daily cyber × ai intelligence

index

tagged

[CVE-2026-85046]

3 editions · 2 items

September 10, 2026

  • BlueMoon, a previously undocumented exploit kit, chains a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape, and a Windows kernel LPE (CVE-2026-85880) present only in older Windows builds. Both V8 bugs were "patch-gap" zero-days: the fix for CVE-2026-85046 was committed upstream on 7 August but did not reach stable Chromium until 3 September. First use was TA412 (APT31 / Violet Typhoon) on 28 August against US NGOs, mining companies and commodity trading firms; UNK_LateNight hit US aerospace from 2 September, UNK_DoubleCheck a Vietnamese manufacturer via a compromised Southeast Asian government mailbox, and UNK_QuietRacket government, consulting and financial targets in Indonesia and Singapore from 3 September. Identical orchestration and loading across samples points to one builder; how multiple actors obtained it is unknown (Proofpoint, The Record). · Exploited in the Wild

in One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon

September 7, 2026

The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart

MikroTik RouterOS underwent a silent patch for SSH authentication bypass and RSA signature forgery bugs (CVE-2026-67276) with active exploitation since at least 2 September, and researchers reverse-engineered the fix with PoC code in six hours. Adobe Magento/Commerce hosts an unpatched zero-day RCE (StyleSmuggler) that gained a second Rust backdoor variant masquerading as fontconfig tools and beaconing to a fixed C2 address. JetBrains disclosed that attackers exploited CVE-2026-63077 in its own TeamCity server to breach Cadence infrastructure and steal source code, credentials, and user data dating to 8 August. Kimsuky's Operation GitPower now uses the OpenCode AI agent to mass-produce financial-themed decoys with anti-analysis evasion and GitHub/Pastebin C2 channels.