❗️🚨 Microsoft Edge keeps every saved password in process memory as cleartext from the moment it launches. Microsoft's responsed when reported: "by design."
All of them. Including credentials for sites you won't open this session.
Researcher @L1v1ng0ffTh3L4N tested every major Chromium browser. Edge is the only one that behaves this way.
Chrome decrypts credentials on demand, and App-Bound Encryption locks the keys to an authenticated Chrome process so other processes can't reuse them.
In Chrome, plaintext surfaces only during autofill or when a password is viewed, making memory scraping far less useful.
What makes this extra weird is that Edge still demands re-authentication before revealing those passwords in its Password Manager UI, while the same browser process already holds every one of them in plaintext.
In shared environments, this turns into a credential harvest. On a terminal server, an attacker with admin rights can read the memory of every logged-on user process. In the published PoC video, a compromised admin account lifts stored credentials from two other logged-on (and even disconnected) users with Edge running.
Microsoft's official response when notified: "by design."
The finding was disclosed April 29 at BigBiteOfTech by PaloAltoNtwks Norway, alongside a small educational tool that lets anyone verify the cleartext storage for themselves.
🚨 Three Windows zero-days released by Nightmare-Eclipse are being used in the wild by threat actors.
BlueHammer (CVE-2026-33825): LPE, Abuses Windows Defender’s signature-update pipeline and VSS to breach protected registry hives, dump SAM hashes/identities, and escalate privileges.
RedSun: LPE to SYSTEM abusing Defender's own cloud remediation to overwrite System32 binaries.
UnDefend: Unprivileged DoS that starves the AV of updates while spoofing healthy EDR telemetry.
🇫🇷📱💵 FLASH | Patrick Drahi ACCEPTE l’offre de 20,35 milliards d’euros du consortium Orange, Free et Bouygues Telecom pour le rachat de SFR. Les opérateurs entrent désormais en négociations exclusives. (Le Point)
@FrenchRapUS Non Linux c’est pas de la merde, non c’est pas fais par des suédois ou des finlandais c’est fais par des gens comme vous comme moi partout dans le monde c’est open source et sécuriser
🛑 Chrome 0-day Warning!
Tracked as CVE-2026-5281, this WebGPU (Dawn) use-after-free bug allows code execution via a crafted page if the renderer is compromised.
It’s the 4th exploited Chrome browser zero-day in 2026.
🔗 Read → https://t.co/MYdqVq06jo