Future TechnologyFuture Technology
← Back to archive
Newsletter

BlueMoon turned a 27 day Chrome patch gap into four espionage campaigns

10 September 2026
BlueMoon turned a 27 day Chrome patch gap into four espionage campaigns
Future Technology

New article published

SECURITY

BlueMoon turned a 27 day Chrome patch gap into four espionage campaigns

Four state-aligned espionage groups deployed the same Chrome and Windows exploit chain within days of each other, according to research Proofpoint published on 9 September. The kit, which Proofpoint tracks as BlueMoon, was first seen in the wild on 28 August 2026 in the hands of the China-aligned actor TA412, also known as APT31 and Violet Typhoon.

Key Takeaways

  • Proofpoint published research on 9 September naming a Chrome and Windows exploit kit it tracks as BlueMoon, first seen on 28 August 2026
  • The chain links CVE-2026-85046 in Chrome's V8 engine, an unnumbered V8 sandbox escape, and CVE-2026-85880 in the Windows kernel
  • Both V8 bugs were patch-gap zero days: the CVE-2026-85046 fix landed in public Chromium source on 7 August but did not reach stable Chrome until 3 September
  • Three further clusters adopted the kit within six days, and Proofpoint says its code carries indicators consistent with AI-assisted development

You received this because you subscribe to Future Technology.

Unsubscribe