BlueMoon Exploit Kit Breaks Out of Chrome to Deploy Espionage Malware
Four espionage groups used a shared Chrome-to-Windows exploit chain. Build checks show current exposure; campaign artifacts support a separate compromise hunt.
Four espionage groups used a shared Chrome-to-Windows exploit chain. Build checks show current exposure; campaign artifacts support a separate compromise hunt.
More than 100 malicious gems used RubyDoc documentation builds to execute supplied code. Maintainers should review package and account changes tied to legacy API keys.
CISA confirms exploitation of CVE-2026-84869. ScreenConnect clients before 26.6.5 can transfer and run files through active sessions without authorization or host confirmation.
An exploited GitLab flaw exposes arbitrary server files through the commits API. Self-managed operators should install 19.1.8, 19.2.6, or 19.3.2 immediately.
CloudSEK found BigBear 2.0 stealing Microsoft 365 session cookies after MFA. Revoke sessions, rotate credentials and require phishing-resistant sign-in.
AOMEI Backupper 8.4.0 exposes physical-disk writes to local users. Without Secure Boot, attackers can plant UEFI code that runs before Windows defenses.
Two certificate-processing flaws reach gateways and management servers. Fixed takes and LivePatch output give operators a direct protection check.
Attackers used Cisco Secure FMC flaws to reach root, steal credentials, tunnel into networks, deploy Cyclops Blink, and encrypt selected endpoints with Qilin.
Kestra OSS versions through 1.3.20 let unauthenticated requests create workflows and run commands as root inside workers. CISA confirms exploitation.
Chrome 153 fixes exploited V8 out-of-bounds write CVE-2026-87491 across desktop and Android. Fleet owners should verify running builds; Google published no attack indicators.
CISA confirmed exploitation of CVE-2025-25249 across FortiOS, FortiSwitchManager and FortiSASE, with federal remediation due September 12.
CISA now links CVE-2025-14733 to ransomware. Patch exposed Fireboxes, check WatchGuard's indicators, and rotate locally stored secrets after confirmed activity.
Customer-managed VPN and AAA appliances need branch-specific fixed builds; configuration determines exposure on later NetScaler releases.