Socket found 19 malicious browser extensions acting as a crypto wallet drainer across Chrome and Edge, exposing up to 80,000 users in one case.
Related Posts:
PackClient RAT: New C2 Framework Sold on Telegram
Amatera Password Stealer Abuses Service Workers and Smart Contracts
Miraak Post Exploitation Framework Adopts Database C2
The post Malicious Browser Extensions Drain Crypto Wallets appeared first on Daily CyberSecurity.
The Chrome Manifest V2 removal is complete: Google has purged all legacy MV2 extensions from the Web Store, the final step of its MV3 migration.
Related Posts:
Darwin-VM Enables Apple Silicon Security Research
Apple OpenAI Lawsuit Escalates Over AI Trade Secrets
Anthropic Bolsters Security After Claude AI Escapes
The post Chrome Manifest V2 Removal: Legacy Extensions Are Now Gone appeared first on Daily CyberSecurity.
Socket tracked 77 malicious Firefox extensions that steal crypto wallet secrets and credentials. See how the Offside Wallet Theft Factory works.
Related Posts:
Grandoreiro Banking Trojan Returns With a DLL Sideloading Campaign
Clop Deploys Custom Web Shell in PTC Windchill Extortion Attacks
WordlistLoader Delivers Amatera Stealer Through ClearFake Campaigns
The post 77 Malicious Firefox Extensions Steal Crypto Wallet Secrets and Credentials appeared first on Daily CyberSecurity.
Microsoft is testing a customizable right-click context menu in Windows 11, letting users collapse app extensions and restore classic menu styling.
Related Posts:
Microsoft 365 on Windows 10 Enters Feature Freeze as Microsoft Pushes Windows 11 Upgrades
Microsoft Defender Causes VLC Playback Issues
Impending End of Support for Windows 10 LTSC 2021
The post Windows 11 Tests Customizable Right-Click Context Menu to Cut App Clutter appeared first on Daily CyberSecurity.
Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to supply-chain risk.
The post 77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data appeared first on TechRepublic.
Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to supply-chain risk.
Google is developing Chrome protections that could block policy-installed extensions from hijacking New Tab pages and search settings on personal devices.
The post Chrome to Block Policy-Abusing Extensions on Personal Devices appeared first on TechRepublic.
Google is developing Chrome protections that could block policy-installed extensions from hijacking New Tab pages and search settings on personal devices.
Researchers say a Claude for Chrome flaw lets rogue extensions trigger Gmail, Docs, and Calendar tasks, with greater risk in unattended mode.
The post Claude for Chrome Flaw Puts Gmail at Risk From Rogue Extensions appeared first on TechRepublic.
Microsoft found a fake Perplexity AI Chrome extension that rerouted searches through attacker servers. Here’s what users should check now.
The post Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features appeared first on TechRepublic.
LayerX research finds 82 Chrome extensions collecting and selling user data, affecting at least 6.5 million users through disclosed but concerning practices.
LayerX research finds 82 Chrome extensions collecting and selling user data, affecting at least 6.5 million users through disclosed but concerning practices.
How many browsers extensions do you have running? Most enterprise users have at least one and seven out of ten have seen an extension expand its permissions over the last 12 months—with AI extensions being the worst offenders…by sixfold.
The post Over Permissive and Proliferating, AI-Driven Browser Extensions Create Security Blindspots appeared first on Security Boulevard.
How many browsers extensions do you have running? Most enterprise users have at least one and seven out of ten have seen an extension expand its permissions over the last 12 months—with AI extensions being the worst offenders…by sixfold.
Extensions installed on almost 1 million devices have been overriding key security protections to turn browsers into engines that scrape websites on behalf of a paid service, a researcher said.
The 245 extensions, available for Chrome, Firefox, and Edge, have racked up nearly 909,000 downloads, John Tuckner of SecurityAnnex reported. The extensions serve a wide range of purposes, including managing bookmarks and clipboards, boosting speaker volumes, and generating random numbers. The common thre
Extensions installed on almost 1 million devices have been overriding key security protections to turn browsers into engines that scrape websites on behalf of a paid service, a researcher said.
The 245 extensions, available for Chrome, Firefox, and Edge, have racked up nearly 909,000 downloads, John Tuckner of SecurityAnnex reported. The extensions serve a wide range of purposes, including managing bookmarks and clipboards, boosting speaker volumes, and generating random numbers. The common thread among all of them: They incorporate MellowTel-js, an open source JavaScript library that allows developers to monetize their extensions.
Intentional weakening of browsing protections
Tuckner and critics say the monetization works by using the browser extensions to scrape websites on behalf of paying customers, which include AI startups, according to MellowTel founder Arsian Ali. Tuckner reached this conclusion after uncovering close ties between MellowTel and Olostep, a company that bills itself as "the world's most reliable and cost-effective Web scraping API." Olostep says its service “avoids all bot detection and can parallelize up to 100K requests in minutes.” Paying customers submit the locations of browsers they want to access specific webpages. Olostep then uses its installed base of extension users to fulfill the request.
As many of us celebrated the year-end holidays, a small group of researchers worked overtime tracking a startling discovery: At least 33 browser extensions hosted in Google’s Chrome Web Store, some for as long as 18 months, were surreptitiously siphoning sensitive data from roughly 2.6 million devices.
The compromises came to light with the discovery by data loss prevention service Cyberhaven that a Chrome extension used by 400,000 of its customers had been updated with code that stole their sen
As many of us celebrated the year-end holidays, a small group of researchers worked overtime tracking a startling discovery: At least 33 browser extensions hosted in Google’s Chrome Web Store, some for as long as 18 months, were surreptitiously siphoning sensitive data from roughly 2.6 million devices.
The compromises came to light with the discovery by data loss prevention service Cyberhaven that a Chrome extension used by 400,000 of its customers had been updated with code that stole their sensitive data.
’Twas the night before Christmas
The malicious extension, available as version 24.10.4, was available for 31 hours, from December 25 at 1:32 AM UTC to Dec 26 at 2:50 AM UTC. Chrome browsers actively running Cyberhaven during that window would automatically download and install the malicious code. Cyberhaven responded by issuing version 24.10.5, and 24.10.6 a few days later.