Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
1+ day, 15+ hour ago (602+ words) Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it…...
The PaperCut Pipeline: How Two Vulnerabilities Became an Automated RCE Factory
16+ hour, 37+ min ago (148+ words) Two PaperCut vulnerabilities are now chained into a fully automated attack pipeline with in-memory persistence—and 47% of installations can't patch. On August 26, security researchers at Huntress identified anomalous activity in customer logs involving base64-encoded commands like whoami and tasklist. This…...
Once in a BlueMoon: How a Chrome Patch-Gap Turned Three V8 Zero-Days Into an Espionage Kit
1+ day, 36+ min ago (65+ words) Three V8 bugs, individually medium-severity, chain into SYSTEM-level access through the patch-gap window. Four espionage clusters adopted the kit within days. The structural shift: browser-based AI agents inherit the same attack surface. Heath Callahan Trust, Identity & Security All stories by Heath…...
BlueMoon Exploit Kit Can Escape Chrome and Elevate Windows Privileges
1+ day, 18+ hour ago (355+ words) Published on September 11, 2026 BlueMoon exploit kit chains Windows and Chrome zero-days in targeted attacks, giving cyber-espionage groups a way to execute code, escape Chrome’s sandbox, and gain elevated Windows privileges. Proofpoint observed attacks involving BlueMoon starting on August 28, 2026, while Volexity…...
Attackers are weaponizing the gap between Chromium fixes and Chrome patches
2+ day, 1+ hour ago (642+ words) A new exploit kit is revealing the perils of the “patch later” mentality. According to the Proofpoint Threat Research team, espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities…...
Microsoft Fixes Nearly 1,000 Vulnerabilities Across Windows, Office, and Azure
2+ day, 11+ hour ago (23+ words) TechPowerUp Automated bot check in progress Drag the handle to the target...
Record September Patch Tuesday: 974 flaws, two exploited
2+ day, 9+ hour ago (302+ words) Microsoft's September Patch Tuesday fixes a record 974 flaws, two already exploited and 20 wormable. What to patch first, and why AI is behind it....
New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
2+ day, 12+ hour ago (118+ words) oodaloop.com Informing your decisions with actionable intelligence Home > Briefs > Cyber > New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender Nightmare Eclipse drops ShieldCrash zero‑day bypassing defender patches. A new exploit called ShieldCrash targets fully patched Windows systems for privilege escalation,…...
AI-powered attack exploited PaperCut flaws to hack 395 organizations
2+ day, 11+ hour ago (523+ words) AdaptHealth confirms 4.1 million people exposed in July cyberattack Over 36,000 exposed Plex servers vulnerable to recent flaws AI-powered attack exploited PaperCut flaws to hack 395 organizations Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers IDScan confirms breach tied to 153 million stolen…...
ShieldCrash Exploit Bypasses Recent Microsoft Defender Patches
2+ day, 13+ hour ago (357+ words) Petri IT Knowledgebase Microsoft Defender Patches Keep Getting Bypassed By New Exploit Variants Each new fix was supposed to close the door on a known attack path, but researchers say another route to the same security boundary may have already…...