the news now

The world's news, cross-checked among reputable sources.

This is a new development in a story we have covered before · earlier coverage

Four Espionage Groups Use BlueMoon Exploit Kit to Target Chrome and Windows

2 sources across 2 countries · United Kingdom · United States

Who reported this

  • The Register United Kingdom · Centre · Situation Publishing Ltd
  • Ars Technica United States · Centre · Conde Nast (Advance Publications)

What the colours mean

  • Left
  • Centre-left
  • Centre
  • Centre-right
  • Right
  • A hatched block means the outlet is affiliated with, or controlled by, a state.

Political lean describes where an outlet sits within the politics of its own country. It is never a position on a single global scale.

Political lean is comparable inside one country and not across them, which is why the bar groups by country first. Publicly funded broadcasters are not marked as state-linked.

The owner of each outlet is listed as a matter of record, not as a judgement about the outlet.

Every outlet covering this story shares the same political lean; read with that in mind.

At least four espionage groups, several with suspected links to China, are using a new exploit kit named BlueMoon to break into organizational networks in the US and Southeast Asia. Security researchers from Proofpoint discovered the kit, which chains three vulnerabilities together to install malware. The attack chain includes two Chromium based browser flaws, including a V8 type confusion vulnerability (CVE-2026-85046) and a sandbox escape, as well as a Windows privilege escalation vulnerability (CVE-2026-85880). Google and Microsoft have since released patches for these flaws.

Proofpoint researchers noted that the kit was developed and shared among multiple threat actors rapidly. One group, TA412, which is linked to China's Ministry of State Security, targeted non governmental organizations, mining companies, and physical commodity trading firms in the US starting August 28. The researchers observed that the attackers took advantage of a patch gap, which is the window of time between when a fix is committed to the open source Chromium code and when it is released in stable browser versions.

Proofpoint suggests that the rapid deployment and sharing of this high value capability may be driven by the use of AI agents, which can reduce the cost and barrier to entry for exploit development. While the damage currently appears limited, with fewer than 20 organizations globally identified as targets, researchers believe the actual number of victims is likely higher.

How each side framed it

Centre
Both center leaning outlets focused on the technical mechanics of the exploit and the role of AI in lowering the barrier for cyberattacks.

Sources

100% of the statements in this article were traced back to the source articles listed above.