daily cyber × ai intelligence

index

tagged

[CVE-2026-85880]

2 editions · 2 items

September 10, 2026

  • BlueMoon, a previously undocumented exploit kit, chains a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape, and a Windows kernel LPE (CVE-2026-85880) present only in older Windows builds. Both V8 bugs were "patch-gap" zero-days: the fix for CVE-2026-85046 was committed upstream on 7 August but did not reach stable Chromium until 3 September. First use was TA412 (APT31 / Violet Typhoon) on 28 August against US NGOs, mining companies and commodity trading firms; UNK_LateNight hit US aerospace from 2 September, UNK_DoubleCheck a Vietnamese manufacturer via a compromised Southeast Asian government mailbox, and UNK_QuietRacket government, consulting and financial targets in Indonesia and Singapore from 3 September. Identical orchestration and loading across samples points to one builder; how multiple actors obtained it is unknown (Proofpoint, The Record). · Exploited in the Wild

in One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon

September 9, 2026

  • Microsoft shipped 974 fixes, 113 of them critical — by far the largest Patch Tuesday ever and well ahead of July's previous record. Two Windows privilege-escalation zero-days, CVE-2026-81963 and CVE-2026-85880, are being actively exploited. Also flagged: CVE-2026-69730, an unauthenticated DNS flaw on Windows Server 2012 onward and Windows 10 rated "exploitation more likely", and CVE-2026-69829, a Windows Shell RCE at CVSS 9.8 with no user interaction. Microsoft credits AI-assisted discovery for the volume; SANS counts 973 and notes critical RCEs in Skype for Business, MSMQ and RRAS (Krebs on Security, SANS ISC) (discussion). · Patch Tuesday & Active Exploitation

in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android