www.malwarebytes.com 14 Sept 2026, 07:01 UTC

BlueMoon Exploit Kit Targets Newly Fixed Chrome and Windows Flaws

BlueMoon Exploit Kit Targets Newly Fixed Chrome and Windows Flaws

MALWAREBYTES’ weekly round-up for 7–13 September 2026 highlighted several major cybersecurity developments. These included scammers targeting cryptocurrency customers after a breach at an email-marketing provider, Android malware creating hidden copies of banking apps, and the BlueMoon exploit kit using Chrome and Windows vulnerabilities in attacks. The publication said four espionage groups had used the same kit against recently fixed flaws, underscoring the risks of delaying patches.

Other reports covered an actively exploited Chrome vulnerability, Microsoft’s September 2026 Patch Tuesday, and a record 964 fixes, including two exploited zero-days. Malwarebytes also reported MikroTik router flaws that could allow takeover without a password, and LG television vulnerabilities that might let attackers listen in, including while devices were in standby mode. The round-up did not provide the CVE numbers, affected versions, exploitation details or mitigation steps for these issues.

The week’s scam and privacy coverage included a campaign involving more than 100,000 fake online shops designed to steal payment-card details and one-time banking confirmation codes, as well as copyright scams that allegedly caused Instagram accounts to be suspended before demanding payment. It also mentioned a $35 million settlement concerning Grindr’s sharing of HIV-status data and research suggesting some flirtatious OnlyFans promoters on X may use artificial intelligence to appear human.

View full article

Article by CyberSIXT