logo

CSRF Vulnerability in Twitter Allows Forced Following

ID: b2704ee5-9941-573b-9961-b65b03b7d530

STIX ID: report--b2704ee5-9941-573b-9961-b65b03b7d530

Feed Name: Darknet

Threat Score
75/100

Date Published: 2008-09-10

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a public post-exploitation tool that harvests browser-stored secrets (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from major Chromium-based and Firefox browsers. It bypasses Chrome's App-Bound Encryption by injecting a DLL into a headless Chromium process using Early Bird APC and the IElevator COM interface to decrypt the app_bound_encrypted_key, supports DPAPI and NSS decryption for other browsers, and includes multiple evasion features to reduce detection by EDRs; the report covers usage, extracted data, detection/mitigation guidance, and red-team applicability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.