Serious Linux/UNIX FTP Flaw Allows Command Execution
ID: ca98adfd-bfba-5e46-ad03-3540d2768be6
STIX ID: report--ca98adfd-bfba-5e46-ad03-3540d2768be6
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials and session artifacts from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It uses headless Chromium + Early Bird APC DLL injection to leverage the IElevator COM interface and bypass App-Bound Encryption for Chromium, retrieves DPAPI or NSS-protected secrets where applicable, and outputs structured JSON; the report covers usage, evasion techniques, an example attack scenario, detection points, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
