Morning Review in IT Security — August 12, 2026
The technology security landscape faces mounting pressure from both malicious actors and systemic vulnerabilities. Today's briefing covers a massive coordinated campaign targeting Chrome users through deceptive VPN extensions, alongside Microsoft's substantial monthly security release addressing hundreds of flaws, including actively exploited zero-day vulnerabilities.
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
Socket's Threat Research Team has identified a coordinated campaign of 737 free VPN and proxy extensions published across at least 40 Chrome Web Store developer accounts, with 274 of them impersonating 66 established VPN and privacy brands. The extensions route users' entire browser sessions through SOCKS5 proxies operated by a single provider, accumulating 75,486 installs across the campaign. Of the 737 extensions, 516 were listed as active when the analysis was conducted, carrying 58,318 installs. The threat actor has placed itself in an adversary-in-the-middle position over all browser traffic, capable of reading every destination the browser reaches, the TLS SNI values of HTTPS connections, the user's source IP address, and the complete contents of any request sent over plain HTTP.
The campaign exhibits sophisticated evasion techniques. One hundred four extensions declare host permissions for Cloudflare and Google DNS-over-HTTPS endpoints, resolving their own proxy hostnames through them and handing Chrome a raw IP address so that the victim's machine never emits a plaintext DNS query for the threat actor's domains. The paid tier advertises servers in Japan, Singapore, Canada, Australia, and Turkey, yet not one of those 200 hostnames resolved during the investigation. The extensions place the threat actor in a position to read all browser traffic, and Socket observed the client side only, making no claim about what the proxy servers retain or transmit beyond what is established from the packages and public infrastructure: the impersonation, the undisclosed proxy configuration, the non-existent premium servers, the false statements submitted to store reviewers, and post-approval code substitution.
The infrastructure and attribution evidence establishes this as a single operation. The extensions declare themselves as products of Myxa VPN, a subscription VPN business operating in Russia. Three hundred sixty of 522 retrieved packages spanning 34 of 37 publisher accounts render a string in the popup naming their own supplier, with 330 reading "Premium доступ предоставляет официальный VPN провайдер Myxa VPN" (Premium access is provided by the official VPN provider Myxa VPN). The campaign targets Russian-speaking users seeking to reach services blocked inside Russia, including Instagram, ChatGPT, and YouTube. Six hundred ninety of the 734 extensions in the source dataset are Russian-targeted by at least one of three tests: a Cyrillic listing name, a Cyrillic manifest description, or a blocked-service name in the listing. The threat actor published a self-employed taxpayer number as its contracting party, and Socket confirmed an active professional income tax registration through the Russian Federal Tax Service's public self-employment taxpayer-status service.
Google has removed 221 of the 737 extensions from the Chrome Web Store, but the campaign persists through structural advantages. An account costs five dollars and publishes a mean of 9.1 extensions before its first removal, then continues and publishes a mean of 15.8 more over a further 69 days. Twenty-eight of 29 core accounts kept publishing after their first removal, and 29 of the 30 accounts that have had an extension removed still hold live extensions. Palo Alto Networks published on part of this campaign on June 5, 2026, naming 18 extension IDs, and all 18 appear in Socket's set. Three had already been removed before publication, and 14 of the remaining 15 were removed in the seven weeks after it. The 15 publisher accounts behind them retained 250 live extensions carrying 26,151 installs. Source: 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
Microsoft Patch Tuesday, August 2026 Security Update Review
Microsoft released its August 2026 Patch Tuesday update addressing 421 vulnerabilities, including 62 critical and 357 important-severity vulnerabilities. The release includes fixes for three zero-day vulnerabilities: two publicly disclosed and one exploited in the wild. As attackers continue to exploit unpatched vulnerabilities, timely patching remains critical for reducing exposure and strengthening enterprise security posture across organizations relying on Microsoft products and services. Source: Microsoft Patch Tuesday, August 2026 Security Update Review
Microsoft Plugs Nearly 400 Security Holes
Microsoft released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software. The release includes one weakness already being actively exploited and two others that were publicly detailed prior to the patch release. This substantial monthly update underscores the ongoing challenge of managing vulnerability risk across Microsoft's extensive product ecosystem. Source: Microsoft Plugs Nearly 400 Security Holes
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft's monthly security update addresses 398 flaws, including a zero-day vulnerability in a core Windows kernel driver that handles network socket operations. The flaw, tracked as CVE-2026-68820 with a CVSS score of 7.0, is already being used in active attacks. An attacker with code already running on a machine can exploit this vulnerability to escalate privileges to SYSTEM level. The Windows driver zero-day represents an immediate threat to unpatched systems and should be prioritized for deployment across enterprise environments. Source: Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
The convergence of large-scale supply-chain threats through browser extensions and critical zero-day exploitation in Windows infrastructure demonstrates the multifaceted nature of contemporary security challenges. Organizations must balance immediate remediation of actively exploited vulnerabilities with broader security hygiene practices, including extension vetting and user awareness training.