Suspicious Polyfill login prompts pop up on Toshiba, Muji websites

2026-06-06T01:23:35Z44ba6b8a4d1d79d5333f63aa8f6d3156e19f9287ad646e0e1e78e453c85879ba
AgentPSDBrickstormCISACVE-2026-20245Chinese-APTDentaQuestHola-BrowserIronWormMagecartOT-exposurePlenetSolarWinds-Serv-UStripe-abuseUNC5221WFP-breachautomatic-tank-gaugebrowser-attackscredential-theftcryptominerdata-breachnpmpolyfill-loginroot-privilege-escalationsupply-chainzero-day

What happened

Multiple active and high-impact threats reported: Cisco disclosed an actively exploited unpatched SD‑WAN zero-day (CVE-2026-20245) enabling root escalation; CISA warned of exploitation of a recently patched SolarWinds Serv‑U flaw to crash servers. Supply‑chain attacks continue — 36 npm packages hit with IronWorm infostealer, Hola Browser update compromised to deliver a cryptominer, and a Magecart campaign abusing Stripe to host skimmers/exfiltrated payment data. Browser‑layer and credential‑theft attacks are rising (suspicious polyfill login prompts on Toshiba/Muji, DBIR findings), while a中国 A

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
44ba6b8a4d1d79d5333f63aa8f6d3156e19f9287ad646e0e1e78e453c85879ba
Enrichment time
2026-06-06T01:23:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.