CVE-2026-1357
Domains:
tapnetic[.]pro
Extension IDs:
gghdfkafnhfpaooiolhncejnlgglhkhe, nlhpidbjmmffhoogcennoiopekbiglbp, acaeafediijmccnjlokgcdiojiljfpbe, kblengdlefjpjkekanpoidgoghdngdgl, llojfncgbabajmdglnkbhmiebiinohek
Get tomorrow's brief in your inbox
Collected: 2026-02-12 12:46 PM EST Generated by: Claude Code (Opus 4.6)
Malicious Chrome Extensions Steal Credentials and Email Data (300K+ Users Affected)
A campaign dubbed "AiFrame" deployed 30 malicious Chrome extensions disguised as AI assistants (Gemini AI Sidebar, AI Assistant, ChatGPT Translate, etc.) that have been installed by over 300,000 users. The extensions steal credentials, browsing data, and email content. A subset of 15 extensions specifically targets Gmail, extracting email thread text directly from the DOM, including drafts. The extensions use iframes to load remote content and communicate with a single C2 domain (tapnetic[.]pro). Some extensions remain on the Chrome Web Store.
gghdfkafnhfpaooiolhncejnlgglhkhe, nlhpidbjmmffhoogcennoiopekbiglbp, acaeafediijmccnjlokgcdiojiljfpbe, kblengdlefjpjkekanpoidgoghdngdgl, llojfncgbabajmdglnkbhmiebiinohekWordPress WPvivid Backup Plugin RCE (CVE-2026-1357, CVSS 9.8)
A critical RCE vulnerability in the WPvivid Backup & Migration plugin (900,000+ installs) allows unauthenticated arbitrary file upload. The flaw stems from improper RSA decryption error handling combined with lack of path sanitization, enabling directory traversal and malicious PHP upload. Exploitation requires the "receive backup from another site" option to be enabled (non-default), with a 24-hour window tied to key validity. This feature is commonly enabled during migrations.
Microsoft to Enable Windows Baseline Security Runtime Integrity
Microsoft announced it will enable runtime integrity safeguards by default in Windows, ensuring only properly signed software runs. This is a significant step toward reducing unsigned malware execution on Windows endpoints.
AMOS Infostealer Targeting macOS via AI App Supply Chain (ClawHavoc Campaign)
The AMOS (Atomic macOS Stealer) infostealer is being distributed through a supply-chain attack on the OpenClaw/ClawHub AI assistant ecosystem. Attackers uploaded malicious "skills" (add-ons) mimicking crypto tools, productivity utilities, and Google Workspace integrations. Once installed, AMOS steals credentials, browser sessions, SSH keys, crypto wallet data, and macOS keychain passwords. AMOS has been active since May 2023 and operates as a $1,000/month MaaS offering.
ApolloMD Data Breach Impacts 626,000 Individuals
ApolloMD, a healthcare staffing company, disclosed that hackers stole personal information of patients from affiliated physicians and practices, affecting 626,000 individuals.
Threat Landscape Fragmentation Creates New Risks for SMBs
Recorded Future's 2026 State of Security report highlights that the threat landscape has fragmented significantly. Law enforcement pressure splintered criminal enterprises into smaller, faster operations. State-sponsored actors (China, Russia, Iran, North Korea) have shifted from dramatic attacks to quiet pre-positioning in identity systems, cloud environments, and edge infrastructure (VPN appliances, unpatched network devices). The convergence of state objectives and criminal capability compresses warning time for defenders.
State Actors and Hacktivists Target Global Defense Industry
Google warns that threat actors from Russia, China, North Korea, and Iran are actively targeting the global defense industry, including contractors and supply chain vendors.
GTIG: Threat Actors Integrating AI to Accelerate Attacks
Google Threat Intelligence Group reports that in Q4 2025, threat actors increasingly used AI for reconnaissance, social engineering, and malware development. Key findings: model extraction ("distillation") attacks are rising as IP theft; DPRK, Iran, China, and Russia are using LLMs for phishing lure generation and technical research; a new malware family (HONESTCUE) uses Gemini's API to generate code for second-stage payload delivery; underground services like "Xanthorox" claim independent AI models but actually rely on jailbroken commercial APIs.
Senegal National Biometric Database Breached
A group called "Green Blood Group" breached Senegal's national biometric database, exposing personal records and biometric data of nearly 20 million residents. The breach highlights systemic security maturity gaps in government biometric systems.
CISA to Host Town Halls on Cyber Incident Reporting Rule (CIRCIA)
CISA will hold sector-by-sector town halls to refine the scope of the CIRCIA regulation, which requires critical infrastructure operators to report significant cyberattacks within 72 hours and ransomware payments within 24 hours. The final rule has been delayed, with the Trump administration pushing it to May.
Memory Prices Drive Hardware Cost Increases
DRAM prices doubled and NAND jumped 70% since late 2025. Cisco, Lenovo, and other vendors are passing costs to buyers. Cisco announced price hikes on networking hardware. A 10-15% decline in PC shipments is forecast if costs are fully passed through. Corporate buyers are accelerating purchases before further increases.
3D Printer Surveillance Legislation in New York
New York's 2026-2027 budget bill includes a provision requiring all 3D printers sold in the state to include "blocking technology" that scans print files through a firearms blueprint detection algorithm.
Three patterns stand out today. First, AI is becoming both weapon and attack surface: threat actors are using LLMs to improve phishing and malware generation, while users installing AI-themed browser extensions and agent add-ons are being hit with credential theft at scale. Second, hardware cost inflation from the memory shortage will squeeze IT budgets across the board, making it harder for SMBs to fund security refresh cycles alongside necessary infrastructure upgrades. Third, the fragmentation of criminal operations into smaller, faster groups, combined with state-sponsored pre-positioning in edge infrastructure, means the threat environment is getting harder to track with traditional perimeter defenses.
Carolina Clear Tech, LLC - carolinacleartech.com