home.social

#browser — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #browser, aggregated by home.social.

fetched live
  1. Hunderte irreführende VPN-Erweiterungen im Chrome Store

    Über 500 betrügerische Browsererweiterungen hat ein Sicherheitsunternehmen im Chrome Web Store gefunden. Google lasse die Herausgeber unbehelligt weitermachen.

    heise.de/news/Hunderte-irrefue

    #Kriminalität #Browser #Chrome #Google #IT #VPN #news

  2. Hunderte irreführende VPN-Erweiterungen im Chrome Store

    Über 500 betrügerische Browsererweiterungen hat ein Sicherheitsunternehmen im Chrome Web Store gefunden. Google lasse die Herausgeber unbehelligt weitermachen.

    heise.de/news/Hunderte-irrefue

    #Kriminalität #Browser #Chrome #Google #IT #VPN #news

  3. AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure

    Indicators extracted from public reporting. Source: jamf.com/blog/amnesia-stealer-

    Pulse ID: 6a7df72c743c82d5d51acf07
    Pulse Link: otx.alienvault.com/pulse/6a7df
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 16:56:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  4. AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure

    Indicators extracted from public reporting. Source: jamf.com/blog/amnesia-stealer-

    Pulse ID: 6a7df72c743c82d5d51acf07
    Pulse Link: otx.alienvault.com/pulse/6a7df
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 16:56:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  5. RE: social.vivaldi.net/@Vivaldi/11

    👋 #DIDiT & #DanmarkSkifter Community

    > #Dugnad is a Norwegian gem of a word and tradition. It's about coming together when a task feels too big to do alone.

    ✅️ Switch your #browser.
    ✅️ Switch your #SearchEngine.
    ✅️ Move your #email.
    ✅️ Change where you store your files. #Cloud

    cc @protonprivacy @DanmarkSkifter @switchingsoftware

    #DutGemacht #2MR #DigitalSovereignty

  6. RE: social.vivaldi.net/@Vivaldi/11

    👋 #DIDiT & #DanmarkSkifter Community

    > #Dugnad is a Norwegian gem of a word and tradition. It's about coming together when a task feels too big to do alone.

    ✅️ Switch your #browser.
    ✅️ Switch your #SearchEngine.
    ✅️ Move your #email.
    ✅️ Change where you store your files. #Cloud

    cc @protonprivacy @DanmarkSkifter @switchingsoftware

    #DutGemacht #2MR #DigitalSovereignty

  7. China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business

    Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.

    Pulse ID: 6a7da6cbe879002fadce7e53
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:13:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault

  8. China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business

    Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.

    Pulse ID: 6a7da6cbe879002fadce7e53
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:13:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault

  9. APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.

    Pulse ID: 6a7daa9c80273555f3d3ccd1
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:29:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault

  10. APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.

    Pulse ID: 6a7daa9c80273555f3d3ccd1
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:29:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault

  11. What are the best #private #browsers in 2026?
    privacytests.org/

    Looks pretty exhaustive, but there are some errors.

    I use @Vivaldi

    PS, duckduckgo is american, and that means it is less safe for #Canadians to use due to things like FISA, the CLOUD act and the NSA.

    #privacy #security #safety #onlinesafety #BrowserSecurity #browser

  12. Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ki

    Pulse ID: 6a7da2b72179e3a4cb0c1d31
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 10:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  13. Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ki

    Pulse ID: 6a7da2b72179e3a4cb0c1d31
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 10:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  14. 🚨🚨 BREAKING: Microsoft Edge to kill uBlock Origin for good 🚨🚨

    Time to switch to #private #browser #alternatives

    Which one do you use? 👇️

    - Firefox
    - LibreWolf
    - DuckDuckGo Browser
    - Tor Browser
    - GNU IceCat
    - Hyphanet
    - Helium

    Recommendation by the Tuta Team:

    tuta.com/blog/best-private-bro

  15. 🚨🚨 BREAKING: Microsoft Edge to kill uBlock Origin for good 🚨🚨

    Time to switch to #private #browser #alternatives

    Which one do you use? 👇️

    - Firefox
    - LibreWolf
    - DuckDuckGo Browser
    - Tor Browser
    - GNU IceCat
    - Hyphanet
    - Helium

