StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years
2026-06-29T20:51:41Z•d325f5429be9bf81428f2cd58e7b7c254262650186504fe5200cbb362fda6802
CL-STA-1062CVE-2026-43503CellebriteDirtyCloneEdge Add-onsFBIKDDILinux kernelMicrosoft Threat IntelligenceRussian cyber espionageSSUSignal recovery keysStegoAdTinyRCTTonRATad fraudbrowser extensionscredential theftdata breachemail accountshospitality sectormessaging compromisephishingprivilege escalationthird-party vulnerability
What happened
Collection of SecurityAffairs reports (late June 2026) covering multiple high-impact incidents: Microsoft dismantled the StegoAd operation—119 malicious Edge extensions with ~2.6M installs used for credential theft and ad fraud; Ukraine's SSU and the FBI exposed a long-running Russian intelligence campaign compromising messaging accounts; KDDI disclosed a breach impacting up to 14.2M email accounts via a third‑party software vulnerability; JFrog disclosed DirtyClone (CVE-2026-43503), a Linux kernel privilege escalation with CVSS 8.8 that enables silent in-memory executable rewriting; plus FBI/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- d325f5429be9bf81428f2cd58e7b7c254262650186504fe5200cbb362fda6802
- Enrichment time
- 2026-06-29T20:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.