threat-intel 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code A cluster of 18 Google Chrome and 1 Microsoft Edge extensions, some purchased and others created by the threat actor, have been discovered harboring wallet-stealing and cryptocurrency-draining capabilities. The campaign, dubbed ‘Superior’ by Socket, has been active since February 2024 and involves acquiring legitimate… The Hacker News · 2d ago High extensionmalwarewallet
threat-intel CRPx0 hacking service for dummies claims victim count more than quintupled This article reports on a hacking service claiming to have significantly increased its victim count, likely related to exploiting vulnerabilities in software and websites. The service is targeting Joomla websites and pot… The Register · 2d ago Medium vulnerabilityjoomlaextension
AI girlfriend review site's secrets were exposed to the world for three weeks A website reviewing AI girlfriends suffered a three-week security breach, exposing sensitive data. The vulnerability stemmed from a flaw in the website's code, allowing attackers to access user information. This highligh… The Register · 2d ago Medium vulnerabilityweb-securitydata-breach
data-breach Carhartt data breach affects 12.9M, half of what ShinyHunters claimed A data breach affecting Carhartt exposed the personal information of 12.9 million customers, with the attackers claiming a larger initial target size. The breach highlights ongoing risks associated with exploiting vulner… The Register · 4d ago High data breachvulnerabilityextension
vulnerability Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks A vulnerability in Joomla extensions, specifically iCagenda and Balbooa Forms, is being exploited by attackers to compromise websites running on vulnerable CMS platforms. This allows attackers to gain unauthorized access… The Register · 5d ago Medium joomlaextensionvulnerability
threat-intel Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials A campaign of malicious Firefox add-ons, dubbed the "Offside Wallet Theft Factory", has been quietly stealing cryptocurrency wallet seed phrases and browser credentials since March 2026. Researchers identified 40 out of… Graham Cluley · 6d ago High browsercryptomalware
threat-intel Hackers poison popular Rust crates to steal developers' credentials Hackers are exploiting vulnerabilities in popular Rust crates (libraries) to steal developers' credentials. Specifically, flaws in extensions for Joomla websites are being used to gain unauthorized access to developer ac… The Register · Aug 21, 2026 Medium rustjoomlavulnerability
threat-intel 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets A group of 40 malicious Firefox extensions, disguised as Web3 products like OKX and Rabby Wallet, are stealing user wallet secrets. These extensions, part of a larger campaign dubbed ‘Offside Wallet Theft Factory,’ have… The Hacker News · Aug 20, 2026 High firefoxwalletextension
vulnerability AWS key exposed in JavaScript may have lit way to Beacon's charity data A vulnerability in Joomla extensions, specifically iCagenda and Balbooa Forms, has been exploited by attackers to gain unauthorized access to vulnerable websites. This allows attackers to inject malicious code and potent… The Register · Aug 13, 2026 Medium joomlavulnerabilityextension
vulnerability Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible Researchers have discovered that some RISC-V chips are vulnerable to Spectre, a hardware-level security flaw that can be exploited to steal sensitive data. This represents a resurgence of Spectre concerns, highlighting t… The Register · Aug 12, 2026 Medium spectrerisc-vhardware
vulnerability Exposed: Woeful security at UK criminal records office that led to sensitive data leak A security vulnerability in Joomla extensions has been exploited to compromise numerous websites, highlighting a broader issue of security weaknesses within open-source CMS platforms. This incident underscores the ongoin… The Register · Aug 12, 2026 Medium joomlavulnerabilityopen-source
threat-intel Brit rail cops bring live facial recognition to the London Underground A security report highlighted a vulnerability where malicious actors are exploiting extension bugs in Joomla websites, allowing them to launch phishing attacks by impersonating Signal support. This follows a broader tren… The Register · Aug 12, 2026 Medium joomlaphishingvulnerability
threat-intel Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities A Chrome extension, initially banned for stealing AI chat conversations, has returned to the Chrome Web Store and is now targeting enterprise browsers through Google's CDN. The extension employs a sophisticated affiliate… SecurityWeek · Aug 11, 2026 High chromeextensionaffiliate
threat-intel Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials A malicious Microsoft Visual Studio Code extension named Solidity Pro has been identified as a sophisticated information stealer, capable of harvesting a wide range of sensitive data from users’ systems, including crypto… The Hacker News · Aug 10, 2026 High vscodeextensionmalware
threat-intel Researchers replace downloaded macOS apps with evil twins, Apple shrugs Researchers have discovered a method to replace downloaded macOS applications with malicious 'evil twin' versions, while Apple has not responded to the issue. This highlights a significant vulnerability in how users obta… The Register · Jul 23, 2026 Medium IRUSmacosmalwarephishing
vulnerability Millions of California-bought cars can be hijacked via Bluetooth A vulnerability in Joomla extensions, specifically iCagenda and Balbooa Forms, is being exploited to compromise websites running the CMS. Attackers are leveraging these flaws to gain unauthorized access to vulnerable sit… The Register · Jul 23, 2026 Medium joomlavulnerabilityextension
vulnerability Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data A vulnerability in the Adobe Acrobat Chrome extension (HermeticReader, CVE-2026-48294) allows attackers to silently steal WhatsApp Web data by tricking users into visiting a malicious website. The flaw requires only user… The Hacker News · Jul 22, 2026 High CVE-2026-48294chromeextensionwhatsapp
malware Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits A new Windows stealer, dubbed ‘Sneaky,’ is targeting over 300 applications, providing criminals with an AI profiler to maximize profits from stolen data. The malware leverages vulnerabilities in extensions to compromise… The Register · Jul 22, 2026 High malwareextensiondata theft
threat-intel Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads A security vulnerability exists in the Claude for Chrome extension, allowing malicious extensions to trigger unauthorized actions within the user's Gmail, Google Docs, and Calendar accounts. The vulnerability stems from… The Hacker News · Jul 14, 2026 High prompt-injectionextensionvulnerability
vulnerability Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar A security firm, Manifold, discovered that unpatched vulnerabilities in Claude for Chrome allow malicious browser extensions to access sensitive user data, including Gmail messages and calendar information, without expli… SecurityWeek · Jul 14, 2026 High browserchromeai