Skip to main content

Tag: browser exploitation

3 articles

Blurred webpage on a laptop screen on a cluttered desk in a modern office workspace.

CISA Mandates Swift Fix for Exploited Ray RCE Flaw

A critical bug in the Ray framework, scoring 9.4 under CVSS v4, can be exploited for remote code execution with a simple visit to a malicious web page or hostile ad in Firefox or Safari. This vulnerability can be triggered when an attacker crafts requests that appear browser-originated, allowing for a potentially disastrous security breach.

Analyst 207
Person sits at desk with laptop, surrounded by empty office space, browser window open.

Chaos Ransomware Gang Exploits Browsers for Stealthy C2 Communications

Cisco Talos researchers have uncovered a sneaky new backdoor, msaRAT, that hijacks Chrome or Microsoft Edge to secretly communicate with its command center, avoiding direct network connections. This stealthy tactic uses the browser's remote debugging interface to inject JavaScript and stay under the radar.

Analyst 207
Smartphone with Chrome app open on a neutral surface, showing a Google sign-in page and blurred tabs.

Stalkers Exploit Chrome's Sync Feature for Surveillance

Imagine having your every online move tracked by someone you trust - all because they exploited a feature meant to make your life easier. A security researcher found that a stalker can use Google Chrome's sync feature to monitor a victim's online activity, gaining access to their browsing history from anywhere in the world.

Analyst 207