Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for BlueMoon exploit kit chaining Chrome and Windows zero-day vulnerabilities used by four espionage groups

Four Spy Groups Chained Chrome and Windows Flaws Into a One-Click Attack

Cybersecurity firm Proofpoint has published research showing that four separate espionage groups — at least three linked to China — deployed the same exploit kit against targets across the US, Southeast Asia and Vietnam in the space of a single week.

The kit, dubbed BlueMoon, chains two Chrome zero-days with a Windows privilege escalation flaw. A target visits a malicious link in Chrome, and the kit does the rest: it escapes Chrome’s sandbox, elevates to SYSTEM on the Windows machine and drops a backdoor. No file downloads, no permission prompts — nothing beyond the initial click.

Why this matters for Australian businesses

This isn’t just a government-and-defence problem. Proofpoint explicitly warns that BlueMoon is “likely to proliferate further and be adopted by financially motivated threat actors.” The pattern is well established: nation-state exploit kits get repackaged for criminal use within weeks.

The three vulnerabilities BlueMoon exploits — CVE-2026-85046 and CVE-2026-87491 in Chrome, and CVE-2026-85880 in Windows — are all now patched. Chrome’s fixes landed on 3 and 8 September. The Windows fix came with Patch Tuesday on 9 September.

Here’s the catch we see repeatedly across our managed client environments: Chrome’s auto-update downloads the patch, but it doesn’t actually apply until the browser restarts. Staff who leave Chrome open for days — and that’s most people — sit in the exact window BlueMoon exploits. If you manage devices, check your fleet’s Chrome version right now. Anything below 153.0.7341.84 is exposed.

What to do

  1. Confirm Chrome is on version 153 or later across all machines. Force a restart policy if you can.
  2. Confirm September Patch Tuesday updates are installed on all Windows endpoints.
  3. Review your endpoint detection for the indicators of compromise Proofpoint published.

If you’re not sure whether your devices are current, get in touch — this is exactly the kind of gap a managed IT service closes for you.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →

Posted in Security