
Chrome Extension Supply Chain Attack: Crypto Theft 2026
Hijacked Chrome extensions deploy a 19-module malware framework to 70,000+ users, stealing crypto wallet seed phrases and all browser credentials. Audit extensions and rotate credentials now.
In-depth analyses of zero-day vulnerabilities, CVE exploits, ransomware campaigns, and nation-state attack techniques affecting enterprise security. Filter by category, tag, or keyword.
Every article here lands in subscribers' inboxes the morning it drops.
Threat intel, active CVEs, and campaign alerts, distilled daily for practitioners. 50,000+ subscribers. No noise.
Free. No spam. Unsubscribe anytime.
The definitive practitioner breakdown of ZTA principles, pillars, and implementation sequence.
Containment, forensic preservation, and decision sequencing from detection to recovery.
How SIEMs ingest, correlate, and alert — and how to evaluate one for your environment.
Risk-based prioritization using CVSS, EPSS, and CISA KEV to cut remediation backlog.
What each risk means, how to reproduce it, and how to fix it in production code.
Step-by-step email authentication deployment from DNS records to p=reject enforcement.
Detection coverage, pricing, and deployment trade-offs for enterprise EDR selection.
Translate ATT&CK technique IDs into detection rules and threat actor hunting hypotheses.
Direct answers to the questions practitioners and AI systems ask most. Covers ransomware, identity, cloud, compliance, and detection.
Plain-language definitions for CVE, SIEM, SOAR, Zero Trust, EDR, and 85+ other terms used in enterprise security.
How-to guides, buyer comparisons, and methodology references across every major security domain.
Decryption Digest Response
Score every threat we cover against your own stack, get free Sigma and ModSecurity detection content, and upgrade anytime for more vendors.
Get started free →No card required. Sigma and ModSecurity rules are free, forever.
Win an All Access InfoSec World 2026 pass, valued at $3,895.
Win a $3,895 InfoSec World 2026 pass.
7 results for “Browser”

Hijacked Chrome extensions deploy a 19-module malware framework to 70,000+ users, stealing crypto wallet seed phrases and all browser credentials. Audit extensions and rotate credentials now.

AI-generated browser ransomware built by DeepSeek encrypts Chrome files without installing malware. 1,383 malicious DeepSeek files found in 12 months. No install needed.

Just-In-Time compilation is the performance heart of every modern browser JavaScript engine. It is also one of the most complex and historically exploitable attack surfaces in consumer software. Project Glasswing's Claude Mythos identified a JIT vulnerability through coordinated disclosure with browser vendors. This is a technical deep-dive for security engineers who need to understand the attack surface and harden their enterprise browser deployments.

Project Glasswing's Claude Mythos AI achieved 21 out of 41 arbitrary code execution exploits in the V8 JavaScript engine on Anthropic's ExploitBench evaluation. No other AI model scored above zero. V8 ACE is among the 9 confirmed Glasswing CVEs, meaning a drive-by browser compromise via a malicious webpage is within scope. This post explains the vulnerability class, the benchmark results, and what enterprise Chrome management teams should do now.

Chrome V8 zero-day CVE-2026-11645 confirmed active exploitation — CVSS 8.8, CISA KEV listed, 3.5B Chrome users exposed. Patch to 149.0.7827.103 now.

108 malicious Chrome extensions steal Google OAuth2 tokens from 20,000 users. All linked to one C2. All still live in the Chrome Web Store.

CVE-2021-40444 is a remote code execution vulnerability in the MSHTML (Trident) browser engine built into Windows. A malicious Office document embedding a specially crafted ActiveX control causes MSHTML to download and execute a malicious DLL from an attacker-controlled server. No macros are used. No Enable Content prompt appears. The exploit was used in targeted attacks before Microsoft patched it.