PEEP is described as a post-compromise framework as it lacks an initial access vector itself, meaning it requires the ...
UTA0560 exploited a Chrome-Windows zero-day chain against NGOs to deploy GRIMWEDGE; APT31 used the same chain to install LONGTALE.
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in ...
Chrome zero-day CVE-2026-85046 is under active attack as the sixth actively exploited Chrome vulnerability of 2026. A type confusion flaw in Chrome's V8 JavaScript engine lets attackers run code ...
Crooks are deploying cheeky browser-in-the-browser techniques to trick victims into downloading RMM tools.
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension ...
Elastic Security Labs has uncovered a long-running malware operation that plants fake browser extensions inside Chrome and ...
A malicious installer disguised as the Exodus cryptocurrency wallet is being used to deploy a modular remote-access trojan ...
Attackers persuade employees to accept a remote-control request during screen sharing or to open Quick Assist and provide its ...
A Telegram Desktop flaw lets bots inject JavaScript into exported chats, enabling data theft and page manipulation.
Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote ...
KREMLIN banking malware uses fake bank documents to steal passwords, cookies, and data from Chrome and Edge users in Brazil.