    Recommendation by the Tuta Team:

    tuta.com/blog/best-private-bro

  16. wacoca.com/games/1438533/ 「スーパーマリオサンシャイン」,「ニンテンドー ゲームキューブ Nintendo Classics」で配信開始。「Nintendo Music」で楽曲も配信 ##GAMING #Android:NintendoMusic #BROWSER:NintendoMusic #Game #GameNews #games #GamingNews #IPhone:NintendoMusic #NintendoSwitch2:NintendoSwitchOnline #NintendoSwitch:NintendoSwitchOnline #ゲーミング #ゲーム #ゲーム攻略 #ゲーム最新情報 #プラットフォーム:Android #プラットフォーム:BROWSER #プラットフォーム:iPhone #プラットフォーム:NintendoSwitch #プラットフォーム:NintendoSwitch2 #掲載日:2026/08/1314:48 #編集部:やわらぎ #記事種別:ニュース

  17. wacoca.com/games/1438533/ 「スーパーマリオサンシャイン」,「ニンテンドー ゲームキューブ Nintendo Classics」で配信開始。「Nintendo Music」で楽曲も配信 ##GAMING #Android:NintendoMusic #BROWSER:NintendoMusic #Game #GameNews #games #GamingNews #IPhone:NintendoMusic #NintendoSwitch2:NintendoSwitchOnline #NintendoSwitch:NintendoSwitchOnline #ゲーミング #ゲーム #ゲーム攻略 #ゲーム最新情報 #プラットフォーム:Android #プラットフォーム:BROWSER #プラットフォーム:iPhone #プラットフォーム:NintendoSwitch #プラットフォーム:NintendoSwitch2 #掲載日:2026/08/1314:48 #編集部:やわらぎ #記事種別:ニュース

  18. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Pulse ID: 6a7d49a4d0b6cb01b304b5f9
    Pulse Link: otx.alienvault.com/pulse/6a7d4
    Pulse Author: Tr1sa111
    Created: 2026-08-13 04:35:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #InfoSec #OTX #OpenThreatExchange #VPN #bot #Tr1sa111

  19. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Pulse ID: 6a7d49a4d0b6cb01b304b5f9
    Pulse Link: otx.alienvault.com/pulse/6a7d4
    Pulse Author: Tr1sa111
    Created: 2026-08-13 04:35:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #InfoSec #OTX #OpenThreatExchange #VPN #bot #Tr1sa111

  20. wacoca.com/games/1438353/ 重ゲーがダイス要素で遊びやすく。人気ボドゲのダイス版「テラフォーミング・マーズ ダイスゲーム」がボードゲームアリーナで本日実装 ##GAMING #BGA #BoardGameArena #BROWSER:ボードゲームアリーナ #Game #GameNews #games #GamingNews #ゲーミング #ゲーム #ゲーム攻略 #ゲーム最新情報 #ジャンル:カードゲーム #ジャンル:ゲーム集 #ジャンル:テーブルゲーム #プラットフォーム:ANALOG #プラットフォーム:BROWSER #ライター:蒼之スギウラ #掲載日:2026/08/1210:56 #記事種別:ニュース

  21. HTML wirkt auf den ersten Blick simpel. Ein paar Tags, ein bisschen Text, ein paar Links, fertig. Gerade wenn du aus Java kommst, kann HTML schnell wie etwas wirken, das man nebenbei mitnimmt. Keine Klassen, keine Interfaces, keine Exceptions, kein Buildprozess, der erst einmal verstanden ...

    magicmarcy.de/html-meistern-da

    #HTML #Struktur #JavaScript #Coding #Browser #Bedeutung #Formulare #Container #Element #Überschriften #Template #Programming #Webentwicklung

  22. 🪲 Dillo — лёгкий ретро-браузер с 25+-летней историей. Использует собственный движок, который не поддерживает большинство функций современного веба и не исполняет JavaScript. Зато очень шустро работает на слабых устройствах и отображает простые и старые сайты.

