Intel Core 2 Duo Vulnerabilities Serious say Theo de Raadt
ID: f44733f0-df77-5b9f-9be8-a88ea638ea21
STIX ID: report--f44733f0-df77-5b9f-9be8-a88ea638ea21
Feed Name: Darknet
DumpBrowserSecrets is a public post‑exploitation credential‑harvesting tool (successor to DumpChromeSecrets) that extracts passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks from Chrome/Edge/Brave (App‑Bound Encryption bypass via headless Chromium + DLL injection and IElevator COM), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS) and writes structured JSON output; it includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), is aimed at red-team/assumed‑breach testing, and represents a high‑impact capability for cloud account takeover and lateral movement from compromised developer endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
