:

MALVERTISING CAMPAIGN BUILDS MALWARE IN BROWSER MEMORY

DEV DESK1 MIN READ
SAT, JUL 25, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A widespread malvertising operation is deploying malicious JavaScript on fake cryptocurrency and trading sites to assemble malware directly in browser memory, bypassing traditional detection methods.

The campaign uses counterfeit webpages mimicking Solana, Luno, and TradingView to distribute the attack. By constructing malware in memory rather than writing files to disk, the threat actors evade antivirus and security tools that typically scan stored files. This in-memory assembly technique represents an escalation in malvertising tactics. The malicious JavaScript executes when users visit the fake sites, allowing attackers to build and deploy malware without leaving traditional forensic traces. The fake pages appear designed to harvest credentials or deploy financial theft malware targeting cryptocurrency users and traders. Security researchers have documented the campaign targeting users across multiple regions. Users should verify URLs carefully before accessing financial platforms and consider using security browser extensions. Organizations can mitigate risk by implementing content security policies and restricting JavaScript execution on untrusted domains.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Security researchers identified four separate threat groups exploiting an identical vulnerability affecting Chrome and Windows. The shared exploit kit suggests a widening security gap in patch deployment.

4H AGOSecurity Desk

Read the Docs, the popular documentation hosting platform, recently experienced a significant distributed denial-of-service (DDoS) attack. The platform has published technical details about the incident and its response.

6H AGOAI Desk

Cisco has confirmed that CVE-2026-20079, a maximum-severity authentication bypass vulnerability in its Secure Firewall Management Center (FMC), is actively being exploited in attacks.

6H AGOSecurity Desk

Carnegie Mellon University's CERT Coordination Center has identified a critical security flaw in Skullcandy Dime 3 earbuds that allows nearby devices to pair without user approval. Attackers can exploit this vulnerability to hijack the earbuds and potentially access connected devices.

6H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.