Recently, the phenomenon of malicious websites utilizing JavaScript to construct malware in browser memory has garnered significant attention. According to a report by BleepingComputer, a large-scale malvertising campaign is underway, where attackers create fake Solana, Luno, and TradingView webpages that employ malicious JavaScript instructions to assemble malware directly in memory. This operation has been active since late 2024, primarily localized to 12 countries in the Asia Pacific and Latin America, using 25 different languages. The attackers employ a filtering system to ensure that only real targets, such as retail traders and crypto investors, land on these malicious pages, while researchers and security scanners are redirected to blank pages. On another front, a security vulnerability in the Adobe Acrobat extension has also been disclosed, allowing malicious sites to read WhatsApp Web data. Research from Guardio Labs indicates that this vulnerability, dubbed HermeticReader, affects the Adobe Acrobat Chrome extension used by over 314 million users. Attackers need only to convince users to visit a maliciously crafted URL to exploit this flaw and gain access to session data from WhatsApp. These incidents highlight the increasingly complex threats facing the cybersecurity landscape, necessitating that both enterprises and users remain vigilant and avoid downloading applications from unverified sources.
Industry Insights · July 26, 2026
Industry Observation on Malicious Websites and Security Vulnerabilities
Malicious websites use JavaScript to build malware in browser memory, while Adobe extension flaw affects WhatsApp data.
