StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years
2026-06-29T14:51:45Z•2517a4495e8f0cd0f5ced62f9d1129a9cc84104f2d4183d8d41cf108e911af8d
APTCL-STA-1062CVE-2026-43503Cellebrite-abuse','AryStinger','CASTLESTEALER'DirtyCloneEdgeFBIKDDILinux-kernelMicrosoftRussian-espionageSSUSignal-recovery-keysStegoAdTinyRCTTonRATaccount-takeoverad-fraudbrowser-extensionscredential-theftdata-breachhospitality-sectorphishingprivilege-escalationthird-party-vulnerability
What happened
Feed of SecurityAffairs headlines (Jun 26–29, 2026): Microsoft dismantled the “StegoAd” campaign — 119 malicious Edge extensions with ~2.6M installs that stole credentials and ran ad-fraud for ~2 years. Ukraine’s SSU and the FBI exposed a sustained Russian intelligence campaign harvesting messenger accounts (including misuse of Signal recovery keys) to enable account takeover. KDDI disclosed a breach impacting up to 14.2M email accounts after attackers exploited third‑party software. JFrog published a working exploit for DirtyClone (CVE-2026-43503), a Linux kernel privilege-escalation (CVSS ~8
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 2517a4495e8f0cd0f5ced62f9d1129a9cc84104f2d4183d8d41cf108e911af8d
- Enrichment time
- 2026-06-29T14:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.