<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week]]></title><description><![CDATA[<p dir="auto">Multiple espionage-motivated threat clusters have been observed deploying a previously undocumented exploit kit dubbed <strong>BlueMoon</strong>, which chains together several vulnerabilities in <strong>Microsoft Windows</strong> and <strong>Google Chrome</strong>.</p>
<p dir="auto">The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as <strong>APT31</strong>, also known as <strong>Bronze Vinewood</strong>, <strong>Judgement Panda</strong>, and <strong>JungleBamboo</strong>.</p>
<p dir="auto">Key points from the reporting:</p>
<ul>
<li>The campaign involved multiple espionage-motivated threat activity clusters rather than a single actor.</li>
<li><strong>BlueMoon</strong> is an exploit kit that chains multiple vulnerabilities together in <strong>Windows</strong> and <strong>Chrome</strong>.</li>
<li>The kit was previously undocumented prior to this activity.</li>
<li>The earliest observed in-the-wild deployment is linked to <strong>APT31</strong>, a China-aligned state-sponsored group with several tracked aliases.</li>
</ul>
<p dir="auto">No specific CVE identifiers or patch numbers were provided in the source material, so none are listed here. Organizations should monitor vendor advisories for Chrome and Windows updates and prioritize timely patching of both browsers and endpoints, given the exploit kit's reliance on chaining multiple flaws across both platforms.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Has anyone seen related telemetry or additional details on the BlueMoon exploit chain in their environment?</p>
]]></description><link>https://xploitlk.com/topic/280/four-spy-groups-used-the-same-chrome-and-windows-exploit-kit-within-a-week</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 05:50:09 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/280.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 10 Sep 2026 02:30:23 GMT</pubDate><ttl>60</ttl></channel></rss>