Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

PEEP toolkit hijacks Chrome and Edge into backdoors that run host commands

Researchers disclosed a post-exploitation toolkit called PEEP that turns Chrome and Edge into backdoors for stealing credentials and running commands on the host. After an attacker already has administrative or code-execution access, PEEP's installer injects a malicious extension disguised as a bookmarks tool directly into browser profiles, forging Chromium's own integrity settings to bypass the Web Store and skip user approval prompts. The planted extension then serves as a covert channel to harvest credentials and execute operating-system commands. Because it abuses a trusted, ever-present browser and hides its extension from the usual checks, it can persist quietly on a compromised machine, a reminder that browsers themselves are a rich post-compromise attack surface.

Check
Hunt for tampering with Chromium's secure preferences file and for extensions loaded outside the Web Store, and treat an unexpected browser extension on a server or admin workstation as a possible backdoor.
Affected
Windows systems an attacker already compromised with admin or code-execution access; PEEP silently installs a browser extension by forging integrity settings, then uses it to steal credentials and run host commands.
Fix
Enforce enterprise extension allowlisting through browser policy, monitor for secure-preferences tampering and unapproved extensions, restrict local administrator rights that enable the install, and include browser artifacts in endpoint detection and incident response.

BigBear phishing service bypassed MFA at 258 organizations and disabled passkeys

Researchers at CloudSEK gained access to the control panel of BigBear, a phishing-as-a-service platform that defeated multi-factor authentication at 258 organizations and stole thousands of Microsoft 365 credentials. It uses an adversary-in-the-middle proxy based on Evilginx to sit between victims and Microsoft's real login, capturing passwords, multi-factor codes, and the session cookie, then replaying the cookie to hijack the already-authenticated session. The panel logged over 5,000 stolen records across 40-plus countries and is rented to multiple affiliates who receive stolen data through Telegram bots. Notably, it runs JavaScript that disables the browser's passkey support, forcing victims off phishing-resistant login onto weaker methods it can intercept.

Check
Enforce phishing-resistant passkeys with conditional access that requires managed devices, so attacker-in-the-middle kits cannot simply capture and replay session cookies or quietly downgrade users to weaker authentication.
Affected
Microsoft 365 organizations relying on passwords plus standard multi-factor authentication; BigBear steals the post-login session cookie to hijack accounts and can disable passkey support in the browser to force weaker login methods.
Fix
Adopt device-bound phishing-resistant authentication, require managed devices through conditional access, revoke sessions and refresh tokens on suspicion, monitor for impossible-travel and residential-proxy sign-ins, and train users on help-desk and login-page lures.

JSCeal malware steals session cookies to log into Google without the password

Researchers at Check Point analyzed JSCeal, malware compiled into a hard-to-analyze bytecode format that steals browser cookies and authentication tokens to hijack accounts. By replaying stolen session cookies, an attacker can access a victim's Google account without the password or a second factor, and the malware also grabs saved passwords, autofill data, and OAuth tokens to automate further account access. It additionally targets cryptocurrency wallets and platforms and includes keylogging, screenshots, and messaging-session theft. The compiled format and layered obfuscation push it outside analysts' usual tooling, though Check Point released a deobfuscator. It is a reminder that stolen session cookies quietly defeat passwords and multi-factor authentication alike.

Check
Treat session cookies as sensitive credentials: monitor endpoints for access to browser cookie databases and suspicious script-to-runtime execution chains, and shorten session lifetimes so stolen cookies expire sooner.
Affected
Users whose browsers are infected by this stealer; theft of session cookies and OAuth tokens lets attackers replay authenticated Google sessions without the password or second factor, and reach crypto accounts.
Fix
Bind sessions to devices where supported, expire and revoke sessions on anomalies, deploy endpoint detection for cookie theft and in-memory browser attacks, and monitor for session replay from unfamiliar locations.

