Jessica Entwistle
September 10 2026
Security researchers at Proofpoint have identified four separate espionage-focused threat groups exploiting the same previously undocumented exploit kit, known as BlueMoon, which chains together vulnerabilities in Google Chrome and Microsoft Windows. The Register reports that the exploit kit was first used by the China-aligned group APT31, with three additional groups deploying the same tooling within a week. The vulnerabilities targeted include CVE-2026-87491, a Chrome V8 out-of-bounds write flaw, and related Windows privilege escalation issues. The speed with which multiple groups adopted the same exploit chain suggests either shared tooling, coordinated activity or rapid reverse-engineering of publicly disclosed vulnerability details. CISA has added the Chrome vulnerability to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild.
This highlights the operational risk created by the gap between vulnerability disclosure and patch deployment. When multiple threat groups exploit the same vulnerability chain within days, the window for defensive action becomes extremely narrow. Chrome and Windows are ubiquitous across UK businesses, making these vulnerabilities relevant to almost every organisation. The coordinated use of the same exploit kit by multiple groups also suggests that once a working exploit becomes available, it spreads quickly across different threat actors. This reinforces the importance of rapid patch deployment, particularly for widely used software such as browsers and operating systems, and the need for clear processes to prioritise and test patches when active exploitation is confirmed. The pattern also reflects how AI-assisted vulnerability research is accelerating both discovery and exploitation, creating a faster-moving threat landscape.
Review whether your organisation has a clear process for prioritising patches when CISA or the NCSC confirm active exploitation, and whether browser and operating system updates are deployed quickly enough to close the window of exposure. Consider whether endpoint detection and response tools are configured to detect exploitation attempts and whether security teams have visibility into patch status across the estate. This includes understanding how quickly critical patches can be tested and deployed, whether automated patch management is in place for high-risk systems, and whether there is a clear escalation path for vulnerabilities confirmed as actively exploited. The speed at which these exploits spread across multiple threat groups suggests that organisations need to be able to respond within days, not weeks.
Source: The Register