Tag: chrome
-
BragJack Attack Hijacks AI Assistants in 5 Popular Browsers With Zero Clicks
Security researchers have revealed a zero-click attack technique known as BragJack, which could enable a malicious browser extension to hijack built-in AI assistants in popular browsers like Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The research, published on September 16 by Gal Weizman of Forever Security, describes a common architectural…
-
BragJack Attack Hijacks AI Assistants in 5 Popular Browsers With Zero Clicks
Security researchers have revealed a zero-click attack technique known as BragJack, which could enable a malicious browser extension to hijack built-in AI assistants in popular browsers like Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The research, published on September 16 by Gal Weizman of Forever Security, describes a common architectural…
-
BragJack attacks hijack AI browser agents through malicious extensions
BragJack, a proof-of-concept attack from Forever Security’s Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/
-
Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities
Google has released Chrome version 153 to the Stable desktop channel, addressing 16 security vulnerabilities, including two critical-severity flaws affecting the Dawn graphics component and WebGL. This update is rolling out as version 153.0.8010.52 for Windows and macOS. Linux users will receive version 153.0.8010.52 over the coming days and weeks. Google Chrome 153 Update Fixes…
-
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People’s Republic of Korea’s (DPRK) Contagious Interview campaign: BeaverTail and First seen on thehackernews.com Jump to…
-
Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service.The extension, named “Twitch Enhanced Viewer | JeetBot,” lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store – Chrome…
-
Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/
-
Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/
-
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension.Once the extension was installed, it could access each product’s built-in AI with a single click.…
-
KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions
A Brazilian banking malware operation, dubbed KREMLIN, that can silently implant malicious extensions in Google Chrome and Microsoft Edge, bypassing Chromium’s built-in integrity protections to steal credentials, cookies, and active banking sessions. Despite its name, the KREMLIN toolkit shows no apparent Russian connection. The campaign relies on Portuguese-language artifacts, lures impersonating 12 Brazilian banks, and…
-
Google Chrome 153 Released With Fixes for 42 Security Vulnerabilities
Google has released Chrome version 153 to the Stable channel for desktop, addressing 42 security vulnerabilities, including three critical-severity flaws affecting WebGL, Chrome internals, and Workers. This update is being rolled out as version 153.0.8010.47/48 for Windows and macOS, and as version 153.0.8010.47 for Linux. The release includes a wide range of memory-safety, authorization, race-condition,…
-
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Tags: banking, browser, chrome, credentials, cybersecurity, finance, google, malicious, malware, threatCybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN.Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google…
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cybercriminals are increasingly turning trusted online platforms into malware delivery channels. Gaming videos, software tutorials, search results, and file-download pages can all be manipulated to make malicious installers appear legitimate. According to Cybersecurity News, hackers abused YouTube gaming channels and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker-2/
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cybercriminals are increasingly turning trusted online platforms into malware delivery channels. Gaming videos, software tutorials, search results, and file-download pages can all be manipulated to make malicious installers appear legitimate. According to Cybersecurity News, hackers abused YouTube gaming channels and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker-2/
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Artificial intelligence is rapidly changing the way software is developed, analyzed, and secured. However, the same capabilities that help developers inspect applications can also be misused by cybercriminals to automate reconnaissance, identify exposed secrets, and accelerate data theft.According to Cybersecurity… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker/
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Artificial intelligence is rapidly changing the way software is developed, analyzed, and secured. However, the same capabilities that help developers inspect applications can also be misused by cybercriminals to automate reconnaissance, identify exposed secrets, and accelerate data theft.According to Cybersecurity… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker/
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Artificial intelligence is rapidly changing the way software is developed, analyzed, and secured. However, the same capabilities that help developers inspect applications can also be misused by cybercriminals to automate reconnaissance, identify exposed secrets, and accelerate data theft.According to Cybersecurity… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker/
-
Researchers Find OAuth Token Exposure in Twitch Extension Used by 30K
Researchers found a Twitch extension used by 30,000 Chrome users transmitting OAuth tokens, potentially exposing authenticated account access. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-twitch-extension-oauth-token-exposure/
-
One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several…
-
12 Best Enterprise Browsers Compared (2026): Features Pricing
Quick Answer: Island and Palo Alto (Talon) lead purpose-built enterprise browsers; Chrome Enterprise (free Core tier) and Edge for Business (bundled) secure the browsers you already run; LayerX and Seraphic add enterprise controls without switching browsers. Note: Mammoth Cyber has ceased operations treat any references as historical. Work happens in the browser now 90%+ of…
-
12 Best Enterprise Browsers Compared (2026): Features Pricing
Quick Answer: Island and Palo Alto (Talon) lead purpose-built enterprise browsers; Chrome Enterprise (free Core tier) and Edge for Business (bundled) secure the browsers you already run; LayerX and Seraphic add enterprise controls without switching browsers. Note: Mammoth Cyber has ceased operations treat any references as historical. Work happens in the browser now 90%+ of…
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
Codeausführung über präparierte Webseiten – Aktiv ausgenutzter V8-Fehler gefährdet Google Chrome
First seen on security-insider.de Jump to article: www.security-insider.de/chrome-v8-sicherheitsluecke-cve-2026-85046-codeausfuehrung-sandbox-a-a632e3a7124d1234b8aa82931becdb78/
-
Twitch extension with 30K installs exposes users’ OAuth tokens
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users’ Twitch OAuth session tokens to a commercial bot service. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/
-
Twitch extension with 30K installs exposes users’ OAuth tokens
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users’ Twitch OAuth session tokens to a commercial bot service. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/
-
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service.The extension, named “Twitch Enhanced Viewer | JeetBot,” lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store – Chrome…
-
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on September 1, 2026, as using identical browser-to-kernel exploit components but ultimately installing separate espionage payloads: the GRIMWEDGE JScript backdoor and the LONGTALE credential-stealing Chrome…
-
Exploit-Kit Bluemoon: Chinesische Hacker attackieren Windows-Nutzer
Ein neues Exploit-Kit nutzt gefährliche Sicherheitslücken in Windows und Google Chrome aus. Mehrere Cybergruppierungen machen davon Gebrauch. First seen on golem.de Jump to article: www.golem.de/news/exploit-kit-bluemoon-chinesische-hacker-bei-angriffen-auf-windows-nutzer-erwischt-2609-212919.html

