[local] Microsoft Edge 150.0.4078.48 - RCE
Exploit-DB publishes a local remote code execution exploit for Microsoft Edge 150.0.4078.48.
A public exploit demonstrates remote code execution in Microsoft Edge version 150.0.4078.48, listed under the local category on Exploit-DB. Successful exploitation could allow arbitrary code execution in the context of the browser. Users should update to the latest patched Edge release.
Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
Russian GRU-linked BlueDelta (APT28) deployed HOOKEDGE backdoor via macro Word lures against European governments using webhook.site and Microsoft Edge for stealthy C2.
Recorded Future's Insikt Group documented a BlueDelta (APT28/Fancy Bear/Forest Blizzard) espionage campaign from late September 2025 through early April 2026 targeting government and diplomatic organizations in Romania, Spain and Türkiye. The group delivered HOOKEDGE, a lightweight Windows batch-script backdoor, via macro-enabled Word documents with diplomatic lures, including one impersonating Spain's Ministry of the Presidency after a Spanish-Moldovan meeting. HOOKEDGE uses webhook.site as C2, a scheduled task every 30 minutes that downloads commands through Microsoft Edge, and canary pixels like docopened.jpg to track phishing funnel progress. A second tier with 5-minute check-ins served high-value victims, and beaconing intervals were stretched to 61 minutes to evade sandboxes; code overlap ties HOOKEDGE to BlueDelta's earlier HEADLACE backdoor.