Skip to content

Enterprise software, read for what it costs and who signs for it.

Security

Google patched two Chrome flaws. Four spy groups already used them.

SecurityWeek reports that Proofpoint found an exploit kit called BlueMoon chaining two Google Chrome vulnerabilities with an Microsoft Windows privilege-escalation flaw.

ERP LEADERS news desk · · First reported by SecurityWeek · Edition no. 7

The Chrome bugs, CVE-2026-85046 and CVE-2026-87491, sit in the V8 JavaScript and WebAssembly engine. They were patched on 3 September and 8 September. The Windows bug, CVE-2026-85880, is an ALPC privilege escalation fixed in the September 2026 Patch Tuesday.

Proofpoint says Violet Typhoon, also tracked as APT31, first deployed BlueMoon on 28 August against US non-governmental organisations. Mining companies and commodity traders were also targeted.

UNK_LateNight targeted US aerospace companies on 2 September. UNK_DoubleCheck targeted a Vietnamese manufacturing organisation. On 3 September, UNK_QuietRacket targeted financial organisations. Government and consulting organisations in Indonesia and Singapore were also targeted.

Proofpoint says: "It is currently unknown how multiple distinct threat actors obtained access to the exploit kit." The firm adds that artefacts suggest its creators might have used AI, though none confirms it.

How long after a browser patch does your fleet actually restart?

Sources

Spotted an error? Tell us. Every correction is logged on Standards.

Your reading room

Companies in this story

Our file on Google

  1. 21 SeptFiled later

    Google's Gemini got into three real companies during a safety test.

  2. 20 SeptFiled later

    OpenAI's agent platform was installed at 75 firms. 69% made it their main one.

  3. 17 SeptFiled later

    CISA says attackers are exploiting a zero-click Google Pixel flaw. Agencies got three days.

  4. 15 SeptFiled later

    Google banned outside AI coding tools. Its engineers may now use Anthropic's Claude.

  5. 11 Sept

    Google bought up to half a nuclear plant's output until 2049.

All 6 Google stories

For your next steering committee

Questions for your own programme. They are not findings about any company in this story.

  1. 1Ask when systems of this kind in your landscape were last patched, and who confirms it.
  2. 2Ask which finance and ERP accounts can be reached from outside, and how each sign-in is protected.
  3. 3Ask how long a restore took the last time it was tested.

Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01

Founding reader view is on in this browser. It is a reading view, not secure access. Print the working sheet

Founding reader

Welcome back. · Issue 01

1 comment under this story on LinkedIn. Read the discussion

Keep reading

The ERP LEADERS brief Get issue 01