Cookie Consent by Free Privacy Policy Generator

Four Threat Groups Exploit Same Chrome and Windows Vulnerability Chain Within Days

Security researchers at Proofpoint have identified four separate espionage-focused threat groups exploiting the same previously undocumented exploit kit, known as BlueMoon, which chains together vulnerabilities in Google Chrome and Microsoft Windows. The Register reports that the exploit kit was first used by the China-aligned group APT31, with three additional groups deploying the same tooling within a week. The vulnerabilities targeted include CVE-2026-87491, a Chrome V8 out-of-bounds write flaw, and related Windows privilege escalation issues. The speed with which multiple groups adopted the same exploit chain suggests either shared tooling, coordinated activity or rapid reverse-engineering of publicly disclosed vulnerability details. CISA has added the Chrome vulnerability to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild.

Why this matters for UK organisations

This highlights the operational risk created by the gap between vulnerability disclosure and patch deployment. When multiple threat groups exploit the same vulnerability chain within days, the window for defensive action becomes extremely narrow. Chrome and Windows are ubiquitous across UK businesses, making these vulnerabilities relevant to almost every organisation. The coordinated use of the same exploit kit by multiple groups also suggests that once a working exploit becomes available, it spreads quickly across different threat actors. This reinforces the importance of rapid patch deployment, particularly for widely used software such as browsers and operating systems, and the need for clear processes to prioritise and test patches when active exploitation is confirmed. The pattern also reflects how AI-assisted vulnerability research is accelerating both discovery and exploitation, creating a faster-moving threat landscape.

What to review

Review whether your organisation has a clear process for prioritising patches when CISA or the NCSC confirm active exploitation, and whether browser and operating system updates are deployed quickly enough to close the window of exposure. Consider whether endpoint detection and response tools are configured to detect exploitation attempts and whether security teams have visibility into patch status across the estate. This includes understanding how quickly critical patches can be tested and deployed, whether automated patch management is in place for high-risk systems, and whether there is a clear escalation path for vulnerabilities confirmed as actively exploited. The speed at which these exploits spread across multiple threat groups suggests that organisations need to be able to respond within days, not weeks.

Source: The Register

News and blog posts
Today's brief highlights the practical challenges organisations face when...
The National Cyber Security Centre has published new guidance explaining why...
Security researchers at Proofpoint have identified four separate...
The chief executive of the UK's Medicines and Healthcare products Regulatory...