Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
4 results for “post-exploitation”
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
PEEP is a post-exploitation toolkit that injects a malicious bookmarks extension into Chrome and Edge browser profiles without user consent or store approval, enabling remote command execution after initial system compromise.
Sep 8, 2026
Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers
A cybersecurity research team disclosed a post-exploitation technique exploiting Chrome DevTools Protocol (CDP) in live Windows browser processes to hijack authenticated sessions, requiring prior code execution on the host.
Published Aug 14, 2026 · Analyzed Aug 17, 2026
Hackers run khunt post-exploitation toolkit from Oracle database
Attackers leveraged a SQL injection flaw to deploy the Khunt post-exploitation toolkit inside an Oracle database, enabling lateral movement and persistence within a corporate network.
Aug 6, 2026
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor allegedly used the open-source Hermes AI agent in autonomous 'YOLO' mode to automate post-exploitation actions during a cyber intrusion targeting Thailand's Ministry of Finance.
Jul 25, 2026