Zero-day Vulnerability In TimThumb Image Utility Threatens Many WordPress Sites
ID: d537bd2f-70a8-5d59-bc62-f8b4e29eaf24
STIX ID: report--d537bd2f-70a8-5d59-bc62-f8b4e29eaf24
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts browser-stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, history and bookmarks) from Chrome/Edge/Brave via an App‑Bound Encryption bypass (injecting a DLL into a headless Chromium process and using the IElevator COM interface), from Opera/Opera GX/Vivaldi via DPAPI key retrieval, and from Firefox via NSS decryption; it includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), outputs structured JSON for red-team use, and is distributed as a precompiled Windows executable on GitHub.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
