Thirteen npm packages deliver WeaselBiscuit, a JavaScript stealer that harvests Chrome extension storage across Windows, macOS, and Linux.
UTA0560 exploited a Chrome-Windows zero-day chain against NGOs to deploy GRIMWEDGE; APT31 used the same chain to install LONGTALE.
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge ...
A China-linked threat actor has chained multiple software flaws to target non-governmental organizations. Security firm Volexity tracked the campaign under the name UTA0560. It observed the activity ...
Espionage groups have been using BlueMoon, an exploit kit chaining recent Chrome and Windows zero-day vulnerabilities.
Google rolls out a major Chrome update patching 42 security vulnerabilities, including 3 critical flaws. Update your desktop browser now to stay safe.
KREMLIN malware has no link to Russia and targets Brazilian Chrome and Edge users with malicious extensions stealing ...
The post New Malware Can Silently Install Browser Extensions Without Your Permission appeared first on Android Headlines.
Google has pushed out an emergency update for Chrome after confirming that hackers were already exploiting a previously ...
A new type of attack hijacks AI assistants built directly into a browser to access sensitive information, execute malicious ...
AdBlock blocks known crypto miners by default, but c/side found 3,500+ sites running stealth WebSocket miners in 2025. What each extension still misses.
Chrome 153 fixes 16 vulnerabilities across Windows, macOS, and Linux, including two critical Dawn and WebGL flaws.