{"id":31585,"date":"2025-12-17T12:51:24","date_gmt":"2025-12-17T12:51:24","guid":{"rendered":"http:\/\/localhost\/?p=31585"},"modified":"2025-12-17T12:51:24","modified_gmt":"2025-12-17T12:51:24","slug":"shadypanda-the-silent-browser-takeover-threat-and-how-qualys-trurisk-eliminate-helps-you-stop-it","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=31585","title":{"rendered":"ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It_QUALYSBLOG:DFBA459B23CBBC98D1D1C2A2B05E0F37"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-12-17T18:05:14&#8243;,&#8221;description&#8221;:&#8221;## **Executive Summary**\\n\\nShadyPanda has exploited trusted browser extensions to compromise millions of users, illustrating how legitimate software can unexpectedly become harmful. Qualys TruRisk Eliminate empowers organizations to identify risky behaviors, prioritize real threats, and eliminate malicious components before attackers exploit them.\\n\\n## How Browser Extensions Have Become a New Blind Spot\\n\\nBrowser extensions are part of everyday work. We install them to save time, stay organized, or improve productivity. However, between 2024 and 2025, one threat actor exploited this trusted ecosystem to create a massive covert malware delivery mechanism that organizations no longer ignore. \\n\\nShadyPanda exploited a widespread misconception:\\n\\n_If an extension is verified, widely used, and looks safe, it must be trustworthy._\\n\\nThat assumption no longer holds.\\n\\n## **Understanding ShadyPanda: A Threat Built on Trust, Not Exploits**\\n\\nUnlike traditional cyberattacks that rely on phishing or zero-day vulnerabilities, ShadyPanda has established an operation built on patience, legitimacy, and a carefully crafted reputation. The group exploits trust within the browser extension ecosystem rather than targeting software flaws. \\n\\nResearchers have uncovered that ShadyPanda has been executing long-term browser supply chain attacks since 2018 by publishing seemingly harmless extensions. These include wallpapers, utilities, and new-tab tools designed to integrate seamlessly into everyday browser use while amassing high installation counts, positive user ratings, and a trusted status in the marketplace.\\n\\nOnce this trust was firmly established, ShadyPanda cleverly weaponized these extensions through updates, turning them into covert malware delivery mechanisms. These malicious updates enabled remote code execution (RCE) backdoors and large-scale spyware operations without raising traditional security alarms.\\n\\nExtensions such as **Clean Master** were operated legitimately for years to build a substantial user base across Chrome and Edge. Researchers estimate that **more than 4.3 million users across both browsers were affected** , underscoring the scale of the campaign. This was not opportunistic malware; it represented **an infrastructure-level compromise of the browser ecosystem itself**.\\n\\nThese malicious extensions are actively harvesting a wide range of sensitive browser data, including:\\n\\n  *  Browsing Activity\\n  * User Input and Search\\n  * Device Fingerprinting\\n  * Behavioral Biometrics\\n  * Identity \\u0026 Storage\\n\\n\\n\\nThis level of access empowers attackers to profile users, hijack sessions, and potentially infiltrate enterprise environments. Addressing this kind of risk requires more than trust signals or periodic controls. It requires the ability to identify, prioritize, and eliminate risk arising from legitimate software that has turned malicious. This is where Qualys TruRisk Eliminate comes in.\\n\\n## **How Qualys TruRisk Eliminate Helps Protect Against ShadyPanda-Like Threats**\\n\\nQualys TruRisk Eliminate delivers this capability by identifying risky behaviors, prioritizing them based on real threat context, and blocking or removing malicious components before they can be exploited.\\n\\nTo help organizations operationalize this approach, here is a high-level playbook on how to use TruRisk Eliminate to defend against ShadyPanda-like threats.\\n\\n### **Step 1 &#8211; Patch Automation for Chrome \\u0026 Edge**\\n\\nLeverage Zero-Touch Patch Automation with Qualys Patch Management to guarantee that all endpoints receive the latest secure browser versions with zero user delay. This proactive measure fortifies browser integrity and significantly minimizes exposure to threats originating from malicious extensions.\\n\\nWith Zero-Touch Patch Automation, you will: \\n\\n  * Automatically deploy the latest Chrome Stable and Edge Stable updates.\\n  * Effectively close exploited CVEs leveraged by malicious extensions.\\n  * Slash Mean Time to Resolution (MTTR) from days or weeks to just hours.