View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Malicious Firefox Extensions Target Crypto Wallets With Secret Theft

🚨 ACTIVE EXPLOITATION

  • Malicious Firefox Extensions Target Crypto Wallets With Secret Theft
    Malicious Firefox extensions are stealing cryptocurrency wallet secrets.
    • Firefox cryptocurrency users are targeted by extensions impersonating OKX, Rabby Wallet, TronLink and other Web3 brands.
    • The campaign includes 40 malicious extensions and 37 deceptive tools, stealing recovery phrases, private keys, credentials and clipboard data.
    • Cloned wallet code and fake listings capture 12- or 24-word phrases and serialized keyrings before sending them to attacker infrastructure.
    • Seven extensions used Supabase-controlled phishing switches; others exfiltrated data through Cloudflare Workers, HTTP servers on port 9000, or C2 IP 77[.]91[.]100[.]175.
    • Observed indicators include portal-web3-extension-welcome[.]pages[.]dev/home and kyfyvuwifdukctqyggto[.]supabase[.]co.
      πŸ“„ Source: socket.dev Β· πŸ“Ž Coverage: cyberpress.org Β· πŸ‘ via Cyber Security News

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Expired Visa Contactless Cards Can Be Reanimated for Purchases
    UMass researchers demonstrated that expired Visa contactless cards can still authorize purchases.

    • Visa contactless cardholders and issuing banks are affected.
    • Expired physical cards can complete contactless payments, including after replacement cards are issued.
    • Two NFC-capable smartphones relay card data between the physical card and a point-of-sale terminal over Wi-Fi.
    • The attack rewrites the unprotected expiration date during transmission; Visa Kernel 3 was vulnerable in testing.
      πŸ“„ Source: usenix.org Β· πŸ“Ž Coverage: umass.edu Β· πŸ‘ via Cyber Security News
  • Cross-Model Replay Exposes Encrypted Reasoning Traces From Major LLM APIs
    Researchers showed that encrypted reasoning traces from major LLM APIs can be recovered through cross-model replay.

    • Anthropic, OpenAI, and Google reasoning-model API customers are affected.
    • Encrypted reasoning blocks are portable across sessions, users, and models within each provider ecosystem.
    • Researchers decoded 315,320 blocks from public agent trajectories, recovering 367 PII artifacts and 182 credentials.
    • Attackers replay a strong model’s encrypted block into a weaker sibling, such as Claude Opus 4.8 into Haiku 4.5, which outputs the hidden reasoning in plaintext.
      πŸ“„ Source: arxiv.org Β· πŸ“Ž Coverage: nsfocusglobal.com Β· πŸ‘ via securityboulevard.com (discovered)

πŸ”“ CVEs & KEV

  • CVE-2026-18776 β€” CVSS 9.8 β€” TrueBooker Appointment Booking before 1.2.7 - Unauthenticated Account Takeover via...

  • CVE-2026-18937 β€” CVSS 9.0 β€” Broken Link Checker before 2.4.12 - Unauthenticated RCE via Query Variable Injecti...

  • CVE-2026-19842 β€” CVSS 8.8 β€” SAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Ta...

  • CVE-2026-14163 β€” CVSS 7.1 β€” In affected versions of Octopus Server under certain circumstances it is poss...

  • CVE-2026-19417 β€” CVSS 6.5 β€” KiviCare before 4.5.4 - Patient+ Arbitrary Media Attachment Read via IDORThe KiviC...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check