← nejvýznamnější zprávy · všechny zprávy

SPOJENO AI KEV ✓ (3 z 3) EPSS 0.01 (nejvyšší)

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]

Číst originál na BleepingComputer →

6 zpráv z 4 zdrojů · první 9. 9. 19:36 · poslední 21. 9. 23:01 CZ · EN/orig

Google Microsoft veřejná správa US

tg: varování tg: zneužíváno tg: rozbor tg: propagace tp: malware tp: phishing tp: špionáž

CVE v události 3

CVEhodnoceníKEVEPSS
CVE-2026-85046 8.8 3.1 · CISA-ADP KEV ✓ 0.01
CVE-2026-85880 7.8 3.1 · microsoft KEV ✓ 0.01
CVE-2026-87491 8.8 3.1 · CISA-ADP KEV ✓ 0.01

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.

Jak se o tom psalo 6

  1. · Volexity US

    Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits

    On September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different Chinese advanced persistent threat (APT) actors. Shortly after that blog post was published, Volexity discovered additional campaigns—this time from a third Chinese threat actor, tracked by Volexity under the alias UTA0565—that used the same chained exploits on September…

  2. · Malwarebytes Labs US

    BlueMoon exploit kit turns Chrome and Windows flaws into attacks

    BlueMoon, a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble. Security updates are easy to put off. The browser still opens, Windows still works, and choosing to relaunch your browser or restart your computer later can feel harmless. But a newly documented exploit kit called “BlueMoon” shows how quickly patching delays can become dangerous. Proofpoint Researchers found four espionage groups using the same exploit chain against Chrome browsers running…

  3. · BleepingComputer US nadpis události

    New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

    Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]

  4. · Volexity US

    Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    On September 1, 2026, Volexity’s Network Security Monitoring (NSM) service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmental organizations (NGOs). The emails contained a message encouraging the users to a click a link that led to the website of a US-based university. These links abused a reflected cross-site scripting (XSS) vulnerability on the website, redirecting recipients to threat-actor-controlled…