Serious XSS Flaw in Google Desktop Allows Data Theft
ID: 016a3a2c-791b-55f6-8087-5d1dfd3abdd5
STIX ID: report--016a3a2c-791b-55f6-8087-5d1dfd3abdd5
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser‑stored credentials and session material from Chrome/Edge/Brave (bypassing App‑Bound Encryption via a headless Chromium process, Early Bird APC DLL injection and the IElevator COM interface), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). The report covers capabilities, operational evasion techniques, output formats, example attack scenarios, detection signals, and mitigations, noting the tool's relevance for red teams and its misuse potential by adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
