logo

Zero-day Vulnerability In TimThumb Image Utility Threatens Many WordPress Sites

ID: d537bd2f-70a8-5d59-bc62-f8b4e29eaf24

STIX ID: report--d537bd2f-70a8-5d59-bc62-f8b4e29eaf24

Feed Name: Darknet

Threat Score
75/100

Date Published: 2011-08-03

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts browser-stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, history and bookmarks) from Chrome/Edge/Brave via an App‑Bound Encryption bypass (injecting a DLL into a headless Chromium process and using the IElevator COM interface), from Opera/Opera GX/Vivaldi via DPAPI key retrieval, and from Firefox via NSS decryption; it includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection), outputs structured JSON for red-team use, and is distributed as a precompiled Windows executable on GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.