BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports.

The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it on August 28. Within days, several other Chinese threat actors started using it, but the activity might not be exclusive to China-aligned groups.

“It is currently unknown how multiple distinct threat actors obtained access to the exploit kit. Given its ease of adoption, it is likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors,” Proofpoint notes.

The BlueMoon exploit kit was adopted fast because it chains together three vulnerabilities that were unpatched when it first emerged: two zero-days in Chrome and one in Windows.

Tracked as CVE-2026-85046 and CVE-2026-87491, the Chrome flaws were patched as zero-days on September 3 and September 8, respectively. Both impact the V8 JavaScript and WebAssembly engine.

The Windows zero-day, tracked as CVE-2026-85880, was fixed on September 2026 Patch Tuesday. It is a privilege escalation in Windows Advanced Local Procedure Call (ALPC).

Advertisement. Scroll to continue reading.

BlueMoon, Proofpoint says, exploits the V8 defects for sandbox escape, then fingerprints the host and executes the privilege escalation code. Next, a CreateProcess stub is injected into the parent Chrome broker process to download an executable via a curl command and execute it.

Proofpoint identified several packaging variations of BlueMoon, all using the same underlying exploit chain and identical orchestration and loading mechanisms.

Retrieved development artifacts suggest that the exploit kit’s creators might have used AI to build it, “though no single artifact conclusively confirms this,” Proofpoint says.

BlueMoon was initially used by Violet Typhoon in attacks targeting NGOs in the US, as well as mining entities and physical commodity trading firms.

Starting September 2, a second China-linked espionage group, tracked as UNK_LateNight, used it against multiple US aerospace companies, and a threat actor tracked as UNK_DoubleCheck targeted a manufacturing organization in Vietnam.

The next day, Chinese espionage group UNK_QuietRacket started using it in attacks against government, consulting, and financial entities in Indonesia and Singapore.

“BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development,” Proofpoint notes.

Related: North Korean Hackers Deploy New Linux Espionage Toolkit

Related: Modified ScreenConnect Clients Used in Worm-Like Campaign

Related: AI Speeds Up Malware Development, Not Its Success Rate: Analysis

Related: Rust Supply Chain Attack Linked to North Korean Hackers

https://www.securityweek.com/bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days/




GitLab Vulnerability Exploited One Day After Disclosure

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek.

https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/




Check Point Patches Critical VPN Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek.

https://www.securityweek.com/check-point-patches-critical-vpn-vulnerabilities/




Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation

Join the webinar for a focused, 20-minute discussion on Frontier Pace Governance, an approach to balancing automation, policy, and business risk as IT operations accelerate.

The post Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation appeared first on SecurityWeek.

https://www.securityweek.com/webinar-today-keep-pace-with-ai-a-new-operating-model-for-endpoint-remediation/




Critical NetScaler Vulnerability Exploited in Attacks

Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.

The post Critical NetScaler Vulnerability Exploited in Attacks appeared first on SecurityWeek.

https://www.securityweek.com/critical-netscaler-vulnerability-exploited-in-attacks/




Organizations Warned of Cisco Secure FMC Exploitation

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek.

https://www.securityweek.com/organizations-warned-of-cisco-secure-fmc-exploitation/




Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia.

Also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the security researcher came to fame for a series of zero-day exploits targeting Microsoft’s products, but has recently moved to other vendors as well.

In late August, Nightmare Eclipse released a privilege escalation zero-day in a Kaspersky endpoint security product. Dubbed HardBreacher, the exploit has been patched by Kaspersky on August 31.

Within a short window last week, Nightmare Eclipse dropped three new zero-day exploits, dubbed PrettyPrague, FalconFlank, and GreenSection.

The PrettyPrague proof-of-concept (PoC) code, the researcher says, targets the Avast sandbox to spawn a shell with full system privileges, and may also affect other GenDigital products, including AVG and Norton.

“Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges. We immediately initiated our security response procedures and have fixed the issue. We take all security matters seriously and encourage users to keep their products up to date to ensure they are protected,” a GenDigital spokesperson said, responding to a SecurityWeek inquiry.

Advertisement. Scroll to continue reading.

FalconFlank exploits a bug in the Office malicious macros remediation feature of CrowdStrike Falcon Sensor for privilege escalation, the researcher says.

“We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal,” CrowdStrike told SecurityWeek.

The GreenSection exploit, Nightmare Eclipse says, targets an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components.

“While this bug does not get SYSTEM privileges immediately, it can be used cross user to user boundary easily or even compromise the dwm.exe process. I didn’t look deeply into it, but I’d be happy to see someone making a full exploit out of it,” Nightmare Eclipse notes.

“We are aware of reports describing a proof-of-concept that demonstrates improper access controls on a shared memory section used by certain NVIDIA GPU display driver components on Windows. NVIDIA is reviewing the reported behavior through our established security and product engineering processes. NVIDIA takes reports of this nature seriously and is actively investigating to determine the root cause, affected configurations, and appropriate remediation,” an Nvidia spokesperson said.

