logo

Serious WordPress Vulnerability/Exploit Verion 2.0.3 and Below

ID: 0a01d816-1a69-5fe4-8f08-2df60b17067d

STIX ID: report--0a01d816-1a69-5fe4-8f08-2df60b17067d

Feed Name: Darknet

Threat Score
75/100

Date Published: 2006-07-26

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a post‑exploitation browser credential‑harvesting tool from Maldev Academy that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and history from major Chromium‑based and Firefox browsers on Windows. It bypasses Chrome's App‑Bound Encryption by injecting a DLL into a headless Chromium process to call the IElevator COM interface, uses DPAPI/NSS handling where applicable, includes multiple evasion techniques, outputs structured JSON, and is positioned for red‑team/assumed‑breach testing while also being applicable to adversaries seeking rapid SaaS and lateral access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.