logo

XML Quadratic Blowup Attack Blows Up WordPress & Drupal

ID: a46eaedd-55d3-5729-b568-06493f00df7b

STIX ID: report--a46eaedd-55d3-5729-b568-06493f00df7b

Feed Name: Darknet

Threat Score
75/100

Date Published: 2014-08-11

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials and session tokens from Chromium- and Gecko-based browsers by using DLL injection and an IElevator COM bypass for App-Bound Encryption (Chrome/Brave/Edge), DPAPI extraction for Opera-family browsers, and NSS decryption for Firefox; it includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and outputs structured JSON for red-team or adversary use, representing a high-risk capability for account takeover and lateral movement on compromised Windows hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.