
BlueMoon Exploit Kit Exploits Patch Gap Across Four Groups
Proofpoint researchers identify BlueMoon, a near-identical exploit kit chaining two Chromium V8 flaws and a Windows kernel vulnerability to drop malware, used by at least four groups (TA412 and three other China-aligned actors) against NGOs, mining firms, traders, and aerospace targets. The campaign leveraged a Chromium patch gap and AI-assisted vulnerability discovery, exploiting CVE-2026-85046 and CVE-2026-85880 with patches issued within 24 hours, and may continue to spread as Chromium-based browsers are updated.