Advertisement
Python Infostealer Targeting Browser Credentials and Discord Tokens
Technical analysis of a Python-based infostealer leveraging Discord webhooks for exfiltration, targeting browser credentials and session tokens.
Securing Enterprise Browser Environments Against AI Extension Risks
Discover the security blind spots of AI browser extensions and how to mitigate data exfiltration risks in corporate environments via managed policies.
Google Chrome Zero-Day Patch: Fourth In-the-Wild Exploit
Google has released an urgent security update for Chrome, patching the fourth zero-day vulnerability actively exploited in 2024. Update now to protect against…
DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft
DeepLoad malware leverages ClickFix social engineering and WMI for persistence to steal browser credentials, employing AI-assisted obfuscation for evasion.
Firefox 149 Integrated VPN: Analysis of Privacy and Security Features
Mozilla introduces a built-in VPN in Firefox 149 with a 50GB monthly data cap, enhancing user privacy while creating new visibility challenges for SOC teams.
GlassWorm Malware: Detecting Obfuscated Payloads in Browser Extensions
Technical analysis of GlassWorm (ChromeLoader) evolution, detailing how the malware hides malicious JavaScript within legitimate browser extension dependencies.
Advertisement
Chrome Extensions QuickLens and BuildMelon Hijacked via Ownership Transfer
Attackers are exploiting Chrome extension ownership transfers to weaponize QuickLens and BuildMelon tools for code injection and data harvesting.
Firefox 148 Security Update: Anthropic AI Uncovers 22 Vulnerabilities
Anthropic's Claude Opus 4.6 AI model identified 22 security vulnerabilities in Firefox, including 14 high-severity flaws addressed in the version 148 release.
Enterprise Browser Security: Emerging Blind Spots & AI Web Tool Risks
Keep Aware's 2026 report reveals critical enterprise browser security gaps, citing AI web tool use, phishing, and extensions as major blind spots for defenders.
Google Chrome Two-Week Release Cycle: Reducing the Patch Gap
Google transitions Chrome to a two-week stable release cycle to accelerate security patching and minimize the window for n-day vulnerability exploitation.
CVE-2026-0628: Chrome Gemini Panel Exploit Enables Privilege Escalation
A high-severity flaw in Google Chrome's Gemini side panel allowed malicious extensions to bypass security policies and access local files on target systems.