Dispatch
Four separate groups were caught running the same Chrome and Windows exploit kit, with AI-assisted bug hunting as a suspected driver
Ars Technica reported on 2026-09-09 that four distinct threat groups were found using an identical Chrome and Windows exploit kit, with a patch gap and the accelerating pace of AI-based vulnerability discovery named as likely contributors. It lands the day after the same outlet covered Microsoft shipping a record 972 patches, 112 of them critical. The pattern to watch is exploit-kit consolidation: when discovery gets cheap, the same working chain shows up across unrelated actors faster than defenders can attribute it.
Source
↳ Follow the thread