[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-four-hacking-groups-used-the-same-chrome-exploit-kit-in-a-week":10,"sections":49},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":38,"tags":39,"sources":44,"feedback":48,"feedback_at":22,"cost_usd":48,"total_tokens":48},6262,"four-hacking-groups-used-the-same-chrome-exploit-kit-in-a-week","Four Hacking Groups Used the Same Chrome Exploit Kit in a Week","Proofpoint says a tight Chrome patch window let four separate groups reuse one exploit kit within days, and floats AI-aided bug-hunting as a factor.","Four unrelated hacking groups, including a China-aligned unit, used the exact same Chrome exploit kit against different targets within a single week.\n\nProofpoint calls the kit BlueMoon. It chains two Chromium flaws in the V8 JavaScript engine (a type confusion bug, CVE-2026-85046, severity 8.8, and an unscored sandbox escape) with a Windows heap overflow, CVE-2026-85880, severity 7.8, that lets code already running in a low-privilege AppContainer jump to SYSTEM. TA412, also tracked as Violet Typhoon, used it first, on August 28, against US NGOs, mining firms, and commodity traders. Within days, three more groups followed: UNK_LateNight against US aerospace companies, UNK_DoubleCheck against a Vietnamese manufacturer, and UNK_QuietRacket across Singapore and Indonesia. All three bugs are now patched, and Proofpoint says they were patch-gap zero-days, already fixed in Chromium's public source but not yet rolled out to Chrome, Edge, or Brave users.\n\nThe real story here isn't the exploits, it's the noise. Four groups burning the same rare, fully weaponized browser chain within a week, each loudly enough to get caught, is unusual: stealth normally buys more mileage from a zero-day. Proofpoint's read is that the patch-gap window itself has become a shared resource, since anyone can reverse-engineer Google's public fix before it reaches actual browsers, leaving no reason to wait quietly. The firm also floats, more cautiously, that AI-assisted bug-hunting may be lowering the cost of turning a patch into a working exploit, though it stops short of calling that the cause.\n\nA fully weaponized Chrome exploit chain used to be a rare, expensive thing state actors hoarded and guarded closely. Four groups grabbing the same one in the same week suggests that scarcity is eroding, patch cadence or not.","[\"chrome\",\"exploit-kit\",\"proofpoint\",\"zero-day\"]","2026-09-10T15:10:00.000Z","2026-09-10T16:39:01.555Z","2026-09-10T16:39:13.448Z","published",null,[24,30,34],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"The dek states that AI-assisted exploit development 'let' the four groups weaponize the kit as settled causation, but Proofpoint only floats AI as a possible factor ('may reflect a reduced cost and barrier to entry') and the body itself hedges with 'Proofpoint suggests' — rewrite the dek to match that hedged framing so it doesn't overstate the source or contradict the body.","resolved",{"id":31,"reviewer":26,"round":32,"reason":33,"status":29},"editor-r2",2,"Add the specific CVE IDs and severity scores for the two Chromium flaws and the Windows ALPC bug (CVE-2026-85046\u002F8.8, unassigned sandbox-escape, CVE-2026-85880\u002F7.8) and name the affected Windows versions from the source, since the draft treats these vulnerabilities as established facts without the identifying details needed to verify them.",{"id":35,"reviewer":26,"round":36,"reason":37,"status":29},"editor-r3",3,"The dek states AI-assisted flaw hunting as 'the cause,' but the body (correctly, per the source) frames it as a secondary theory Proofpoint only 'floats' alongside the patch-gap explanation — rewrite the dek so it doesn't outrun the body's hedged framing.","security",[40,41,42,43],"chrome","exploit-kit","proofpoint","zero-day",[45],{"name":46,"url":47},"TechRadar","https:\u002F\u002Fwww.techradar.com\u002Fpro\u002Fsecurity\u002Fmultiple-hacking-groups-found-using-the-same-chrome-malware-in-the-same-week-so-what-does-it-mean",0,{"sections":50},[51,56,59,64,69,74,79,83,88,93,98,103,108,113],{"name":52,"slug":53,"count":54,"latest_published_at":55},"AI","ai",3480,"2026-09-11T04:00:00.000Z",{"name":57,"slug":38,"count":58,"latest_published_at":55},"Security",628,{"name":60,"slug":61,"count":62,"latest_published_at":63},"Policy","policy",336,"2026-09-11T00:56:21.000Z",{"name":65,"slug":66,"count":67,"latest_published_at":68},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":70,"slug":71,"count":72,"latest_published_at":73},"Hardware","hardware",153,"2026-09-09T15:12:32.000Z",{"name":75,"slug":76,"count":77,"latest_published_at":78},"Consumer Tech","consumer-tech",99,"2026-09-09T17:27:33.000Z",{"name":80,"slug":81,"count":82,"latest_published_at":55},"Science","science",98,{"name":84,"slug":85,"count":86,"latest_published_at":87},"Software","software",75,"2026-09-10T20:41:21.000Z",{"name":89,"slug":90,"count":91,"latest_published_at":92},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":94,"slug":95,"count":96,"latest_published_at":97},"Startups","startups",55,"2026-09-09T23:14:29.000Z",{"name":99,"slug":100,"count":101,"latest_published_at":102},"Gaming","gaming",43,"2026-09-10T12:18:06.000Z",{"name":104,"slug":105,"count":106,"latest_published_at":107},"General","general",41,"2026-09-08T01:57:23.000Z",{"name":109,"slug":110,"count":111,"latest_published_at":112},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":114,"slug":115,"count":116,"latest_published_at":117},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]