REVSTEALER modules disable Windows Update and Defender to hide a crypto miner

Researchers at Elastic documented four persistent programs tied to the REVSTEALER infostealer that stay on a machine even after the stealer deletes itself. One disables Windows Update services and Microsoft Defender, adds Defender exclusions, and kills update and malware-removal tasks before hiding a cryptocurrency miner inside legitimate Windows processes. The malware also bypasses Chrome's app-bound encryption by launching the browser in a debugger to read the decryption key from memory, and steals session cookies to take over accounts without passwords. It spreads through game-cheat lures on hijacked video channels and pirated or fake application installers. Because these modules outlive the stealer, a confirmed infection warrants reimaging rather than cleanup.

Check
Treat any REVSTEALER or infostealer detection as an incident and reimage the machine, since companion modules persist after the stealer removes itself, and watch for disabled Defender and high CPU usage.
Affected
Windows users who run game cheats or pirated and fake software; the modules disable protection, mine cryptocurrency, bypass Chrome's encryption to steal cookies, and persist after the stealer deletes itself.
Fix
Restrict local administrator rights so malware cannot disable Update and Defender, block game-cheat and pirated-software sources, monitor for security-tool tampering and mining activity, and reimage confirmed infections rather than deleting individual files.

Shai-Hulud npm worm now hunts credentials across 469 different locations

Researchers at GitGuardian found that a recent variant of the self-spreading Shai-Hulud npm worm has expanded its credential theft to scan 469 distinct locations on infected developer machines. The targets now span developer environments, continuous integration and deployment tooling, cloud configuration files, and even the configuration of AI tools. That breadth turns a single compromised package into a wide net for secrets, from cloud and registry credentials to keys held by developer and AI tooling. It reflects how supply-chain worms are industrializing secret collection, treating any credential a developer's machine can reach as fair game once malicious code runs during installation or use.

Check
Scan your dependencies and lockfiles for known-compromised packages, rotate any credentials that a developer machine or pipeline can reach, and reduce the number of long-lived secrets stored in reachable configuration files.
Affected
Developers and CI/CD systems that install compromised npm packages; the worm harvests credentials from 469 locations across developer, pipeline, cloud, and AI-tool configurations, then uses them to spread and steal further secrets.
Fix
Pin and vet dependencies, use scoped short-lived tokens instead of long-lived secrets, isolate build environments, monitor for credential access during installs, and keep secrets out of files developer and AI tools read.

Attackers abuse the trusted Node.js runtime to run malware past defenses

Symantec reported that threat actors are abusing the legitimate, digitally signed Node.js runtime to run malicious JavaScript while slipping past security tools, in attacks on government, technology, and hospitality targets since February. Because the Node.js executable is a trusted developer tool, defenses rarely flag it, so instead of dropping a malicious program the attackers stage the genuine runtime and keep their harmful logic in interpreted scripts. They gain persistence through a Windows registry startup key and, in one case, pulled command-and-control instructions from the blockchain using a technique called EtherHiding. The activity has been tied to a ClickFix social-engineering entry point and an initial-access broker.

Check
Hunt for unexpected Node.js installations on machines that should not run developer tools, suspicious registry startup entries invoking the runtime, and outbound traffic to blockchain endpoints used for command and control.
Affected
Windows environments where a signed Node.js runtime can be introduced and run scripts unnoticed; attackers use it to execute malicious JavaScript, persist through registry keys, and evade tools that trust the binary.
Fix
Apply application control to restrict where the Node.js runtime may run, alert on its use outside development, monitor script execution and registry run-key changes, and block known blockchain command-and-control and ClickFix infrastructure.

Global phishing campaign tricks victims into installing legitimate remote-control software

Researchers at ANY.RUN documented a phishing campaign spanning 46 countries, with about 45 percent of activity aimed at the United States, that tricks victims into installing legitimate remote monitoring and management software to give attackers persistent access. The lures pose as tax documents, invoices, shipping notices, and government messages, and the operation leans on disposable infrastructure hosted on trusted platforms like Vercel, GitHub Pages, and Netlify, with most hosts appearing for only a single day. Because the specific domains and remote-access tools are interchangeable while the delivery chain stays stable, defenders cannot rely on individual indicators or malware verdicts alone. Remote-management governance is the more durable control.

