The Actual News

Fact-first summaries of the news — stay informed, stay grounded.

4 groups caught using the same Chrome and Windows exploit kit

4 groups caught using the same Chrome and Windows exploit kit

Summary

A hacking tool called BlueMoon is being used by at least four groups to exploit security weaknesses in Chromium-based browsers like Chrome and in older Windows versions. This tool combines three known vulnerabilities to install harmful software quickly, taking advantage of the time delay between patches being released and applied.

Key Facts

  • BlueMoon targets two weaknesses in Chromium browsers and one in certain older Windows systems.
  • The affected Windows versions include Windows 10 (from October 2018 update), Windows Server 2019 and 2022, and the first release of Windows 11.
  • The vulnerabilities were patched by developers within 24 hours of being discovered.
  • Four hacking groups have used the BlueMoon exploit kit; two groups are linked to the Chinese government.
  • The groups targeted organizations in the US aerospace sector, Vietnamese manufacturing, and companies in Singapore and Indonesia.
  • Attackers used bugs in V8, which is the part of Chromium that runs JavaScript, to run malicious code remotely.
  • After the Chrome exploit, they used a Windows security flaw to gain full system control.
  • The quick sharing and use of this exploit kit show how artificial intelligence may be helping hackers discover and use vulnerabilities faster than before.
Read the Full Article

This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.

Save articles & personalize your feed — Create a free account