Microsoft is changing Edge’s plaintext password behavior
2026-05-18T20:51:52Z•da697c5c0ccb2631365b8f74a64c886b7d0bf68e82342f5c45db20503eb71a96
ai-investment-scamai-model-downloadbrowser-vulnerabilitybun-runtimecanvas-breachclick-fraudclickfixcredential-exposuredata-breachdeepfake-sextortiongoogle-chromeinfostealeriot-vulnerabilitiesjdownloaderkeitaro-adtrackingmac-malwaremalicious-downloadsmicrosoft-edgenwhstealerphysical-safetyplaintext-passwordsshinyhunterssupply-chain-compromisetrojanized-installeryarbo
What happened
Malwarebytes Labs round-up (May 2026) covering multiple active and emerging threats: Microsoft Edge loads saved passwords into plaintext memory at startup (raising local credential-exposure concerns) and is changing behavior after researcher disclosure; the JDownloader website was compromised and installer links were replaced with malware (supply‑chain/trojanized installers); attackers are repurposing the Bun JavaScript runtime to distribute NWHStealer (Windows infostealer); a ClickFix campaign uses fake Claude setup guides to trick macOS users into installing malware; Google Chrome silently下載
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- da697c5c0ccb2631365b8f74a64c886b7d0bf68e82342f5c45db20503eb71a96
- Enrichment time
- 2026-05-18T20:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.