Thursday, October 8, 2026 SourcesAbout🌓
🇺🇸 US ▾
BREAKING
› Dominion still has pending lawsuits against election deniers such as Rudy Giuliani and Sidney Powell› Russia is 'going backwards' in equipment and deploying post WWII-era tanks, according to Western officials› Podcast: One country musician is calling for other artists to oppose assault rifles› Bidets save you money and reduce waste — we tested the best options out there› 50+ products to make your life easier and our planet cleaner› Mother's Day is around the corner. Here are 50+ thoughtful gifts she'll love› A head-to-toe guide of how men should dress this spring, and where they should shop› 42 of the most useful travel products you can buy on Amazon› The 7 best high-yield savings accounts of April 2023› Taxes are due tomorrow. Here's how to file for an extension› Dominion still has pending lawsuits against election deniers such as Rudy Giuliani and Sidney Powell› Russia is 'going backwards' in equipment and deploying post WWII-era tanks, according to Western officials› Podcast: One country musician is calling for other artists to oppose assault rifles› Bidets save you money and reduce waste — we tested the best options out there› 50+ products to make your life easier and our planet cleaner› Mother's Day is around the corner. Here are 50+ thoughtful gifts she'll love› A head-to-toe guide of how men should dress this spring, and where they should shop› 42 of the most useful travel products you can buy on Amazon› The 7 best high-yield savings accounts of April 2023› Taxes are due tomorrow. Here's how to file for an extension
Technology

Four groups caught using the same Chrome and Windows exploit kit

Ars Technica ·
Four groups caught using the same Chrome and Windows exploit kit

A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used by at least four hacking groups, some of which have ties to the Chinese government.

Researchers from security firm Proofpoint said Wednesday that BlueMoon, the name they gave to the kit, chains three vulnerabilities together so the attackers using it can install malware of their choice.

BlueMoon exploits two Chromium vulnerabilities and one in the kernel of Windows 10 (Oct.

2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11.

All three vulnerabilities have received patches in the past 24 hours.

Deployed rapidly, widely shared The attacks lacked the stealth found in many campaigns.

More often, hackers want to exploit newly discovered vulnerabilities sparingly to lengthen their longevity.

Proofpoint hypothesized that one reason for the widely used and visible exploit chain was to take advantage of a “patch gap” in the Chromium supply chain, which spans the time a patch is available from developers and the time that patch is incorporated into browsers such as Chrome and Edge.

Another likely contributor was the use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans.

Read full article Comments

Read the full article on Ars Technica ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on arstechnica.com — the content belongs to Ars Technica.

More from Ars Technica

See all ›

More in Technology

See all ›