Microsoft is changing Edge’s plaintext password behavior

2026-05-18T20:51:52Zda697c5c0ccb2631365b8f74a64c886b7d0bf68e82342f5c45db20503eb71a96
ai-investment-scamai-model-downloadbrowser-vulnerabilitybun-runtimecanvas-breachclick-fraudclickfixcredential-exposuredata-breachdeepfake-sextortiongoogle-chromeinfostealeriot-vulnerabilitiesjdownloaderkeitaro-adtrackingmac-malwaremalicious-downloadsmicrosoft-edgenwhstealerphysical-safetyplaintext-passwordsshinyhunterssupply-chain-compromisetrojanized-installeryarbo

What happened

Malwarebytes Labs round-up (May 2026) covering multiple active and emerging threats: Microsoft Edge loads saved passwords into plaintext memory at startup (raising local credential-exposure concerns) and is changing behavior after researcher disclosure; the JDownloader website was compromised and installer links were replaced with malware (supply‑chain/trojanized installers); attackers are repurposing the Bun JavaScript runtime to distribute NWHStealer (Windows infostealer); a ClickFix campaign uses fake Claude setup guides to trick macOS users into installing malware; Google Chrome silently下載

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
da697c5c0ccb2631365b8f74a64c886b7d0bf68e82342f5c45db20503eb71a96
Enrichment time
2026-05-18T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft is changing Edge’s plaintext password behavior · Baitaphish