Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subseque...
On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing sig...
Google's Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in 2025, a rise from 78 in 2024. Less than half of these vulnerabilities were attributed to specific threat actors, with spyware vendors and China being the most prominent. This increase highlights ongoing cybersecurity...
AI models have demonstrated a 73% success rate in exploiting Chrome's V8 JavaScript engine, according to David Brumley. However, the actual goal of hacking is to gain control of the target machine, where leading models achieved zero successful sandbox escapes. Google has reported fixing 1,072 securi...