🖲️ #Noticia #CiberSeguridad #Cybersecurity #CiberNoticia PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution Leer Más / Read More... Haz clic para acceder al contenido completo.
Security researchers documented a Brazilian banking malware operation called KREMLIN, active since May 2025, that installs malicious Chrome and Edge extensions to steal credentials and session tokens. By September 16, 2026, the malware was using Ethereum smart contracts for command-and-control infrastructure resistant to takedown efforts.
Security researchers and vendors disclosed numerous critical vulnerabilities including zero-day flaws in SonicWall SMA1000 devices, infrastructure flaws tracked in an InfraTrust report, and large-scale malware campaigns using GitHub repositories and DDoS botnets. The Dysphoria botnet has infected approximately 200,000 devices worldwide.
Various unrelated cybersecurity incidents were disclosed including CISA warnings about Check Point authentication vulnerabilities and Rockwell PLC exploits by Iran-linked hackers, Chick-fil-A credential compromise, and a Bluetooth vulnerability affecting 2.2 million vehicles. These represent distinct incidents across different sectors with no unified narrative.
The Chaos ransomware gang is using msaRAT, a Rust-based backdoor, to hide command-and-control communication by routing it through Chrome or Edge browsers to evade detection. Cisco Talos found the malware on a compromised Windows machine before the gang deployed ransomware encryption.
ChonkyChicken Malware Steals Chrome Credentials, Moves Laterally and Spies on Victims ChonkyChicken is a newly identified remote access trojan designed to turn one infected Windows device into a platform for credential theft, network movement, and surveillance. The malware is part of the TAG-195, also called Golden Chickens or Venom Spider, malware-as-a-service ecosystem, which supplies tooling to financially motivated criminal operators.
Hackaday articles cover industrial GPU adaptation, Pico voice controls, and 3D printed stencils. Separate posts report Dolphin X malware stealing from 300+ apps, TriBack espionage malware, and an HTTP/2 vulnerability enabling denial-of-service attacks.
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures.
This cluster contains social media posts sharing links to climate analysis (El Niño), political commentary cartoons, an unrelated CNN article about China's internet, and blog posts—with no unifying story or theme connecting them.
⚪️ KREMLIN Banker Steals Credentials and Session Tokens from Chrome and Edge 🗨️ Researchers at Elastic Security Labs have analyzed the KREMLIN banking malware, which can install malicious extensions for Chrome and Edge on an infected machine without the user’s knowledge.
🤖 PEEP: a Chromium post-compromise toolkit that injects a malicious "bookmarks" extension directly into Chrome/Edge profiles, forging Secure Preferences to bypass Web Store checks and user prompts. Enables persistent host command execution after admin access.
🤖 Volexity: China-linked threat actor UTA0560 used spear-phishing exploiting recently patched Chrome and Windows flaws to deploy the GRIMWEDGE JavaScript backdoor, targeting NGOs on Sep 1.
Proofpoint identified BlueMoon, an exploit kit chaining two Chrome/V8 flaws with a Windows privilege escalation. In use since August 28 by four espionage groups including APT31, it goes from phishing click to sandbox escape and SYSTEM, making patching critical.
Elastic Security Labs researchers Cyril François & Andrew Pease analyse KREMLIN, a malicious browser extension installer from a Brazilian banking malware operation. https://www.
Imagine being a PM trying to make number go up, and pulling this shit thinking "yeah this is what the people want" 🤮 A blog about software craft and quality
Researchers discovered a vulnerability in the Adobe Acrobat Chrome extension (HermeticReader) that allowed access to private WhatsApp conversations without authentication, potentially affecting 329 million users. Adobe has patched the security flaw.
🤖 New JS stealer "WeaselBiscuit" found in 13 npm packages, harvesting Chrome extension storage. Linked to BeaverTail and the DPRK Contagious Interview campaign.
Disparate reports cover Samsung Galaxy S27 camera redesigns (2026-08-25), Anthropic's Claude memory integration (2026-08-25), Bangkok flooding and California ocean phenomena (2026-09-28), and an NRC workforce assessment (2026-09-29). A systemd SSD issue also circulated online (2026-08-27).
On 27–28 August 2026, OpenAI led an open letter signed by nearly 130 organizations—including Anthropic, Microsoft, Google, Amazon, and Cisco—warning of escalating AI-enabled cyberattacks and urging coordinated global cyber defenses. The coalition cautioned that sophisticated AI-powered attacks could proliferate within months without coordinated action.
Between August 19–20, 2026, multiple data breaches were announced on cybercrime forums: CONALEP Morelos (Mexico, 24K+ student records), Hamara (Zimbabwe, 11K+ agricultural users), Quero Namoro (Brazil, 19K users, 5GB backup), Adornis GmbH (source code), and University of Delhi (database advertised for sale). No single coordinated story; these are separate incidents.