KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
2026-09-16T01:23:59Z•591bae65341f682174c06c2fe4f5e460895a83ae41bc66cfe87d1f7bdaeef746
CVE-2026-42016CVE-2026-76461CVE-2026-85706ChromeCiscoGitLabGiteaLinuxLiteSpeedMQTTRCETelegramViteWindowsactive-exploitationbanking-trojanbrowser-extensioncloud-credential-theftcredential-theftespionagemalwarepasskeysphishingransomwareremote-accesssession-token-theftstate-sponsoredsupply-chain
What happened
The feed reports active and emerging cyber threats spanning banking malware, state-sponsored espionage, MQTT-controlled cross-platform malware, mass exploitation of exposed development servers, browser and desktop data theft, supply-chain attacks, and critical vulnerabilities under exploitation. Notable high-impact items include an actively exploited Cisco Secure Email Gateway flaw enabling unauthenticated root command execution (CVE-2026-76461, CVSS 9.8), a CVSS 10 GitLab arbitrary file-read vulnerability (CVE-2026-85706), and multiple vulnerabilities added to CISA's KEV catalog. Campaigns by
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 591bae65341f682174c06c2fe4f5e460895a83ae41bc66cfe87d1f7bdaeef746
- Enrichment time
- 2026-09-16T01:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.