    Конфигурация в основном осуществляется через текстовый файл, смотрите документацию. Можно блокировать домены, задать стиль (CSS) для всех страниц. Cookie отключены по умолчанию. Поддерживаются плагины для других протоколов. Отображается счётчик ошибок.

    Официальные сборки Dillo не предоставляются: вы можете найти готовые сборки в репозитории своей операционной системы или самостоятельно собрать из исходного кода. Поддерживаются Linux, macOS, BSD и Windows через Cygwin.

    #browser #retro

  23. 🪲 Dillo — лёгкий ретро-браузер с 25+-летней историей. Использует собственный движок, который не поддерживает большинство функций современного веба и не исполняет JavaScript. Зато очень шустро работает на слабых устройствах и отображает простые и старые сайты.

    Конфигурация в основном осуществляется через текстовый файл, смотрите документацию. Можно блокировать домены, задать стиль (CSS) для всех страниц. Cookie отключены по умолчанию. Поддерживаются плагины для других протоколов. Отображается счётчик ошибок.

    Официальные сборки Dillo не предоставляются: вы можете найти готовые сборки в репозитории своей операционной системы или самостоятельно собрать из исходного кода. Поддерживаются Linux, macOS, BSD и Windows через Cygwin.

    #browser #retro

  24. 𝗠𝗶𝗱𝗼𝗿𝗶:

    #Browser #OpenSource #Midori

    thewhale.cc/posts/midori-7

    Midori is an open source web browser that focuses more on being lightweight than providing you a ton of features.

  25. 𝗠𝗶𝗱𝗼𝗿𝗶:

    #Browser #OpenSource #Midori

    thewhale.cc/posts/midori-7

    Midori is an open source web browser that focuses more on being lightweight than providing you a ton of features.

  26. OpenAI’s #Browser Could Be #Hijacked to #Spam Your #WhatsApp Contacts

    Researchers at #security firm #Zenity found more than a dozen flaws in #AI browsers—and managed to get OpenAI’s Atlas to make an unauthorized Amazon purchase.
    #openai #privacy

    wired.com/story/openais-browse

  27. OpenAI’s #Browser Could Be #Hijacked to #Spam Your #WhatsApp Contacts

    Researchers at #security firm #Zenity found more than a dozen flaws in #AI browsers—and managed to get OpenAI’s Atlas to make an unauthorized Amazon purchase.
    #openai #privacy

    wired.com/story/openais-browse

  28. 737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies

    Indicators extracted from public reporting. Source: socket.dev/blog/chrome-vpn-ext

    Pulse ID: 6a7c7b770ce5c908efa958f2
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 13:56:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Troll #VPN #bot #socks5 #CyberHunter_NL

  29. 737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies

    Indicators extracted from public reporting. Source: socket.dev/blog/chrome-vpn-ext

    Pulse ID: 6a7c7b770ce5c908efa958f2
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 13:56:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Troll #VPN #bot #socks5 #CyberHunter_NL

  30. Oh joy, another *“revolutionary”* #project to liberate us from the oppressive chains of Mathematica—because clearly, what the world has been desperately lacking is a Rust-based #Wolfram #Language #clone 🤖. Now you can enjoy complex mathematical operations in the comfort of your #browser, while still pretending you're doing something groundbreaking! 🚀🔧
    woxi.ad-si.com #revolutionary #Rust #Mathematica #HackerNews #ngated

  31. Oh joy, another *“revolutionary”* #project to liberate us from the oppressive chains of Mathematica—because clearly, what the world has been desperately lacking is a Rust-based #Wolfram #Language #clone 🤖. Now you can enjoy complex mathematical operations in the comfort of your #browser, while still pretending you're doing something groundbreaking! 🚀🔧
    woxi.ad-si.com #revolutionary #Rust #Mathematica #HackerNews #ngated

  32. heise+ | Screenshots und -casts erstellen mit dem Snipping Tool von Windows 11

