SPOJENO AI KEV ✓ (3 z 3) EPSS 0.01 (nejvyšší)
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]
CVE v události 3
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-85046 | 8.8 3.1 · CISA-ADP | KEV ✓ | 0.01 |
| CVE-2026-85880 | 7.8 3.1 · microsoft | KEV ✓ | 0.01 |
| CVE-2026-87491 | 8.8 3.1 · CISA-ADP | KEV ✓ | 0.01 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.
Jak se o tom psalo 6
-
· Volexity US
Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits
On September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different Chinese advanced persistent threat (APT) actors. Shortly after that blog post was published, Volexity discovered additional campaigns—this time from a third Chinese threat actor, tracked by Volexity under the alias UTA0565—that used the same chained exploits on September…
-
· Malwarebytes Labs US
BlueMoon exploit kit turns Chrome and Windows flaws into attacks
BlueMoon, a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble. Security updates are easy to put off. The browser still opens, Windows still works, and choosing to relaunch your browser or restart your computer later can feel harmless. But a newly documented exploit kit called “BlueMoon” shows how quickly patching delays can become dangerous. Proofpoint Researchers found four espionage groups using the same exploit chain against Chrome browsers running…
-
· BleepingComputer US nadpis události
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]
-
· Proofpoint US
Four groups caught using the same Chrome and Windows exploit kit
-
· Volexity US
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
On September 1, 2026, Volexity’s Network Security Monitoring (NSM) service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmental organizations (NGOs). The emails contained a message encouraging the users to a click a link that led to the website of a US-based university. These links abused a reflected cross-site scripting (XSS) vulnerability on the website, redirecting recipients to threat-actor-controlled…