Four Spy Groups Deploy BlueMoon Exploit Kit Targeting Chrome and Windows
Four espionage-linked threat groups use the BlueMoon exploit kit to chain Chrome and Windows vulnerabilities, with initial in-the-wild activity linked to APT31.
Tag
7 results in the archive.
Four espionage-linked threat groups use the BlueMoon exploit kit to chain Chrome and Windows vulnerabilities, with initial in-the-wild activity linked to APT31.
Researchers identify BraZetsu, a Python-based Windows malware that enables Initial Access Brokers to commercialize compromised systems as marketplace inventory.
CISA warns of active exploitation of a critical remote code execution vulnerability in the Windows Internet Key Exchange Service Extensions, enabling attacker code execution without user interaction.
CISA confirms ransomware groups are actively exploiting a high-severity Windows Task Host vulnerability, posing increased risk to enterprise environments.
North Korea's Lazarus Group exploited a recently patched Windows zero-day to deploy a new backdoor targeting defense and aerospace firms as part of Operation Dream Job.
The DOUBLECUP loader uses ClickFix attacks to embed malware within PNG images cached by browsers on Windows and macOS, complicating detection.
CERT-UA has identified a campaign where a fake Notepad++ plugin delivers MATCHBOIL.V2 malware, linked to the Russia-aligned UAC-0099 threat group targeting Windows systems.