KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

2026-09-15T19:24:00Z•9d6aa3f5e559f2b7a7aa0fcc4e47300446e414a8fb9924c1ad41cb53c5e5b74e
CVE-2026-42016CVE-2026-76461CVE-2026-85706C2ChromeCiscoGitLabGiteaLinuxLiteSpeedMQTTMicrosoft-WindowsRCETelegramWindowsbanking-trojanbrowser-extensioncloud-credential-theftcredential-theftespionageexposed-dev-serversmalwarepasskeysphishingprivilege-escalationsession-token-theftstate-sponsoredsupply-chain-security」「AI-assisted-attacks

What happened

The feed reports multiple active and emerging cyber threats, including banking malware, state-sponsored espionage, MQTT-controlled cross-platform malware, mass exploitation of exposed development servers, critical vulnerabilities exploited in the wild, browser-extension credential theft, phishing against cloud accounts, and AI-assisted attack operations. Notable high-impact items include Cisco Secure Email Gateway CVE-2026-76461 (CVSS 9.8) enabling unauthenticated root command execution, GitLab CVE-2026-85706 (CVSS 10.0) allowing arbitrary file reads, actively exploited vulnerabilities addedแ?

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
9d6aa3f5e559f2b7a7aa0fcc4e47300446e414a8fb9924c1ad41cb53c5e5b74e
Enrichment time
2026-09-15T19:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.