XML Quadratic Blowup Attack Blows Up WordPress & Drupal
ID: a46eaedd-55d3-5729-b568-06493f00df7b
STIX ID: report--a46eaedd-55d3-5729-b568-06493f00df7b
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens from Chromium- and Gecko-based browsers by using DLL injection and an IElevator COM bypass for App-Bound Encryption (Chrome/Brave/Edge), DPAPI extraction for Opera-family browsers, and NSS decryption for Firefox; it includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and outputs structured JSON for red-team or adversary use, representing a high-risk capability for account takeover and lateral movement on compromised Windows hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
