Researchers disclosed a post-exploitation toolkit called PEEP that turns Chrome and Edge into backdoors for stealing credentials and running commands on the host. After an attacker already has administrative or code-execution access, PEEP's installer injects a malicious extension disguised as a bookmarks tool directly into browser profiles, forging Chromium's own integrity settings to bypass the Web Store and skip user approval prompts. The planted extension then serves as a covert channel to harvest credentials and execute operating-system commands. Because it abuses a trusted, ever-present browser and hides its extension from the usual checks, it can persist quietly on a compromised machine, a reminder that browsers themselves are a rich post-compromise attack surface.
Researchers at CloudSEK gained access to the control panel of BigBear, a phishing-as-a-service platform that defeated multi-factor authentication at 258 organizations and stole thousands of Microsoft 365 credentials. It uses an adversary-in-the-middle proxy based on Evilginx to sit between victims and Microsoft's real login, capturing passwords, multi-factor codes, and the session cookie, then replaying the cookie to hijack the already-authenticated session. The panel logged over 5,000 stolen records across 40-plus countries and is rented to multiple affiliates who receive stolen data through Telegram bots. Notably, it runs JavaScript that disables the browser's passkey support, forcing victims off phishing-resistant login onto weaker methods it can intercept.
Researchers at Check Point analyzed JSCeal, malware compiled into a hard-to-analyze bytecode format that steals browser cookies and authentication tokens to hijack accounts. By replaying stolen session cookies, an attacker can access a victim's Google account without the password or a second factor, and the malware also grabs saved passwords, autofill data, and OAuth tokens to automate further account access. It additionally targets cryptocurrency wallets and platforms and includes keylogging, screenshots, and messaging-session theft. The compiled format and layered obfuscation push it outside analysts' usual tooling, though Check Point released a deobfuscator. It is a reminder that stolen session cookies quietly defeat passwords and multi-factor authentication alike.
Researchers at Elastic documented four persistent programs tied to the REVSTEALER infostealer that stay on a machine even after the stealer deletes itself. One disables Windows Update services and Microsoft Defender, adds Defender exclusions, and kills update and malware-removal tasks before hiding a cryptocurrency miner inside legitimate Windows processes. The malware also bypasses Chrome's app-bound encryption by launching the browser in a debugger to read the decryption key from memory, and steals session cookies to take over accounts without passwords. It spreads through game-cheat lures on hijacked video channels and pirated or fake application installers. Because these modules outlive the stealer, a confirmed infection warrants reimaging rather than cleanup.
Researchers at GitGuardian found that a recent variant of the self-spreading Shai-Hulud npm worm has expanded its credential theft to scan 469 distinct locations on infected developer machines. The targets now span developer environments, continuous integration and deployment tooling, cloud configuration files, and even the configuration of AI tools. That breadth turns a single compromised package into a wide net for secrets, from cloud and registry credentials to keys held by developer and AI tooling. It reflects how supply-chain worms are industrializing secret collection, treating any credential a developer's machine can reach as fair game once malicious code runs during installation or use.
Symantec reported that threat actors are abusing the legitimate, digitally signed Node.js runtime to run malicious JavaScript while slipping past security tools, in attacks on government, technology, and hospitality targets since February. Because the Node.js executable is a trusted developer tool, defenses rarely flag it, so instead of dropping a malicious program the attackers stage the genuine runtime and keep their harmful logic in interpreted scripts. They gain persistence through a Windows registry startup key and, in one case, pulled command-and-control instructions from the blockchain using a technique called EtherHiding. The activity has been tied to a ClickFix social-engineering entry point and an initial-access broker.
Researchers at ANY.RUN documented a phishing campaign spanning 46 countries, with about 45 percent of activity aimed at the United States, that tricks victims into installing legitimate remote monitoring and management software to give attackers persistent access. The lures pose as tax documents, invoices, shipping notices, and government messages, and the operation leans on disposable infrastructure hosted on trusted platforms like Vercel, GitHub Pages, and Netlify, with most hosts appearing for only a single day. Because the specific domains and remote-access tools are interchangeable while the delivery chain stays stable, defenders cannot rely on individual indicators or malware verdicts alone. Remote-management governance is the more durable control.
Group-IB detailed BraZetsu, a modular malware framework that turns compromised Windows machines into products sold to other criminals. It uses generative AI to triage stolen data and flag high-value victims for initial-access brokers, and it collects digital certificates, browser histories from several browsers, and financial files while watching users through screenshots. Compromised hosts feed an underground access-as-a-service marketplace where buyers can pay a small deposit to purchase entry into a victim's system and then run their own follow-on payloads. Some samples were fully undetected by antivirus at the time of analysis. It shows attackers using AI to scale the triage and resale of stolen access.
Researchers at Manifold Security disclosed a class of flaws across several command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs automatically on the developer's machine. The command executes outside the agent's sandbox, with the user's privileges, and without any approval prompt, often before the agent even contacts the model. Simply reviewing or opening a malicious project can run attacker code. It triggers when a repository arrives as files with its hidden Git directory intact, such as through a shared drive, archive, or USB stick, rather than a normal clone. Several tools shipped fixes, but some remained vulnerable at disclosure.
Attackers used a BGP hijack, a manipulation of internet routing, to divert update traffic for Virtualizor, a widely used server and hypervisor management panel, to a server they controlled. During the diversion, which began August 28, they obtained a valid TLS certificate so the connection looked legitimate, then delivered a malicious update that installed persistent root access on affected hosts. One hosting provider found root-level compromise on five of thirty-four hypervisors it checked. Because the software's updates were not cryptographically signed, transport encryption alone did not stop the tampering once routing was hijacked. The vendor released a scanner and patch, but package signing remains unfinished, leaving update integrity dependent on routing security.