Security Highlights Of The Day [02/03/26]

Chrome Gemini Panel Vulnerability Allowed Extension Hijacking
Researchers disclosed CVE-2026-0628, a high severity vulnerability in Google Chrome’s Gemini Live feature that could allow malicious browser extensions with basic permissions to hijack the Gemini panel and access local files. The flaw could have enabled privilege escalation by tapping into the browser environment. Google was notified responsibly and released a fix in early January before public disclosure.
Source: Unit 42

APT28 Linked to MSHTML Zero Day Exploited Before Patch Tuesday
The Russia linked threat actor APT28 is believed to have exploited CVE-2026-21513, a high severity MSHTML security feature bypass vulnerability with a CVSS score of 8.8, before it was patched in Microsoft’s February 2026 Patch Tuesday release. The flaw allowed attackers to bypass security protections over a network and may have been used in targeted operations.
Source: SecurityWeek

StegaBin Campaign Uses Malicious npm Packages and Pastebin Steganography
Researchers identified 26 malicious npm packages deploying a multi stage credential harvesting operation targeting developers. The campaign, dubbed StegaBin, hides command and control infrastructure within Pastebin content using character level steganography. The infection chain ultimately installs a remote access trojan and a nine module infostealer toolkit targeting developer assets including SSH keys, git repositories, browser credentials, and locally stored secrets.
Source: Socket

Thousands of Google Cloud API Keys Exposed with Gemini Access
Research revealed nearly 3,000 publicly exposed Google Cloud API keys embedded in client side code. Although typically used as billing project identifiers, these keys could be abused to authenticate to sensitive Gemini endpoints and access private data once APIs were enabled, highlighting risks tied to key exposure in web applications.
Source: The Hacker News

ClawJacked Flaw Enabled Hijacking of Local OpenClaw AI Agents
A high severity vulnerability in OpenClaw allowed malicious websites to connect to locally running AI agents via a WebSocket gateway bound to localhost. Under specific conditions involving social engineering, attackers could gain control of the agent without plugins or additional extensions. The issue has since been fixed by the vendor.
Source: The Hacker News

Scroll to top