
Security firm Proofpoint identified a new exploit kit named BlueMoon, used by at least four hacking groups to target critical vulnerabilities in Chromium browsers and Windows kernels.
The attacks utilized CVE-2026-85046 and CVE-2026-85880 to execute remote code and gain system-level privileges, with all three involved vulnerabilities receiving patches within the last 24 hours.
Researchers noted that the exploit kit was rapidly developed and shared, likely leveraging AI to reverse-engineer public Chromium patches before they were applied to stable browser releases.