Windows Vista & Windows 7 Kernel Bug Can Bypass UAC
ID: a8a3c0b3-4b09-53a0-aa49-6b0aec5b636e
STIX ID: report--a8a3c0b3-4b09-53a0-aa49-6b0aec5b636e
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests credentials and session data from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox). The report describes the tool's architecture—including a DLL injection + IElevator COM-based App‑Bound Encryption bypass for Chromium browsers—what data it extracts (cookies, OAuth refresh tokens, saved logins, credit cards, autofill, history), operational evasion features, an example attack scenario, detection opportunities, and mitigation recommendations, and frames the tool as a red-team utility with realistic implications for cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
