Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software

2026-04-27T14:51:48Z6d7d880910210ce29f47708fb66fca0a45b6f0b6f632152f3c9e6cb92256c60f
BrowserGateCVE-2026-40050CVE-2026-6770Chinese-actorCrowdStrikeFast16Go-based-malwareGopherWhisperNASATorTrigonabrowser-fingerprintingdata-breachespionageexfiltrationpath-traversalprivacyransomwarespear-phishingvulnerability

What happened

Multiple high-impact security stories: a Chinese national ran a spear-phishing campaign posing as a U.S. researcher to trick NASA staff and steal defense-related software data; an investigation dubbed “BrowserGate” alleges LinkedIn extensions and device fingerprinting were used to secretly track users and exfiltrate encrypted results; Firefox/Tor fingerprinting vulnerability CVE-2026-6770 (patched in Firefox 150 and Tor Browser 15.0.10) allowed cross-site/Tor fingerprinting even in Private mode; CrowdStrike LogScale self-hosted was patched for a critical unauthenticated path traversal allowing

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
6d7d880910210ce29f47708fb66fca0a45b6f0b6f632152f3c9e6cb92256c60f
Enrichment time
2026-04-27T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.