Tech & AI News
Ars Technica

4 groups caught using the same Chrome and Windows exploit kit

BlueMoon chains two Chromium vulnerabilities and a Windows 10 kernel flaw (Oct 2018 Update, Windows 10 2004, Windows Server 2019, Windows Server 2022, initial Windows 11) to install malware. Proofpoint identified use by at least four hacking groups, some linked to the Chinese government. All three vulnerabilities were patched within 24 hours. The kit’s rapid deployment and broad sharing indicate exploitation of a Chromium supply-chain patch gap and use of AI to locate vulnerabilities.