malicious extensions

Winsage
September 9, 2026
Recent investigations have identified the BlueMoon exploit kit, used by espionage-driven threat activity clusters, particularly linked to APT31, a China-aligned state-sponsored group, since August 28, 2026. BlueMoon exploits three vulnerabilities: CVE-2026-85046 (a type confusion vulnerability in Google Chrome's V8 engine), an unassigned V8 sandbox escape, and CVE-2026-85880 (a heap-based buffer overflow in Windows ALPC). Google and Microsoft have released patches for these vulnerabilities, which were exploited as "patch-gap" zero-days. The attack vectors typically begin with phishing emails that lead victims to malicious URLs, triggering the vulnerabilities for code execution and privilege escalation. Variants of BlueMoon have been detected, featuring modifications for specific campaigns. Notable attack chains include: - APT31 targeting NGOs and mining firms in the U.S. with a malicious browser add-on called GemStone. - UNK_LateNight targeting U.S. aerospace companies, deploying BlueMoon alongside the ShadowPad backdoor. - UNK_DoubleCheck targeting a Vietnamese manufacturer, using DLL sideloading to execute a Rust binary. - UNK_QuietRacket targeting government and financial organizations in Indonesia and Singapore, modifying BlueMoon to execute a .NET assembly. CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, 2026, requiring federal agencies to apply patches by September 18, 2026. Indicators of compromise include specific process trees, files, folders, scheduled tasks, mutexes, and registry keys. Proofpoint has released detection rules to help organizations identify and mitigate these threats.
Tech Optimizer
December 7, 2025
Modern antivirus solutions have reduced PC infections, but risks persist as cybercriminals develop stealthy methods to infiltrate systems. Signs of infection include unfamiliar programs, missing files, slow performance, and disabled security settings. If infection is suspected, disconnect from the internet, boot into Safe Mode, and run a full system scan with Windows Security or Microsoft Defender. To enhance cybersecurity post-infection, users should clear temporary files, reset browser settings, uninstall suspicious applications, scan external drives, keep Windows updated, use strong passwords, and verify sources before engaging with links or attachments. Tools like VirusTotal can help scan files from unverified sources. If performance issues continue, a complete reinstallation of Windows 11 may be necessary, ensuring essential files are backed up first.
Winsage
October 7, 2025
Windows 10 is reaching the end of its life cycle next week, with Microsoft extending security support under certain conditions. Google is promoting its Chromebooks and ChromeOS as a user-friendly alternative, targeting Windows 10 users through advertisements highlighting the security vulnerabilities of Windows 10. Chromebooks offer a 10-year support promise starting from the device's release date, but users should be aware that while ChromeOS has not had a virus, it is still susceptible to malicious extensions and phishing attacks. Google is also integrating AI technology into ChromeOS and Android, which may lead to user frustrations similar to those experienced with Windows.
Tech Optimizer
July 8, 2025
Nearly a dozen malicious extensions in Google’s Chrome Web Store have collectively received 1.7 million downloads. These extensions can track browser activity, redirect users to harmful websites, and include various types such as VPNs and weather tools. Koi Security reported these extensions to Google, resulting in the removal of some, but others remain available. Users are advised to monitor their online activities and utilize antivirus software for protection.
Search