Malware bypasses browser checks to force install Chrome, Edge extensions
2026-09-16T19:23:22Z•4f6337f90b452081d06a58a5aaad995203d43d881fe9dce596a5226f5d4eb59a
AcronisAndroidBambooTokenMQTTScreenConnectVMware vCenterWordPressactive exploitationbrowser extensionscredential theftdata breachmalwareprivilege escalationransomwareremote code executionsession token theftsupply-chain compromisezero-day
What happened
A BleepingComputer security-news feed reports multiple active threats, including malware installing malicious browser extensions, actively exploited critical vulnerabilities in ScreenConnect and VMware vCenter, an Android zero-day, an Acronis cPanel backup-plugin privilege-escalation flaw, WordPress supply-chain and plugin compromises, and the BambooToken malware framework controlling Windows and Linux systems via MQTT. The feed also includes data-breach reporting and ransomware-impact guidance. Overall, the most urgent items involve vulnerabilities being actively exploited in the wild and may
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 4f6337f90b452081d06a58a5aaad995203d43d881fe9dce596a5226f5d4eb59a
- Enrichment time
- 2026-09-16T19:23:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.