State-linked hackers adopt Chrome and Windows zero-day exploit chain
BlueMoon exploit chain includes the recently disclosed CVE-2026-85046 and CVE-2026-87491 in Chrome V8 engine, and CVE-2026-85880 in Windows ALPC.
In brief: Microsoft and Google fix actively exploited zero-days, Anthropic reveals fourth hacking incident, and more.
BlueMoon exploit chain includes the recently disclosed CVE-2026-85046 and CVE-2026-87491 in Chrome V8 engine, and CVE-2026-85880 in Windows ALPC.
The implant appears to be a second-stage payload deployed after attackers exploited a critical RCE flaw affecting F5 BIG-IP systems.
Users are strongly advised to apply the security updates as soon as possible.
Threat actors are increasingly targeting proprietary AI research, models, and related intellectual property.
Researchers used the method to access email data from a victimu2019s connected Gmail account and send the data back to an attacker.
The vulnerability allows attackers to inject PHP code into Magentou2019s template system and execute it without user interaction.