Patching the Gap: The Unsettling Case of BlueMoon The recent takedown of four hacking groups using an identical exploit kit, dubbed BlueMoon by security firm Proofpoint, highlights the ongoing cat and mouse game between cybersecurity researchers and malicious actors.
This exploit kit leveraged three vulnerabilities in both Chromium based browsers and older versions of Windows. All three vulnerabilities have received patches within the past 24 hours.
However, this rapid pace of vulnerability discovery and exploitation has created a "patch gap" – as Proofpoint dubbed it – which refers to the window between when a patch is made available by developers and when it's actually incorporated into browsers like Chrome and Edge.