Superior: 19 Browser Extensions Steal Wallets and Passwords
The Superior campaign weaponized 19 Chrome and Edge extensions to steal crypto, passwords, sessions, and form data. Check the list and recovery steps.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
October 4, 2026
The Superior campaign weaponized 19 Chrome and Edge extensions to steal crypto, passwords, sessions, and form data. Check the list and recovery steps.
The validated Carhartt breach contains 12.9 million accounts with names, emails, phone numbers, and addresses, but no listed passwords.
Microsoft says TerminalFix uses a fake CAPTCHA, PowerShell, DLL sideloading, and a reverse tunnel. Check these artifacts if the command ran.
The FBI and DOJ disabled QTFY’s QScan and QTRouter platforms. Compromised routers and IoT devices hid attacks on critical infrastructure.
Klever-Go flaws CVE-2026-54754 and CVE-2026-54755 could create unbacked KLV. One was exploited in June; version 1.7.19 fixes both.
WatchGuard fixed four critical Firebox RCE flaws in Fireware 2026.2.2, 12.12.2 and 12.5.20. Check exposure, update, and review device evidence.
CVE-2026-53362 is now in CISA KEV after active exploitation. Learn which Linux container hosts are exposed, how to patch, and what evidence to review.
OpenAI banned accounts very likely operated from Russia that promoted a fake think tank with copied research and AI-generated social posts.
CISA says CVE-2026-8452 is actively exploited. Check affected Citrix NetScaler builds, SAML exposure, patch versions, and compromise indicators.