JSCeal Replays Browser Sessions to Steal Fresh Google Tokens
Recovered JSCeal code replays stolen cookies and passwords through a headless browser to obtain fresh Google OAuth tokens and exposes concrete Windows hunt artifacts.
Read article →Reader view
Choose the default article length.
Authentication, access, credentials, and identity systems.
Recovered JSCeal code replays stolen cookies and passwords through a headless browser to obtain fresh Google OAuth tokens and exposes concrete Windows hunt artifacts.
Read article →Zenity saw file-read probes matching CVE-2026-35029. LiteLLM advises upgrading to 1.83.0 or later; defenders should hunt configuration changes and rotate exposed secrets.
Read article →JetBrains confirmed that an unpatched TeamCity flaw exposed Cadence users’ code and secrets. Former users should rotate credentials and review connected systems.
Read article →Five exposed SecFlow workspaces linked Claude, Qwen and DeepSeek to Asian government and education intrusions involving credential theft, webshells, and implants.
Read article →Microsoft observed fake IT support sessions progress from Teams remote control to a persistent JavaScript implant and WinRM movement toward domain controllers.
Read article →A server tied to The Gentlemen exposed TukTuk C2, a credential-stealing prompt, EDR-killer research, exfiltrated Jira data, and healthcare credentials.
Read article →A fail-open agent dashboard exposed one public-model key for three weeks, while noisy usage signals and absent spend limits delayed recognition.
Read article →Socket found 19 browser extensions using automatic updates, rotating command servers and injected modules to steal wallet secrets, sessions and passwords.
Read article →Mandiant traced BREEZE COMET from vishing, rogue branch hardware and stolen cloud credentials to payment APIs used for hundreds of fraudulent transfers.
Read article →An exposed server revealed a repeatable Active Directory attack path, AI-assisted planning, Aurora lockers, and payment trails across multiple victims.
Read article →A new Windows loader arrives through a fake Teams help desk; modules sent to Expel’s emulator phish passwords and tunnel into internal services.
Read article →Two exploited miniOrange SAML flaws can mint WordPress admin sessions. Seven independently versioned editions make ordinary update and vulnerability checks unreliable.
Read article →The browser extension exposed vault tokens to untrusted page messages. Version 3.49.6 adds origin, frame, and nonce checks; later builds supersede it.
Read article →