BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

2026-09-12T13:23:58Z•d9c3c66d7da990e772040615e04a7b497cafe7f189dd229d71b4e4c20f0d0851
CVE-2026-85102CVE-2026-85103AI misuseBlueMoonBrevoCheck PointContiGitLabSIM swappingVPNactive exploitationarbitrary file readdata exposureexploit kitmisconfigurationpath traversalphishingransomwareremote code executionsupply chain compromisezero-day

What happened

SecurityWeek RSS collection covering active exploitation of a critical GitLab path traversal flaw, critical Check Point VPN vulnerabilities enabling potential remote code execution, Chrome and Windows zero-day exploitation via the BlueMoon exploit kit, phishing campaigns following a Brevo compromise, exposed engineering data from a misconfigured Surfshark test server, and other cybersecurity developments.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
d9c3c66d7da990e772040615e04a7b497cafe7f189dd229d71b4e4c20f0d0851
Enrichment time
2026-09-12T13:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days · Baitaphish