberattacks

Four hacking groups exploited open-source patch delays and AI tools to deploy a potent browser exploit kit.

Sep 9, 2026

6 cards · 1 min · tap to begin

From · · 1 min

Shared Chrome and Windows Exploit Kit Exposed in Global Cyberattacks

Four hacking groups exploited open-source patch delays and AI tools to deploy a potent browser exploit kit.

In brief

Four hacking groups exploited open-source patch delays and AI tools to deploy a potent browser exploit kit. Update Chromium browsers and Windows immediately to close vulnerability windows created by open-source patch gaps. Originally reported by Ars Technica.

Four hacking groups share one kit

Security researchers uncovered a shared exploit kit named BlueMoon that targets Chrome and Windows, used by at least four distinct threat actors.

A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used...

Chaining three zero-days together

BlueMoon combines two V8 JavaScript engine bugs in Chromium with a Windows kernel flaw, letting attackers run malicious code with full system rights.

Exploiting the open-source patch gap

Exploiting the open-source patch gap

Hackers exploited the time window between when fixes were committed to upstream Chromium code and when stable browser updates reached end users.

AI speeds up exploit creation

Attackers likely used AI tools to rapidly analyze public code fixes and weaponize browser exploits faster than human researchers typically could.

This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development.

Global targets across key industries

Campaigns struck US defense, aerospace, mining, and commodity trading entities, as well as organizations in Vietnam, Singapore, and Indonesia.

Threat remains for unpatched devices

Photo of Dan Goodin

Although vendor patches are available now, experts warn the exploit kit will continue spreading to financial cybercriminals and state-sponsored groups.

Given its ease of adoption, it is likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors...

What matters most

Update Chromium browsers and Windows immediately to close vulnerability windows created by open-source patch gaps.

Read the original on Ars Technica

React

Sign in to react and comment.

Comments (0)

Life is short. Keep it sweet. Respect others' opinions and be kind!

    Recommended next

    More decks on cybersecurity and related topics.