September 15, 2026
- “Twitch Enhanced Viewer | JeetBot” exposed live Twitch OAuth tokens to operator-controlled proxies. Socket found that version 85.x placed tokens in an
auth query parameter for every watched channel except ten hardcoded Russian-language channels, making them available in proxy logs. Store listings showed roughly 31,000 users across Chrome and Firefox; tokens could reach chat, whispers, and account settings. Both add-ons were still listed on September 14, The Hacker News reports.
· Cloud, Identity & Supply Chain
in Scope Questions Recast Anthropic’s “Rogue Agent” Incidents
September 10, 2026
- BlueMoon, a previously undocumented exploit kit, chains a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape, and a Windows kernel LPE (CVE-2026-85880) present only in older Windows builds. Both V8 bugs were "patch-gap" zero-days: the fix for CVE-2026-85046 was committed upstream on 7 August but did not reach stable Chromium until 3 September. First use was TA412 (APT31 / Violet Typhoon) on 28 August against US NGOs, mining companies and commodity trading firms; UNK_LateNight hit US aerospace from 2 September, UNK_DoubleCheck a Vietnamese manufacturer via a compromised Southeast Asian government mailbox, and UNK_QuietRacket government, consulting and financial targets in Indonesia and Singapore from 3 September. Identical orchestration and loading across samples points to one builder; how multiple actors obtained it is unknown (Proofpoint, The Record).
· Exploited in the Wild
- Chrome shipped 230 fixes on Tuesday including CVE-2026-87491, an out-of-bounds write in V8 under active exploitation — the seventh exploited Chrome zero-day this year, and distinct from the BlueMoon CVEs (BleepingComputer, The Hacker News).
· Exploited in the Wild
- Fortinet patched an unauthenticated authentication bypass in FortiMonitorOnSight plus a flaw in the Privileged Access Agent browser extension where any visited site could reconfigure the agent's proxy and observe the user's tab (SecurityWeek, research write-up).
· Exploited in the Wild
in One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon
September 8, 2026
- PEEP is a Chromium-based post-exploitation toolkit posing as a "Smart Bookmarks" extension. Given prior admin or code execution, its installer injects the extension straight into Chrome/Edge profiles and forges Chromium's own Secure Preferences integrity values to bypass Web Store checks and user prompts; a native-messaging component takes it beyond browser telemetry into host command execution and file management (SOCRadar, The Hacker News).
· Threat Activity
in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited
August 29, 2026
- 18 Chrome and one Edge extension published over the past six months shipped wallet-secret theft and crypto-draining code, sharing enough code and tradecraft to indicate a single cluster, per Socket (The Hacker News).
· Threat Activity
in PaperCut Ships a Second Emergency Patch After Researchers Bypass the First
August 22, 2026
- Kimsuky is installing a malicious Chrome extension that auto-exfiltrates victims' Gmail to C2 in spear-phishing against South Korean and Japanese targets, alongside abuse of legitimate remote-control tooling. Korean-language comments and debug strings throughout the extension's JavaScript suggest most of it was written with generative AI (ENKI).
· Threat Activity
in A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight
July 24, 2026
- msaRAT, a new Rust backdoor from the Chaos ransomware crew, tunnels C2 through headless Chrome/Edge and WebRTC. Cisco Talos found it abusing the Chrome DevTools Protocol and WebRTC DataChannels, ChaCha20-Poly1305-encrypting payloads, and hiding behind Twilio TURN and Cloudflare Workers to blend into legitimate traffic. Talos, BleepingComputer.
· Threat Activity
in The Week AI Agents Started Doing the Hacking