cd /news/ai-safety/4-groups-caught-using-the-same-chrom… · home topics ai-safety article
[ARTICLE · art-125285] src=machinebrief.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

4 groups caught using the same Chrome and Windows exploit kit

Security firm Proofpoint said Wednesday that at least four hacking groups, some with ties to the Chinese government, are actively using a nearly identical exploit kit it named BlueMoon that chains three vulnerabilities in Chromium-based browsers and older versions of Windows. BlueMoon exploits two Chromium vulnerabilities and one in the Windows kernel affecting Windows 10 (Oct 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11, all of which received patches in the past 24 hours. Proofpoint attributed the kit's rapid, widely shared deployment to a Chromium supply-chain "patch gap" and to AI-based vulnerability discovery that can spot flaws faster than humans alone.

by read1 min views1 publishedSep 9, 2026
4 groups caught using the same Chrome and Windows exploit kit
Image: Machinebrief (auto-discovered)

Ars Technica AI A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors.

A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used by at least four hacking groups, some of which have ties to the Chinese government.

Researchers from security firm Proofpoint said Wednesday that BlueMoon, the name they gave to the kit, chains three vulnerabilities together so the attackers using it can install malware of their choice. BlueMoon exploits two Chromium vulnerabilities and one in the kernel of Windows 10 (Oct 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three vulnerabilities have received patches in the past 24 hours.

Deployed rapidly, widely shared #

The attacks lacked the stealth found in many campaigns. More often, hackers want to exploit newly discovered vulnerabilities sparingly to lengthen their longevity. Proofpoint hypothesized that one reason for the widely used and visible exploit chain was to take advantage of a “patch gap” in the Chromium supply chain, which spans the time a patch is available from developers and the time that patch is incorporated into browsers such as Chrome and Edge. Another likely contributor was the use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans.

Get AI news in your inbox

Daily digest of what matters in AI.

── more in #ai-safety 4 stories · sorted by recency
── more on @proofpoint 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/4-groups-caught-usin…] indexed:0 read:1min 2026-09-09 ·