Back to Blog

How to protect your business from the new Chrome‑Windows exploit kit

How to protect your business from the new Chrome‑Windows exploit kit
September 10, 2026|David Velarde RoblesDavid Velarde Robles

Why you must protect your business from the BlueMoon exploit kit

A security firm called Proofpoint has identified a new exploit kit—named BlueMoon—that targets the web browsers and Windows operating systems most Dutch small businesses use every day. If a hacker succeeds, they can install any kind of malware, potentially stealing customer data, shutting down online sales, or locking you out of your own systems. The good news: the vulnerabilities it exploits have just been patched, and you can close the gap with three simple actions.

What the BlueMoon exploit kit does

BlueMoon chains together three known flaws:

  1. Two flaws in Chromium‑based browsers (such as Google Chrome and Microsoft Edge).
  2. One flaw in the Windows kernel (the core part of the operating system) that affects Windows 10 (Oct 2018 Update), Windows 11, and recent Windows Server versions.

When a user visits a compromised website, the kit can silently take advantage of those flaws, drop malware onto the computer, and then run it with the same privileges as the user. In plain language, it’s like a thief finding an unlocked back door that most businesses never even knew existed.

Proofpoint says the three vulnerabilities were patched within the last 24 hours. Unfortunately, many small‑business owners miss those patches because they either don’t know they exist or the updates are hidden behind automatic‑update settings that haven’t been turned on.

Why many SMEs miss the patches

  • Automatic updates are often disabled on older machines to avoid unexpected restarts. (Many owners turn them off to avoid unexpected restarts during business hours.)
  • IT responsibilities are spread thin; the owner may be juggling sales, staff, and inventory, leaving little time for software maintenance.
  • Multiple devices (point‑of‑sale terminals, laptops, tablets) can each have their own update schedule, making it easy for one device to fall behind.

Because the exploit kit is already being used by several state‑linked cyber‑espionage groups, every unpatched device is a potential entry point.

Three concrete actions you can take today

1. Apply the latest Windows updates

  • Open Settings → Update & Security → Windows Update.
  • Click Check for updates and install everything that appears, especially any “Security Update” for Windows 10 or Windows 11.
  • Restart the computer when prompted.

If you have multiple Windows PCs, repeat the steps on each one. For servers, the same process applies through the Windows Server Update Services (WSUS) console or the built‑in update tool.

2. Update Chromium‑based browsers

  • In Chrome or Edge, go to Menu → Help → About. The browser will automatically check for the newest version and install it.
  • Ensure the setting “Automatically update Chrome/Edge” is turned on.
  • If you use other Chromium‑based browsers (e.g., Brave, Vivaldi), repeat the same check.

Keeping the browser current removes the two Chromium flaws that BlueMoon relies on.

3. Deploy an endpoint‑protection solution

An endpoint‑protection solution continuously monitors each device for suspicious activity and can block exploit attempts before they succeed. Look for a product that:

  • Offers real‑time scanning for malware and exploit attempts.
  • Provides automatic updates of its detection signatures.
  • Can be managed centrally, so you don’t have to install it manually on every device.

Even a basic, reputable endpoint‑protection tool adds a strong layer of defence against the BlueMoon kit and future threats.

FAQ: How to protect your business – common questions

Q: How do I know if my Windows machine is already up‑to‑date?
A: Open Settings → Update & Security → Windows Update and look for the message “Your device is up to date.” If any updates are listed as “Pending restart,” install them and reboot.

Q: My browser says it’s up to date, but I’m still worried. What else can I check?
A: In Chrome or Edge, type chrome://version/ (or edge://version/) into the address bar. The version number should be the latest released by Google or Microsoft—check the official release notes on their websites to confirm.

Q: Which endpoint‑protection solution should I choose?
A: Look for a solution that is easy to deploy across multiple devices, offers automatic updates, and has a clear reputation for detecting exploit‑based attacks. Many vendors provide a free trial, so you can test it on a single workstation before rolling it out company‑wide.

Stay protected with a “Patch & Protect” audit

A quick “Patch & Protect” audit helps you verify updates and add endpoint‑protection, the fastest way to keep your business safe. At IT Move NL we offer a rapid “Patch & Protect” audit as part of our Security & Protection service. We’ll:

  • Review every Windows update on your network.
  • Verify that all Chromium‑based browsers are running the latest versions.
  • Install and configure an endpoint‑protection solution that fits your business size.

Think of it as a health check for your digital environment—quick, practical, and focused on keeping your business running smoothly. If you’d like us to take a look, just drop us a line or give us a call. We’re here to help you stay safe without the tech‑headache.


Sources:

David Velarde Robles
David Velarde Robles

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent

Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.

>

STAY IN THE LOOP

// Cloud, AI & DevOps insights — straight to your inbox.

>

No spam. Unsubscribe anytime.

Share this article:

Need help with your cloud infrastructure?

Our team of experts is ready to help you navigate the complexities of modern cloud architecture.

Get in Touch