News · curated 9 Sep 2026

Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days | Proofpoint US

Coverage timeline

discovered proofpoint.com primary 9 Sep 2026theregister.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

BlueMoon's speed of creation and sharing across multiple state-aligned actors is presented as a signal that AI-assisted exploit development is compressing the timeline from patch-gap disclosure to weaponized zero-day chains, changing defenders' patch-window assumptions.

Proofpoint documented BlueMoon, a new exploit kit chaining two Chromium V8 zero-days (CVE-2026-85046 plus a sandbox escape) and a Windows kernel LPE (CVE-2026-85880), used from 28 August 2026 by at least four espionage clusters, most with a suspected China nexus including TA412/APT31. Researchers frame the kit's rapid development and cross-actor proliferation as evidence that AI agents are lowering the cost and barrier to exploit development, a class of capability that was historically rare and high value.