    Microsofts Screenshot-Werkzeug erstellt nicht nur Bilder, Videos und GIFs, sondern erkennt auch Text und ist erstaunlich flexibel einstellbar.

    heise.de/ratgeber/Screenshots-

    #Browser #Chrome #Firefox #IT #Microsoft #Windows #news

  33. heise+ | Screenshots und -casts erstellen mit dem Snipping Tool von Windows 11

    Microsofts Screenshot-Werkzeug erstellt nicht nur Bilder, Videos und GIFs, sondern erkennt auch Text und ist erstaunlich flexibel einstellbar.

    heise.de/ratgeber/Screenshots-

    #Browser #Chrome #Firefox #IT #Microsoft #Windows #news

  34. StackRender - Database Schema Diagram Editor & SQL Migration Generator links.shikiryu.com/shaare/iLfq MySQLWorkBench mais pour toutes sortes de BDD à relations et dans le navigateur (une petite commande docker et le bouzin est installé)
    #MySQL #sqlite #browser #selfhosted

  35. Sehr begrüßenswert, dass der #Browser #Librewolf vom #AUR ins offizielle #Arch Package Repository gewechselt ist. Damit wurde aber eine Patt-Situation geschaffen. #pikaur kann das Programm nicht mehr updaten, weil es das Ziel nicht mehr gibt und #pacman kann es nicht updaten, weil es das Programm nicht kennt, da es als librewolf-bin installiert wurde.

    Hilft wohl nur eine De- und anschließender Neuinstallation. Und alles neu einrichten? Puh, dann warte ich noch damit.

  36. Sehr begrüßenswert, dass der #Browser #Librewolf vom #AUR ins offizielle #Arch Package Repository gewechselt ist. Damit wurde aber eine Patt-Situation geschaffen. #pikaur kann das Programm nicht mehr updaten, weil es das Ziel nicht mehr gibt und #pacman kann es nicht updaten, weil es das Programm nicht kennt, da es als librewolf-bin installiert wurde.

    Hilft wohl nur eine De- und anschließender Neuinstallation. Und alles neu einrichten? Puh, dann warte ich noch damit.

  37. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  38. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  39. Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack

    The provided document does not contain an intelligence report. Instead, it appears to be a webpage notification indicating that JavaScript needs to be enabled in the browser to proceed with viewing content. The page includes a verification mechanism to confirm that the user is not an automated bot. No threat intelligence information, malicious activity, threat actors, malware campaigns, attack techniques, or cybersecurity-related content is present in the provided material. Therefore, no meaningful analysis of threat activity, targeted countries, industries, or technical indicators can be extracted from this content.

    Pulse ID: 6a7b8b7a783979ea34063bad
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: AlienVault
    Created: 2026-08-11 20:52:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #InfoSec #Java #JavaScript #Malware #OTX #OpenThreatExchange #ZeroDay #bot #AlienVault

  40. Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack

    The provided document does not contain an intelligence report. Instead, it appears to be a webpage notification indicating that JavaScript needs to be enabled in the browser to proceed with viewing content. The page includes a verification mechanism to confirm that the user is not an automated bot. No threat intelligence information, malicious activity, threat actors, malware campaigns, attack techniques, or cybersecurity-related content is present in the provided material. Therefore, no meaningful analysis of threat activity, targeted countries, industries, or technical indicators can be extracted from this content.

    Pulse ID: 6a7b8b7a783979ea34063bad
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: AlienVault
    Created: 2026-08-11 20:52:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #InfoSec #Java #JavaScript #Malware #OTX #OpenThreatExchange #ZeroDay #bot #AlienVault

  41. Fake CCleaner installs GhostDesk Chrome spyware

    A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.

    Pulse ID: 6a7b8dab529ad28b12d29796
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: AlienVault
    Created: 2026-08-11 21:01:31

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #Browser #CCleaner #Chrome #ChromeExtension #CryptoJacking #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #ZIP #bot #AlienVault

  42. Fake CCleaner installs GhostDesk Chrome spyware

    A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.

