BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
2026-09-12T13:23:58Z•d9c3c66d7da990e772040615e04a7b497cafe7f189dd229d71b4e4c20f0d0851
CVE-2026-85102CVE-2026-85103AI misuseBlueMoonBrevoCheck PointContiGitLabSIM swappingVPNactive exploitationarbitrary file readdata exposureexploit kitmisconfigurationpath traversalphishingransomwareremote code executionsupply chain compromisezero-day
What happened
SecurityWeek RSS collection covering active exploitation of a critical GitLab path traversal flaw, critical Check Point VPN vulnerabilities enabling potential remote code execution, Chrome and Windows zero-day exploitation via the BlueMoon exploit kit, phishing campaigns following a Brevo compromise, exposed engineering data from a misconfigured Surfshark test server, and other cybersecurity developments.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- d9c3c66d7da990e772040615e04a7b497cafe7f189dd229d71b4e4c20f0d0851
- Enrichment time
- 2026-09-12T13:23:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.