Security researcher Kevin Beaumont said late last week that the Avast, CrowdStrike, and Kaspersky exploits work.

*updated with statement from Nvidia

Related: VMware Workstation and Fusion Updates Patch Critical Vulnerability

Related: Google Patches 6th Chrome Zero-Day of 2026

Related: Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/




Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores.

The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek.

https://www.securityweek.com/adobe-commerce-zero-day-exploited-to-backdoor-online-stores/




Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Hackers have been exploiting a critical-severity vulnerability in the Elementor Pro WordPress plugin to hack websites, WordPress security firm Defiant warns.

A highly popular drag-and-drop website builder, Elementor is a free WordPress plugin with over 10 million installations. Elementor Pro is the paid version that offers additional features, including a Form widget with support for File Upload fields.

The bug, tracked as CVE-2026-32475 (CVSS score of 9.8), is described as an arbitrary file upload issue in the function that handles form submissions.

While submissions are passed through the plugin’s validation and processing mechanisms, when the validation loop encounters an upload slot marked as empty, it triggers an error and returns, aborting the validation of other files in the field.

The normal behavior would be to continue, skipping the empty entry, but the vulnerability results in checks never being applied to the remaining files uploaded through the same form field.

An attacker can submit an upload field as an array with two parts: an empty slot that triggers the return, followed by a PHP payload that is uploaded without validation.

Advertisement. Scroll to continue reading.

Because the function that handles field processing correctly skips the empty slot and processes the second, unvalidated part of the field, the attacker-supplied file is written to disk.

“As a result, an unauthenticated attacker can request the uploaded file to execute their PHP payload on the server,” Defiant explains, noting that this could lead to full site compromise.

CVE-2026-32475 impacts all Elementor Pro plugin versions up to 4.2.1 and was patched in version 4.2.2 on August 19. Site owners should update to the fixed iteration as soon as possible.

According to Defiant, threat actors started exploiting the security defect immediately after the fixes landed. The security firm has blocked over 190,000 exploit attempts to date.

Successful exploitation of the vulnerability results in a PHP file being written to the /wp-content/uploads/elementor/forms/ directory, which stores uploaded form submissions.

Site administrators are advised to check the directory for the presence of any PHP file, which is a strong indicator of compromise (IoC). They should also check logs for requests to /wp-admin/admin-ajax.php and check their sites for backdoors if any evidence of compromise is discovered.

Defiant notes that Elementor Pro has over 6 million active installations, but it is unclear how many of them are affected. According to WordPress data, approximately two-thirds of Elementor’s 10 million installations run a vulnerable plugin version as of September 4.

Related: 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

Related: VMware Workstation and Fusion Updates Patch Critical Vulnerability

Related: Google Patches 6th Chrome Zero-Day of 2026

Related: Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

https://www.securityweek.com/elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites/




Sangoma Switchvox Vulnerabilities Exploited in the Wild

Threat actors have been exploiting a critical-severity vulnerability in the enterprise VoIP telephony management solution Sangoma Switchvox, Horizon3 and CISA warn.

Tracked as CVE-2026-9586 (CVSS score of 9.3) and described as an unauthenticated SQL injection issue, the security defect can be exploited remotely for arbitrary code execution.

It resides in an endpoint that processes XML content, which did not perform sanitization or parameterization when concatenating the user-controlled PhoneIP value into PostgreSQL queries.

“An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution,” a NIST advisory reads.

On Tuesday, cybersecurity firm Horizon3 warned that threat actors had started exploiting CVE-2026-9586 in the wild and shared indicators of compromise (IoCs) to help organizations identify potential intrusions.

On Wednesday, the US cybersecurity agency CISA added the security flaw to its Known Exploited Vulnerabilities (KEV) catalog along with six other issues, including the JFrog Artifactory bug and two SonicWall SMA1000 zero-days recently flagged as exploited.

Advertisement. Scroll to continue reading.

The fifth vulnerability added to CISA KEV is CVE-2026-48710, an HTTP request/response smuggling flaw in the lightweight ASGI framework Starlette that was publicly disclosed in May. Hackers have been exploiting it since May, Horizon3 said in early June.

Next in line is CVE-2026-49869, a critical-severity command injection defect in the open source orchestration platform Kestra that was disclosed in June and flagged as exploited by Microsoft last week.

The last vulnerability added to CISA’s KEV list on Wednesday is CVE-2026-59822, a high-severity authentication bypass in LiteLLM. Last week, Wiz said its honeypots caught exploit attempts targeting this bug.

CISA is urging federal agencies to patch these vulnerabilities within three days, except for the Kestra and Starlette flaws, which should be patched within two weeks, in line with BOD 26-04’s recommendations.

Related: Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

Related: Exploit Published for Fresh Cleo Harmony Vulnerability

Related: Hackers Start Exploiting Critical Langflow Vulnerability

https://www.securityweek.com/sangoma-switchvox-vulnerabilities-exploited-in-the-wild/