VoidStealer malware steals Chrome master key via debugger trick
2026-03-23T07:23:27Z•3f9101c7a61cb5d5c1779d11da35fc7aa5b0d82edcf05ac48b0c2cc3de2b733d
Application-Bound EncryptionAzure MonitorCISACVE-2026-20131CVE-2026-21992ChromeCiscoGitHub ActionsIdentity ManagerMagentoOraclePolyShellRCERussian intelligenceSignalTeamPCPTrivybrowser-securitycallback-phishingdata-breach`,`law-enforcement`,`botnet-takedowndebuggerinformation-stealermalwarephishingsupply-chain
What happened
A BleepingComputer news roundup reports multiple high-impact security developments: VoidStealer malware abuses a debugger trick to bypass Chrome’s Application-Bound Encryption and extract the browser master key; Trivy’s supply chain was compromised by TeamPCP to distribute an infostealer via official releases and GitHub Actions; and Microsoft Azure Monitor alerts are being abused for callback phishing while the FBI links Signal/WhatsApp phishing to Russian intelligence-linked actors. Oracle issued an emergency out-of-band fix for a critical unauthenticated RCE (CVE-2026-21992) and CISA ordered
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 3f9101c7a61cb5d5c1779d11da35fc7aa5b0d82edcf05ac48b0c2cc3de2b733d
- Enrichment time
- 2026-03-23T07:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.