Tag: chrome
-
Exploit-Kit Bluemoon: Chinesische Hacker bei Angriffen auf Windows-Nutzer erwischt
Ein neues Exploit-Kit nutzt gefährliche Sicherheitslücken in Windows und Google Chrome aus. Mehrere Cybergruppierungen machen davon Gebrauch. First seen on golem.de Jump to article: www.golem.de/news/exploit-kit-bluemoon-chinesische-hacker-bei-angriffen-auf-windows-nutzer-erwischt-2609-212919.html
-
4 Spy Groups Used BlueMoon on Chrome, Windows in One Week
Four spy groups used BlueMoon to chain Chrome and Windows zero-days in one week, showing why fast patching and post-compromise hunting matter. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-bluemoon-chrome-windows-exploit-kit/
-
New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
-
New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
-
New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
-
New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
-
Chinese Hackers Deploy Chrome Zero-Day Exploit Chain
Chinese hackers launch Chrome zero-day exploit chain attacks against NGOs. Learn how this Chrome zero-day exploit chain exploits patch gaps. First seen on securityonline.info Jump to article: securityonline.info/chrome-zero-day-exploit-chain/
-
Chinese Hackers Deploy Chrome Zero-Day Exploit Chain
Chinese hackers launch Chrome zero-day exploit chain attacks against NGOs. Learn how this Chrome zero-day exploit chain exploits patch gaps. First seen on securityonline.info Jump to article: securityonline.info/chrome-zero-day-exploit-chain/
-
Chinese Hackers Deploy Chrome Zero-Day Exploit Chain
Chinese hackers launch Chrome zero-day exploit chain attacks against NGOs. Learn how this Chrome zero-day exploit chain exploits patch gaps. First seen on securityonline.info Jump to article: securityonline.info/chrome-zero-day-exploit-chain/
-
Four groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors. First seen on arstechnica.com Jump to article: arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/
-
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use. Google’s Threat Intelligence Group, Microsoft’s MSTIC, and Volexity all contributed to…
-
China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
Researcher has discovered a rapidly spreading exploit kit called BlueMoon, which combines vulnerabilities in the Chrome browser with a Windows kernel privilege-escalation flaw to compromise targets in espionage campaigns. This activity was first observed on August 28, 2026, and at least four threat clusters have adopted it, most of which are suspected to have ties…
-
4 groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors. First seen on arstechnica.com Jump to article: arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/
-
4 groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors. First seen on arstechnica.com Jump to article: arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/
-
4 groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors. First seen on arstechnica.com Jump to article: arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/
-
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, First seen on thehackernews.com Jump to…
-
Multiple Chinese hacking groups seen using identical Chrome zero-day exploit
A Google Chrome bug identified in August was exploited by at least four China-linked cyber-espionage groups, according to researchers. First seen on therecord.media Jump to article: therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups
-
Chrome is now shipping updates every 2 weeks as AI changes the security landscape
Google is speeding up Chrome’s release schedule to ship security patches and new features faster. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/08/chrome-is-now-shipping-updates-every-2-weeks-as-ai-changes-the-security-landscape/
-
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser.”Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s own Secure Preferences First seen on thehackernews.com…
-
âš¡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.Elsewhere, a trusted software source delivered code that stole…
-
Hackers Can Use PEEP Chrome Extension to Steal Credentials and Execute Shell Commands
A newly identified Chromium-based post-exploitation toolkit named PEEP can turn Google Chrome and Microsoft Edge into persistent remote-access platforms, enabling attackers to steal browser data, hijack sessions, manage files and execute shell commands on compromised endpoints. Unlike a conventional initial-access malware strain, PEEP requires attackers to already possess administrative privileges or code-execution access on a…
-
Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
Google patched CVE-2026-85046, the sixth Chrome zero-day exploited in the wild in 2026. Here’s how to update your browser and stay protected. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-google-chrome-cve-2026-85046-zero-day/
-
Google patches actively exploited Chrome zero-day (CVE-2026-85046)
Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. >>Google is aware that an … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/google-chrome-zero-day-cve-2026-85046/
-
Google warns of new Chrome zero-day flaw exploited in attacks
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/google-warns-of-new-chrome-zero-day-flaw-exploited-in-attacks/
-
Google fixes the sixth actively exploited Chrome zero-day of 2026
Tags: browser, chrome, cve, exploit, flaw, google, remote-code-execution, update, vulnerability, zero-dayGoogle patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8 type confusion flaw. The bug affects Chrome’s JavaScript and WebAssembly engine and could let a…
-
Ein falscher Klick reicht: Schadcode-Attacken auf Chrome-Nutzer beobachtet
Google hat Patches für hochgefährliche Chrome-Lücken veröffentlicht. Eine davon wird bereits aktiv ausgenutzt. Anwender sollten zügig updaten. First seen on golem.de Jump to article: www.golem.de/news/ein-falscher-klick-reicht-schadcode-attacken-auf-chrome-nutzer-beobachtet-2609-212654.html
-
Ein falscher Klick reicht: Schadcode-Attacken auf Chrome-Nutzer beobachtet
Google hat Patches für hochgefährliche Chrome-Lücken veröffentlicht. Eine davon wird bereits aktiv ausgenutzt. Anwender sollten zügig updaten. First seen on golem.de Jump to article: www.golem.de/news/ein-falscher-klick-reicht-schadcode-attacken-auf-chrome-nutzer-beobachtet-2609-212654.html
-
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild.The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome’s JavaScript and WebAssembly engine.”Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a…
-
Google Chrome V8 Flaw Actively Exploited in the Wild, Update Released
Google has released an urgent update for Chrome Stable to address CVE-2026-85046, a high-severity type confusion vulnerability in the V8 JavaScript and WebAssembly engine that is actively being exploited. This flaw can allow remote attackers to execute code within Chrome’s sandbox by convincing a victim to open a specially crafted HTML page. The security update…
-
Google Patches 26 Chrome Vulnerabilities, Including Critical WebGL and Shared Tab Groups Flaws
Google has released a new update for the Chrome Stable Channel on desktop platforms, addressing 26 security vulnerabilities. This includes two critical use-after-free flaws affecting WebGL and Shared Tab Groups. The update upgrades Chrome to version 152.0.7977.75 on Windows and macOS, while Linux users receive version 152.0.7977.76. Google stated that the update will be rolled…

