daily cyber × ai intelligence

index

tagged

[chrome]

6 editions · 8 items

September 15, 2026

  • “Twitch Enhanced Viewer | JeetBot” exposed live Twitch OAuth tokens to operator-controlled proxies. Socket found that version 85.x placed tokens in an auth query parameter for every watched channel except ten hardcoded Russian-language channels, making them available in proxy logs. Store listings showed roughly 31,000 users across Chrome and Firefox; tokens could reach chat, whispers, and account settings. Both add-ons were still listed on September 14, The Hacker News reports. · Cloud, Identity & Supply Chain

in Scope Questions Recast Anthropic’s “Rogue Agent” Incidents

September 10, 2026

  • BlueMoon, a previously undocumented exploit kit, chains a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape, and a Windows kernel LPE (CVE-2026-85880) present only in older Windows builds. Both V8 bugs were "patch-gap" zero-days: the fix for CVE-2026-85046 was committed upstream on 7 August but did not reach stable Chromium until 3 September. First use was TA412 (APT31 / Violet Typhoon) on 28 August against US NGOs, mining companies and commodity trading firms; UNK_LateNight hit US aerospace from 2 September, UNK_DoubleCheck a Vietnamese manufacturer via a compromised Southeast Asian government mailbox, and UNK_QuietRacket government, consulting and financial targets in Indonesia and Singapore from 3 September. Identical orchestration and loading across samples points to one builder; how multiple actors obtained it is unknown (Proofpoint, The Record). · Exploited in the Wild
  • Chrome shipped 230 fixes on Tuesday including CVE-2026-87491, an out-of-bounds write in V8 under active exploitation — the seventh exploited Chrome zero-day this year, and distinct from the BlueMoon CVEs (BleepingComputer, The Hacker News). · Exploited in the Wild
  • Fortinet patched an unauthenticated authentication bypass in FortiMonitorOnSight plus a flaw in the Privileged Access Agent browser extension where any visited site could reconfigure the agent's proxy and observe the user's tab (SecurityWeek, research write-up). · Exploited in the Wild

in One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon

September 8, 2026

  • PEEP is a Chromium-based post-exploitation toolkit posing as a "Smart Bookmarks" extension. Given prior admin or code execution, its installer injects the extension straight into Chrome/Edge profiles and forges Chromium's own Secure Preferences integrity values to bypass Web Store checks and user prompts; a native-messaging component takes it beyond browser telemetry into host command execution and file management (SOCRadar, The Hacker News). · Threat Activity

in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited

July 24, 2026

  • msaRAT, a new Rust backdoor from the Chaos ransomware crew, tunnels C2 through headless Chrome/Edge and WebRTC. Cisco Talos found it abusing the Chrome DevTools Protocol and WebRTC DataChannels, ChaCha20-Poly1305-encrypting payloads, and hiding behind Twilio TURN and Cloudflare Workers to blend into legitimate traffic. Talos, BleepingComputer. · Threat Activity

in The Week AI Agents Started Doing the Hacking