π¨ ACTIVE EXPLOITATION
- Malicious Firefox Extensions Target Crypto Wallets With Secret Theft
Malicious Firefox extensions are stealing cryptocurrency wallet secrets.- Firefox cryptocurrency users are targeted by extensions impersonating OKX, Rabby Wallet, TronLink and other Web3 brands.
- The campaign includes 40 malicious extensions and 37 deceptive tools, stealing recovery phrases, private keys, credentials and clipboard data.
- Cloned wallet code and fake listings capture 12- or 24-word phrases and serialized keyrings before sending them to attacker infrastructure.
- Seven extensions used Supabase-controlled phishing switches; others exfiltrated data through Cloudflare Workers, HTTP servers on port 9000, or C2 IP 77[.]91[.]100[.]175.
- Observed indicators include portal-web3-extension-welcome[.]pages[.]dev/home and kyfyvuwifdukctqyggto[.]supabase[.]co.
π Source: socket.dev Β· π Coverage: cyberpress.org Β· π via Cyber Security News
π΅οΈ RESEARCH & DEEP DIVES
-
Expired Visa Contactless Cards Can Be Reanimated for Purchases
UMass researchers demonstrated that expired Visa contactless cards can still authorize purchases.- Visa contactless cardholders and issuing banks are affected.
- Expired physical cards can complete contactless payments, including after replacement cards are issued.
- Two NFC-capable smartphones relay card data between the physical card and a point-of-sale terminal over Wi-Fi.
- The attack rewrites the unprotected expiration date during transmission; Visa Kernel 3 was vulnerable in testing.
π Source: usenix.org Β· π Coverage: umass.edu Β· π via Cyber Security News
-
Cross-Model Replay Exposes Encrypted Reasoning Traces From Major LLM APIs
Researchers showed that encrypted reasoning traces from major LLM APIs can be recovered through cross-model replay.- Anthropic, OpenAI, and Google reasoning-model API customers are affected.
- Encrypted reasoning blocks are portable across sessions, users, and models within each provider ecosystem.
- Researchers decoded 315,320 blocks from public agent trajectories, recovering 367 PII artifacts and 182 credentials.
- Attackers replay a strong modelβs encrypted block into a weaker sibling, such as Claude Opus 4.8 into Haiku 4.5, which outputs the hidden reasoning in plaintext.
π Source: arxiv.org Β· π Coverage: nsfocusglobal.com Β· π via securityboulevard.com (discovered)
π CVEs & KEV
-
CVE-2026-18776 β CVSS 9.8 β TrueBooker Appointment Booking before 1.2.7 - Unauthenticated Account Takeover via...
-
CVE-2026-18937 β CVSS 9.0 β Broken Link Checker before 2.4.12 - Unauthenticated RCE via Query Variable Injecti...
-
CVE-2026-19842 β CVSS 8.8 β SAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Ta...
-
CVE-2026-14163 β CVSS 7.1 β In affected versions of Octopus Server under certain circumstances it is poss...
-
CVE-2026-19417 β CVSS 6.5 β KiviCare before 4.5.4 - Patient+ Arbitrary Media Attachment Read via IDORThe KiviC...