#browser


The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

Oct 2, 2026 // 23:17

Article written by Andrius Buinovskis, VP of product strategy at NordLayer Explore NordLayer Browser in 30 minutes. See how your team can deploy managed browser […]

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Sep 26, 2026 // 21:27

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The […]

⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

Sep 21, 2026 // 17:32

A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things […]

BragJack attacks hijack AI browser agents through malicious extensions

Sep 19, 2026 // 17:57

Security researcher Gal Weizman of Forever Security has disclosed a new attack technique that can hijack the AI assistants built into popular browsers using a […]

Malware bypasses browser checks to force install Chrome, Edge extensions

Sep 16, 2026 // 23:57

A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session […]

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

Sep 14, 2026 // 11:51

A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. […]

Chrome Web Store extensions caught stealing crypto, browser data

Aug 30, 2026 // 17:37

Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, and to […]

Brave browser adds email aliases to help users evade tracking

Aug 29, 2026 // 18:00

The latest version of the Brave browser, 1.94, introduces a feature called ‘Email Aliases’ that allows users to generate disposable email addresses when signing up to […]

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Aug 18, 2026 // 14:52

Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, […]

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

Aug 17, 2026 // 16:26

The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser […]

1 2 3 4 Next