60
Multiple Chinese hacking groups seen using identical Chrome zero-day exploit
Four China-linked espionage groups share identical BlueMoon Chrome zero-day exploit kit targeting US defense contractors and Asian government agencies.
Proofpoint identified at least four Chinese-aligned espionage groups (TA412/RedBravo, UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket) using an identical Chrome zero-day exploit kit dubbed BlueMoon in late August through this week. Targets include US defense contractors, NGOs, mining companies, and Southeast Asian government agencies. The exploit chains a Chromium patch-gap vulnerability with a Windows flaw, delivering malware such as ShadowPad and a fake Gemini browser extension backdoor, with possible AI-assisted exploit development.
85
60
45
Flaw in Philippines’ contact-tracing app served up data on 30K health care providers, research finds
60
60
60
60
50
60
60
60
45
50
60
60
60
60
50
60
60
60
57
60
45
Spies hacked Azerbaijan government officials as Nagorno-Karabakh conflict escalated, researchers say
60
57
60
60
60
60
60
60
60
45
57
60
60
60
60