Check
Maintain an inventory and allowlist of approved remote-management tools, block or alert on any others, and warn staff that finance and government-themed messages may push legitimate remote-access software.
Affected
Organizations and users targeted by business-themed phishing that delivers legitimate remote monitoring and management tools; once installed, attackers gain hands-on remote access that looks like ordinary IT activity and evades reputation-based defenses.
Fix
Allowlist approved remote-access software and disable the rest, require remote access through controlled paths like VPNs, monitor for unexpected remote-management execution, and detect on the stable delivery chain rather than disposable domains.

AI-enhanced malware turns hacked Windows machines into marketplace inventory

Group-IB detailed BraZetsu, a modular malware framework that turns compromised Windows machines into products sold to other criminals. It uses generative AI to triage stolen data and flag high-value victims for initial-access brokers, and it collects digital certificates, browser histories from several browsers, and financial files while watching users through screenshots. Compromised hosts feed an underground access-as-a-service marketplace where buyers can pay a small deposit to purchase entry into a victim's system and then run their own follow-on payloads. Some samples were fully undetected by antivirus at the time of analysis. It shows attackers using AI to scale the triage and resale of stolen access.

Check
Treat any infostealer infection as a potential gateway that could be resold, respond by fully rebuilding and rotating credentials, and hunt for stealthy data collection, browser theft, and unauthorized remote access.
Affected
Windows users infected by this framework; it harvests certificates, browser data, and financial files, uses AI to rank victims for brokers, and enrolls the machine into a resale marketplace.
Fix
Strengthen endpoint detection and application control, enforce phishing-resistant authentication so stolen credentials are less useful, monitor for stealthy collection and remote access, and rebuild rather than clean machines suspected of infostealer compromise.

Malicious repository settings can make AI coding agents run attacker commands

Researchers at Manifold Security disclosed a class of flaws across several command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs automatically on the developer's machine. The command executes outside the agent's sandbox, with the user's privileges, and without any approval prompt, often before the agent even contacts the model. Simply reviewing or opening a malicious project can run attacker code. It triggers when a repository arrives as files with its hidden Git directory intact, such as through a shared drive, archive, or USB stick, rather than a normal clone. Several tools shipped fixes, but some remained vulnerable at disclosure.

Check
Update command-line AI coding agents to patched versions, treat opening or reviewing an untrusted repository in an agentic tool as running its code, and prefer plain clones over copied repositories.
Affected
Developers using command-line AI coding agents who open untrusted repositories delivered as files with their Git directory intact; repository settings can execute attacker commands outside the sandbox, without approval.
Fix
Keep agent tools updated, run them against untrusted code in isolated environments, restrict what the agent can reach, avoid opening repositories from shared drives or archives without inspection, and watch startup commands.

BGP hijack poisons a server-panel update to plant persistent root access

Attackers used a BGP hijack, a manipulation of internet routing, to divert update traffic for Virtualizor, a widely used server and hypervisor management panel, to a server they controlled. During the diversion, which began August 28, they obtained a valid TLS certificate so the connection looked legitimate, then delivered a malicious update that installed persistent root access on affected hosts. One hosting provider found root-level compromise on five of thirty-four hypervisors it checked. Because the software's updates were not cryptographically signed, transport encryption alone did not stop the tampering once routing was hijacked. The vendor released a scanner and patch, but package signing remains unfinished, leaving update integrity dependent on routing security.

Check
Run the vendor's scanner on Virtualizor hosts, check for the published indicators like the malicious service and payload file, rotate and IP-restrict API keys, and audit for unknown SSH keys and users.
Affected
Hosting providers and organizations running Virtualizor that pulled updates during the hijack window; a malicious signed-looking update could install persistent root access on hypervisors, exposing every virtual machine they host.
Fix
Scan and remediate affected hosts preserving evidence, rotate credentials and API keys, verify update integrity independently of transport encryption, monitor routing for hijacks of critical vendors, and prefer vendors that sign updates.