
Attackers are weaponizing the gap between Chromium fixes and Chrome patches
A new exploit kit is revealing the perils of the “patch later” mentality.
According to the Proofpoint Threat Research team, espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities to allow them to launch targeted spear phishing campaigns.
Proofpoint, which researched the new attack method along with Google’s Threat Intelligence Group, Microsoft’s Threat Intelligence Center, and cybersecurity company Volexity, has dubbed it BlueMoon.
“BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals,” Proofpoint noted. It off...