KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

2026-09-16T01:23:59Z•591bae65341f682174c06c2fe4f5e460895a83ae41bc66cfe87d1f7bdaeef746
CVE-2026-42016CVE-2026-76461CVE-2026-85706ChromeCiscoGitLabGiteaLinuxLiteSpeedMQTTRCETelegramViteWindowsactive-exploitationbanking-trojanbrowser-extensioncloud-credential-theftcredential-theftespionagemalwarepasskeysphishingransomwareremote-accesssession-token-theftstate-sponsoredsupply-chain

What happened

The feed reports active and emerging cyber threats spanning banking malware, state-sponsored espionage, MQTT-controlled cross-platform malware, mass exploitation of exposed development servers, browser and desktop data theft, supply-chain attacks, and critical vulnerabilities under exploitation. Notable high-impact items include an actively exploited Cisco Secure Email Gateway flaw enabling unauthenticated root command execution (CVE-2026-76461, CVSS 9.8), a CVSS 10 GitLab arbitrary file-read vulnerability (CVE-2026-85706), and multiple vulnerabilities added to CISA's KEV catalog. Campaigns by

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
591bae65341f682174c06c2fe4f5e460895a83ae41bc66cfe87d1f7bdaeef746
Enrichment time
2026-09-16T01:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.