\\n\\n![Dashboard view of Qualys Patch Management, configuring zero-touch automation for Chrome and Edge browsers.](https:\/\/ik.imagekit.io\/qualys\/wp-content\/uploads\/2025\/12\/Dashboard-View.png)\\n\\n### **Step 2- Use CAR Scripts for Eliminating Non-Default \/ Rogue Browser Extensions**\\n\\nLeverage Qualys Custom Assessment \\u0026 Remediation (CAR)  to deploy decisive scripts that will detect and remove any non-default or unauthorized Chrome\/Edge extensions.\\n\\n**With CAR Scripts, you can:**\\n\\n  * Identify all installed extensions (Chrome\/Edge) immediately.\\n  * Compare them rigorously against your approved extension list.\\n  * Eliminate any untrusted or malicious extensions without hesitation.\\n  * Execute a comprehensive organization-wide clean-up within minutes.\\n\\n\\n\\nCAR Scripts also enables you to remove all passwords stored in Chrome, Edge, or Firefox directly using PowerShell. Import the script from the Library and proceed confidently with your actions.\\n\\n![Qualys CAR script execution interface showing detection and removal of unauthorized browser extensions.](https:\/\/ik.imagekit.io\/qualys\/wp-content\/uploads\/2025\/12\/Qualys-Car-Script.png)\\n\\n## **Conclusion**\\n\\nShadyPanda exposes a critical shift in attacker strategy: weaponizing trusted software to infiltrate environments silently. Defending modern enterprises requires more than patching vulnerabilities. It demands behavioral intelligence and proactive risk elimination.\\n\\nQualys TruRisk Eliminate delivers these capabilities at scale, empowering teams to uncover malicious behaviors, block emerging threats, and remove compromised components before attackers gain a foothold.\\n\\n**_Go Beyond Patching with Qualys TruRisk Eliminate and de-risk cyber threats before they impact your business._**\\n\\n![Qualys TruRisk Eliminate](https:\/\/ik.imagekit.io\/qualys\/wp-content\/uploads\/2025\/12\/Qualys-TruRisk-Eliminate.png)\\n\\n* * *\\n\\n* * *\\n\\n## **Frequently Asked Questions (FAQs)**\\n\\n**What is ShadyPanda?  **\\n\\nShadyPanda is a significant threat campaign that exploits trusted browser extensions to deliver spyware and malicious functionality on a large scale. The attackers cleverly launched seemingly legitimate extensions, earning user trust, and then weaponized them through updates that affected millions of Chrome and Edge users.\\n\\n**Why are browser extensions a growing security risk?  **\\n\\nBrowser extensions possess extensive permissions and deep access to user activity. When a trusted extension turns malicious, it operates silently, collecting sensitive data, redirecting traffic, or executing scripts without relying on traditional vulnerabilities.\\n\\n**Did ShadyPanda exploit browser vulnerabilities or zero-days?**\\n\\nNo. ShadyPanda exploited trust and reputation rather than zero-day vulnerabilities. This campaign relied on legitimate distribution channels and behavior-based abuse, steering clear of specific CVEs.\\n\\n**Why isn\u2019t traditional CVE-based security enough for threats like ShadyPanda?**\\n\\nBecause ShadyPanda does not depend on exploitable vulnerabilities, it leverages normal extension functionality and updates. This reality underscores the urgent need for continuous visibility into software behavior, far exceeding simple vulnerability scanning.\\n\\n**How does Qualys TruRisk Eliminate address ShadyPanda-like threats?**\\n\\nQualys TruRisk Eliminate helps organizations to identify when legitimate software starts behaving maliciously, prioritize those risks using real threat context, and take decisive action to block or remove compromised components before they can be exploited.\\n\\n**Does Qualys TruRisk Eliminate scan browser stores or extension marketplaces?**\\n\\nNo. TruRisk Eliminate does not monitor browser marketplaces. It focuses on risk identification and elimination within your environment, relying on observed behavior, exposure, and threat context.\\n\\n**Can Qualys TruRisk Eliminate help reduce the impact of malicious browser updates?**\\n\\nAbsolutely. By delivering continuous visibility into software behavior and prioritizing risks based on tangible real-world context, Qualys TruRisk Eliminate equips organizations to respond swiftly when trusted components turn malicious, effectively reducing exposure and limiting impact.\\n\\n**Is patching still important for defending against extension-based threats?**\\n\\nCertainly, keeping browsers up to date is crucial for closing known vulnerabilities and fortifying the security foundation. Patch automation enhances risk-based detection by minimizing the overall attack surface.\\n\\n**What is the key lesson organizations should take away from ShadyPanda?**\\n\\nThe key lesson is that **trust is no longer a static concept**. Legitimate software can become a risk at any time, making continuous risk assessment and elimination essential to modern security strategies.