Threat Advisory

New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws

HIGH September 10, 2026

What happened

Multiple cyber-espionage groups have deployed an exploit kit known as “BlueMoon,” which targets zero-day vulnerabilities in Microsoft Windows and Google Chrome. The vulnerabilities exploited are zero-day flaws, meaning they were not publicly known or patched at the time of exploitation. The use of this kit has been confirmed to be actively exploited in the wild, indicating that affected organisations are at imminent risk. The exploit kits take advantage of these zero-day flaws to execute malicious code, potentially allowing attackers to conduct espionage activities or gain unauthorised access to systems without detection.

Who is affected

Organisations running Microsoft Windows and using Google Chrome browsers are affected by this threat. Any deployments that are unpatched or have not mitigated these vulnerabilities are at risk of exploitation. Since both Windows and Chrome are widely adopted, the potential impact spans across many sectors. The exploitation is believed to be targeted, but given the widespread use of affected products, the threat can lead to significant information compromise if exploited successfully.

Recommended actions

  1. Review all security policies surrounding the use of Microsoft Windows and Google Chrome within organisational environments.
  2. Implement network controls to monitor for activity associated with exploit kit behaviour, especially regarding suspicious URL access or abnormal processes indicative of BlueMoon activity.
  3. Apply available security updates and patches for affected software as soon as they become available to eliminate the zero-day vulnerabilities exploited by BlueMoon.
  4. Enhance endpoint security with intrusion detection systems that can flag unusual activity related to exploit kit deployment.
  5. Consider implementing network segmentation to contain malicious activity should exploitation occur, and limit lateral movement of threat actors within organisational networks.

Indicators of compromise

Specific indicators of compromise are not yet available for this threat. Organisations are advised to increased vigilance and monitor security advisories regularly for updates on this exploit kit and associated activity.

Is your organisation exposed?

Argos matches live threat intelligence to your own asset inventory and tells you what actually affects you.

Discover Argos

At a glance

Severityhigh
PublishedSeptember 10, 2026
VendorMicrosoft
ProductsWindows

Get in touch

We respond within 1 hour on weekdays
Exeo Logo White Transparent