< Back to all clusters
[TECHNOLOGY] · 4 sources

started · updated

Cybersecurity threats evolve through AI automation and browser exploits

Cybersecurity researchers have identified a significant shift in threat actor tactics, specifically regarding the exploitation of browser vulnerabilities and the integration of AI into attack lifecycles.

An exploit kit known as ‘BlueMoon’ leverages a patch-gap window to chain three V8 vulnerabilities—CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880—to achieve SYSTEM-level access on Windows systems. This kit was adopted by several espionage-motivated clusters, including TA412 (APT31), which has been linked to Chinese economic espionage. The kit utilizes a malicious extension called GemStone, masquerading as Google Gemini, to perform credential theft and keystroke logging.

Simultaneously, attackers are increasingly adopting multi-agent AI frameworks to automate complex operations. Google’s Threat Intelligence Group reported that attackers have moved beyond simple prompt-based interactions to using AI agents for entire attack lifecycles, including vulnerability scanning and credential harvesting. Anthropic also reported that the Russian threat actor Midnight Blizzard used Claude AI to automate operations targeting military and diplomatic organizations in Ukraine, Europe, and the United States.

Entities

Anthropic · Google · Microsoft · Midnight Blizzard · TA412