Suspicious Polyfill login prompts pop up on Toshiba, Muji websites
2026-06-06T01:23:35Z•44ba6b8a4d1d79d5333f63aa8f6d3156e19f9287ad646e0e1e78e453c85879ba
AgentPSDBrickstormCISACVE-2026-20245Chinese-APTDentaQuestHola-BrowserIronWormMagecartOT-exposurePlenetSolarWinds-Serv-UStripe-abuseUNC5221WFP-breachautomatic-tank-gaugebrowser-attackscredential-theftcryptominerdata-breachnpmpolyfill-loginroot-privilege-escalationsupply-chainzero-day
What happened
Multiple active and high-impact threats reported: Cisco disclosed an actively exploited unpatched SD‑WAN zero-day (CVE-2026-20245) enabling root escalation; CISA warned of exploitation of a recently patched SolarWinds Serv‑U flaw to crash servers. Supply‑chain attacks continue — 36 npm packages hit with IronWorm infostealer, Hola Browser update compromised to deliver a cryptominer, and a Magecart campaign abusing Stripe to host skimmers/exfiltrated payment data. Browser‑layer and credential‑theft attacks are rising (suspicious polyfill login prompts on Toshiba/Muji, DBIR findings), while a中国 A
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 44ba6b8a4d1d79d5333f63aa8f6d3156e19f9287ad646e0e1e78e453c85879ba
- Enrichment time
- 2026-06-06T01:23:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.