Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
15 / 74 results
highbug_reportVulnerability19 malicious Chrome/Edge extensions steal crypto wallets and credentials
Google Chrome and Microsoft Edge users who installed any of 19 malicious extensions, including "Enable Right Click & Copy" (70,000+ Chrome users, 10,000+ Edge users). Campaign active since early 2024.
highbug_reportVulnerability19 malicious Chrome/Edge extensions drain crypto wallets via auto-updates
19 browser extensions (18 Chrome, 1 Edge) published since February 2024, with "Enable Right Click & Copy — Smart Unlock + OCR" having 80,000 installs. Extensions either created by threat actor or purchased from legitimate owners.
highperson_alertThreat ActorUNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionage
UNC6293, UNC7005, and UNC5976 are three distinct suspected Russian cyber espionage threat clusters conducting persistent account compromise operations. UNC6293 is assessed to be a sub-cluster of Ice Relic (formerly APT29, also tracked as Cozy Bear an…
highbug_reportVulnerability737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxies
Google Chrome Web Store users who installed any of 737 malicious extensions impersonating VPN/proxy services (Proton VPN, NordVPN, Surfshark, ExpressVPN, Cloudflare 1.1.1.1). Approximately 75,000 downloads recorded, primarily Russian users.
highbug_reportVulnerability737 malicious Chrome VPN extensions route traffic through attacker proxies
Google Chrome users who installed any of 737 malicious VPN/proxy extensions from Chrome Web Store, primarily targeting Russian-speaking users. 274 extensions impersonated 66 legitimate VPN brands (Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec,…
highbug_reportVulnerabilityOpenAI, Anthropic, Google reasoning APIs leaked secrets via session replay
OpenAI, Anthropic, and Google reasoning APIs (GPT-5.6 Luna, Claude Haiku 4.5, Gemini Robotics ER-1.6). Affects developers who published raw agent logs containing encrypted reasoning objects.
highbug_reportVulnerabilityCSS attacks bypass webmail sanitizers to steal passwords and tokens
Microsoft Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail webmail interfaces. Attacks exploit CSS and HTML parsing discrepancies to escape message boundaries.
highbug_reportVulnerabilityAWS, Google, Vercel agent flaws allow tool execution without model checks
Amazon Bedrock AgentCore InvokeHarness API (fixed July 31, 2026; CVE-2026-18830, CVSS 8.6), open-source Strands Python library (unpatched resume path remains), Google Agent Development Kit (ADK) for Python <2.5.0 (CVE-2026-18236, CVSS 9.3), Vercel AI…
highbug_reportVulnerabilityGoogle removes ADK workflows after prompt injection exposed CI credentials
Google Agent Development Kit (ADK) Python repository on GitHub. Three workflows removed: issue-analyze.yml, issue-fix.yml, and pr-analyze.yml. Affected repository automation infrastructure, not the distributed ADK Python package itself.
highbug_reportVulnerabilityMalware can hijack Google Password Manager passkeys on Windows via TPM abuse
Google Password Manager synced passkeys on Chrome for Windows with TPM. All three attacks require pre-existing malware on the victim's Windows device. Services that do not properly validate user verification flags (e.g., eBay, now patched) are vulner…
highbug_reportVulnerabilityChrome Password Manager passkey bypass allows malware to hijack accounts
Google Chrome Password Manager on Windows systems with TPM. All three attack paths require malware already running as an ordinary user. Specific affected Chrome versions not disclosed.
highbug_reportVulnerabilityChrome 149–151 fix 1,442 flaws as AI-driven bug discovery outpaces patching
Google Chrome versions 149, 150, and 151 (released June–July 2026). All prior Chrome versions are affected by the resolved vulnerabilities. One critical flaw (CVE-2026-3545, CVSS 9.6) is a 13-year-old sandbox escape in Navigation component, patched i…
highperson_alertThreat ActorChaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsers
Chaos is a ransomware group that operates through spam floods, vishing campaigns, Quick Assist abuse, and RMM tools for initial access and persistence. The group deploys custom tooling including the msaRAT Rust-based implant as a pre-ransomware stage…
highperson_alertThreat ActorChaos ransomware gang deploys msaRAT backdoor via browser hijacking
Chaos is a ransomware gang that emerged in early 2025, distinct from the earlier same-named ransomware family active since 2021. The group has been linked to Iranian state-backed threat actor MuddyWater, who reportedly leveraged Chaos ransomware to d…
highbug_reportVulnerabilityAdobe Acrobat Chrome extension flaw exposed WhatsApp Web chats
Adobe Acrobat extension for Chrome versions 26.5.2.1 and below. Affects approximately 329 million browser installations. Exploitation requires victim to visit attacker-controlled webpage while extension is installed and WhatsApp Web is in use.