Skip to content
Threat Feed

Product

Microsoft Edge

9 briefs RSS
high advisory

Entra ID PRT Extraction via BrowserCore.exe Abuse

Adversaries are abusing the legitimate BrowserCore.exe component to perform unauthorized extraction of Entra ID Primary Refresh Tokens (PRTs) by invoking the binary outside of expected browser-managed contexts.

Microsoft Edge +1 credential-access browser-security windows session-hijacking
1r 2t
critical threat

Active Exploitation of Google Chromium V8 Type Confusion Vulnerability

A type confusion vulnerability in the Google Chromium V8 engine is being actively exploited in the wild, allowing remote attackers to achieve arbitrary code execution within the sandbox environment via crafted HTML pages.

exploited Chromium V8 +8 vulnerability chromium browser-security
1t 2c updated
high threat

Astaroth Botnet Deploys New WhatsApp Web Spambot Component

Operators of the Astaroth (aka Guildma) botnet, which targets Brazil-based users, introduced a new spambot component in Q4 2025 that leverages WhatsApp Web in headless browser mode for malware distribution, exhibiting evasion techniques like payload encryption and WebDriver automation indicator stripping.

Windows +5 Astaroth botnet malware spambot latin-america
1r 9t 8i updated
high threat

Suspicious File Download via Headless Browser

The DUCKTAIL threat actor leverages Chromium-based web browsers (such as Microsoft Edge and Chrome) running in headless mode with the `--dump-dom` argument to stealthily download malicious content from the internet via suspicious file-sharing domains, impacting compromised endpoints.

Brave Browser +4 DUCKTAIL headless-browser file-download data-exfiltration malware-delivery endpoint network
1r 2t 26i
high advisory

ClickFix Campaign Activity

Tracking brief for the ClickFix campaign; individual sightings are folded in as reported.

open source packages +49 campaign clickfix
29i updated
high advisory

Apple Security Updates — July 2026

Roundup of Apple security advisories published in July 2026.

PoC macOS LaunchAgents +46 roundup
4c 10i updated
high advisory

Google Security Updates — July 2026

Roundup of Google security advisories published in July 2026.

golang.org/x/crypto/ssh +74 roundup
5c 41i updated
high advisory

Windows Defender Phishing Filter Override via Registry Modification

The analytic detects modifications to the Windows registry that disable the Windows Defender phishing filter, potentially allowing attackers to deceive users into visiting malicious websites without browser warnings.

Microsoft Edge +3 defense-evasion windows registry-abuse
2r 1t
low advisory

DNS-over-HTTPS Enabled via Registry Modification

Detection of DNS-over-HTTPS (DoH) being enabled via registry modifications on Windows systems, potentially indicating defense evasion by masking network activity and hindering traditional DNS monitoring.

Microsoft Edge +2 defense-evasion windows dns-over-https
3r 2t