:

MALVERTISING CAMPAIGN BUILDS MALWARE IN BROWSER MEMORY

DEV DESK1 MIN READ
SAT, JUL 25, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A widespread malvertising operation is deploying malicious JavaScript on fake cryptocurrency and trading sites to assemble malware directly in browser memory, bypassing traditional detection methods.

The campaign uses counterfeit webpages mimicking Solana, Luno, and TradingView to distribute the attack. By constructing malware in memory rather than writing files to disk, the threat actors evade antivirus and security tools that typically scan stored files. This in-memory assembly technique represents an escalation in malvertising tactics. The malicious JavaScript executes when users visit the fake sites, allowing attackers to build and deploy malware without leaving traditional forensic traces. The fake pages appear designed to harvest credentials or deploy financial theft malware targeting cryptocurrency users and traders. Security researchers have documented the campaign targeting users across multiple regions. Users should verify URLs carefully before accessing financial platforms and consider using security browser extensions. Organizations can mitigate risk by implementing content security policies and restricting JavaScript execution on untrusted domains.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

ID verification service IDScan has confirmed a data breach exposing 153 million driver's licenses after hackers placed them up for sale. The stolen credentials pose significant identity theft risks to affected individuals.

1H AGOSecurity Desk

Trezor alerted customers Wednesday that attackers exploited a breach at its third-party email provider to launch phishing campaigns. The cryptocurrency hardware wallet maker urged users to remain vigilant against fraudulent communications.

6H AGOAI Desk

Forgejo, a self-hosted Git service, released version 16.0.4 to address a critical remote code execution vulnerability affecting all versions up to 16.0.3. Users should upgrade immediately.

7H AGOIndustry Desk

Microsoft's September 2026 security patches are disabling Remote Desktop Services across Windows Server 2019, 2022, and 2025, leaving administrators unable to access systems and requiring hard resets in some cases.

7H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.