Adobe Reader Vulnerability Being Actively Exploited
ID: 5065841b-d8d8-5e4f-a0ed-e81534e9d4f3
STIX ID: report--5065841b-d8d8-5e4f-a0ed-e81534e9d4f3
Feed Name: Darknet
**DumpBrowserSecrets** is a post‑exploitation credential‑harvesting tool that extracts saved passwords, cookies, OAuth refresh tokens, credit card data and browsing history from Chromium‑based and Firefox browsers by bypassing App‑Bound Encryption (via DLL injection into a headless Chromium process using the IElevator COM interface) and using DPAPI/NSS methods where applicable; the report covers its technical implementation, supported browsers, evasion features, an attack scenario, and detection and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