    Pulse ID: 6a7b8dab529ad28b12d29796
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: AlienVault
    Created: 2026-08-11 21:01:31

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #Browser #CCleaner #Chrome #ChromeExtension #CryptoJacking #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #ZIP #bot #AlienVault

  43. CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials

    A sophisticated credential theft campaign manipulates DNS and HTTP traffic on captive portal networks at hotels, conference centers, and hospitality venues to redirect victims to attacker-controlled infrastructure. The operation harvests Microsoft 365 credentials through phishing pages, device code phishing abusing Microsoft Entra ID authentication flow, and malware delivery via ClickFix social engineering techniques. Evidence indicates compromised shared captive portal services rather than individual venue breaches, with affected gateways identified in several U.S. cities, India, and Saudi Arabia. The campaign deploys two primary malware tools: CornFlake, a Go-based RAT providing persistent access and extensive surveillance capabilities, and ChocoShell, an in-memory PowerShell stealer that harvests browser credentials, Microsoft 365 tokens, and Azure AD tokens. The operation targets travelers across multiple sectors and has expanded to include Android devices through malicious APK files.

    Pulse ID: 6a7bdb051d6a41c7ea440061
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:31:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Azure #Browser #CyberSecurity #DNS #HTTP #Hospital #India #InfoSec #Malware #Microsoft #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SaudiArabia #SocialEngineering #Troll #bot #AlienVault

  44. CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials

    A sophisticated credential theft campaign manipulates DNS and HTTP traffic on captive portal networks at hotels, conference centers, and hospitality venues to redirect victims to attacker-controlled infrastructure. The operation harvests Microsoft 365 credentials through phishing pages, device code phishing abusing Microsoft Entra ID authentication flow, and malware delivery via ClickFix social engineering techniques. Evidence indicates compromised shared captive portal services rather than individual venue breaches, with affected gateways identified in several U.S. cities, India, and Saudi Arabia. The campaign deploys two primary malware tools: CornFlake, a Go-based RAT providing persistent access and extensive surveillance capabilities, and ChocoShell, an in-memory PowerShell stealer that harvests browser credentials, Microsoft 365 tokens, and Azure AD tokens. The operation targets travelers across multiple sectors and has expanded to include Android devices through malicious APK files.

    Pulse ID: 6a7bdb051d6a41c7ea440061
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:31:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Azure #Browser #CyberSecurity #DNS #HTTP #Hospital #India #InfoSec #Malware #Microsoft #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SaudiArabia #SocialEngineering #Troll #bot #AlienVault

  45. Vanadium version 151.0.7922.137.0 released:

    github.com/GrapheneOS/Vanadium

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/41114

    #GrapheneOS #privacy #security #browser

  46. Vanadium version 151.0.7922.137.0 released:

    github.com/GrapheneOS/Vanadium

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/41114

    #GrapheneOS #privacy #security #browser

  47. An Evolution of the Botnet

    A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.

    Pulse ID: 6a7b3ea11dca2e714d4bff8d
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:24:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault

  48. An Evolution of the Botnet

    A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.

    Pulse ID: 6a7b3ea11dca2e714d4bff8d
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:24:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault

  49. How the ErrTraffic Malware Campaign Uses ClickFix and EtherHiding

    WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims...

    Pulse ID: 6a7b3ff969397d537e5d24fa
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:30:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #Chrome #CyberCrime #CyberSecurity #Encryption #EtherHiding #InfoSec #InfoStealer #Malware #MalwareAsAService #OTX #Onion #OpenThreatExchange #RAT #RDP #SocialEngineering #Vidar #Windows #Word #Wordpress #bot #AlienVault

  50. Fake Google Translate Chrome Extension Steals Browser Data and Enables Remote Control

    -Fake Google Translate Chrome extension campaign targets browser users by stealing sensitive data and enabling remote control of Chrome sessions.

    Pulse ID: 6a7b4100873ebae65e20a65c
    Pulse Link: otx.alienvault.com/pulse/6a7b4
    Pulse Author: cryptocti
    Created: 2026-08-11 15:34:24

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #ChromeExtension #CyberSecurity #Google #InfoSec #OTX #OpenThreatExchange #bot #cryptocti