&#8221;,&#8221;published&#8221;:&#8221;2025-12-17T18:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-17T18:00:00&#8243;,&#8221;type&#8221;:&#8221;qualysblog&#8221;,&#8221;title&#8221;:&#8221;ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;QUALYSBLOG:DFBA459B23CBBC98D1D1C2A2B05E0F37&#8243;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/blog.qualys.com\/category\/product-tech&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-12-17T18:05:14&#8243;,&#8221;description&#8221;:&#8221;## **Executive Summary**\\n\\nShadyPanda has exploited trusted browser extensions to compromise millions of users, illustrating how legitimate software can unexpectedly become harmful. Qualys TruRisk Eliminate empowers&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,13,33,120,7,11,5],"class_list":["post-31585","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-news","tag-none","tag-qualysblog","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It_QUALYSBLOG:DFBA459B23CBBC98D1D1C2A2B05E0F37 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=31585\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It_QUALYSBLOG:DFBA459B23CBBC98D1D1C2A2B05E0F37 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-12-17T18:05:14&#8243;,&#8221;description&#8221;:&#8221;## **Executive Summary**nnShadyPanda has exploited trusted browser extensions to compromise millions of users, illustrating how legitimate software can unexpectedly become harmful. Qualys TruRisk Eliminate empowers...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=31585\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-17T12:51:24+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31585#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31585\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It_QUALYSBLOG:DFBA459B23CBBC98D1D1C2A2B05E0F37\",\"datePublished\":\"2025-12-17T12:51:24+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31585\"},\"wordCount\":1365,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"news\",\"NONE\",\"qualysblog\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=31585#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31585\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31585\",\"name\":\"ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It_QUALYSBLOG:DFBA459B23CBBC98D1D1C2A2B05E0F37 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-12-17T12:51:24+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31585#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=31585\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31585#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It_QUALYSBLOG:DFBA459B23CBBC98D1D1C2A2B05E0F37\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It_QUALYSBLOG:DFBA459B23CBBC98D1D1C2A2B05E0F37 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=31585","og_locale":"en_US","og_type":"article","og_title":"ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It_QUALYSBLOG:DFBA459B23CBBC98D1D1C2A2B05E0F37 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-12-17T18:05:14&#8243;,&#8221;description&#8221;:&#8221;## **Executive Summary**nnShadyPanda has exploited trusted browser extensions to compromise millions of users, illustrating how legitimate software can unexpectedly become harmful. Qualys TruRisk Eliminate empowers...","og_url":"https:\/\/zero.redgem.net\/?p=31585","og_site_name":"zero redgem","article_published_time":"2025-12-17T12:51:24+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=31585#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=31585"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It_QUALYSBLOG:DFBA459B23CBBC98D1D1C2A2B05E0F37","datePublished":"2025-12-17T12:51:24+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=31585"},"wordCount":1365,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","news","NONE","qualysblog","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=31585#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=31585","url":"https:\/\/zero.redgem.net\/?p=31585","name":"ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It_QUALYSBLOG:DFBA459B23CBBC98D1D1C2A2B05E0F37 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-12-17T12:51:24+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=31585#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=31585"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=31585#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It_QUALYSBLOG:DFBA459B23CBBC98D1D1C2A2B05E0F37"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/31585","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=31585"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/31585\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=31585"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=31585"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=31585"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}