A nearly identical hacking tool, dubbed BlueMoon by cybersecurity firm Proofpoint, is being actively used by at least four hacking groups, some of which are suspected to have ties to the Chinese government. This exploit kit targets critical security flaws in both Chromium-based browsers—such as Google Chrome and Microsoft Edge—and older versions of the Windows operating system. According to Proofpoint, BlueMoon combines three separate vulnerabilities to allow attackers to install malicious software of their choice on targeted systems. The vulnerabilities include two in the Chromium browser framework and one in the core (kernel) of several Windows versions, including Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the original release of Windows 11. All three vulnerabilities have been patched by developers in the past 24 hours. Despite the availability of patches, the attacks using BlueMoon were not particularly stealthy. In many hacking campaigns, attackers prefer to use newly discovered flaws sparingly to avoid detection and extend the usefulness of the exploit. However, Proofpoint suggests that the widespread and visible use of BlueMoon may have been intentional. One possible reason is to exploit a "patch gap" in the Chromium supply chain—the time between when a security fix is made available by developers and when it is actually implemented in browsers like Chrome and Edge. Another factor that may have contributed to the rapid deployment of BlueMoon is the use of artificial intelligence (AI). AI systems can analyze large amounts of data and detect potential security flaws more quickly than traditional human-led methods. This ability might have allowed the attackers to identify and exploit the vulnerabilities in the Chromium and Windows systems more efficiently than would have been possible otherwise. The discovery of BlueMoon highlights the ongoing challenge of securing software supply chains and the increasing role of AI in both cybersecurity and cyberattacks. As patches are deployed, the focus now shifts to ensuring that users and organizations update their systems promptly to close these security gaps.