daily cyber × ai intelligence

index

tagged

[firefox]

3 editions · 2 items

September 15, 2026

  • “Twitch Enhanced Viewer | JeetBot” exposed live Twitch OAuth tokens to operator-controlled proxies. Socket found that version 85.x placed tokens in an auth query parameter for every watched channel except ten hardcoded Russian-language channels, making them available in proxy logs. Store listings showed roughly 31,000 users across Chrome and Firefox; tokens could reach chat, whispers, and account settings. Both add-ons were still listed on September 14, The Hacker News reports. · Cloud, Identity & Supply Chain

in Scope Questions Recast Anthropic’s “Rogue Agent” Incidents

July 12, 2026

Exploit Chains, Poisoned Packages, and AI Agents Turned Against Their Owners

Android 17 users face a public browser-to-kernel exploit chain combining Firefox JIT RCE (CVE-2026-10702) with kernel exploits for full device compromise. U-Boot firmware has six critical signature-verification flaws affecting 50+ stable releases and embedded devices worldwide, enabling arbitrary code execution and root-of-trust bypass. AI coding agents are now targets: Ghostcommit hides prompt-injection payloads in PNG images to steal environment secrets, while HalluSquatting weaponizes AI model hallucinations to register fake package names and deliver botnets to trusting developers. The jscrambler npm package was compromised with a Rust infostealer that executes on installation across Windows, macOS, and Linux.