New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
-
Multiple cyber-espionage groups have been observed deploying an exploit kit tracked as BlueMoon, which chained zero-day vulnerabilities in Microsoft Windows and Google Chrome.
According to reporting, the kit was used in targeted campaigns, with the zero-days giving attackers a way into victim environments before patches were available. The activity has been attributed to more than one espionage-focused threat group, suggesting the tooling was shared or reused across operations.
Key points:
- The exploit kit is named BlueMoon.
- It leveraged zero-day flaws in Windows and Chrome.
- Multiple cyber-espionage groups were involved in deploying it.
- The campaign relied on previously unknown vulnerabilities, meaning no fix was available at the time of exploitation.
Details on specific affected versions, indicators of compromise, and mitigation guidance were not provided in the source material.
Source: BleepingComputer
Has your organization reviewed its Windows and Chrome patch cadence in light of shared exploit kits like this one?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login