Visualização normal

Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • Malicious Browser Extensions Drain Crypto Wallets Do Son
    Socket found 19 malicious browser extensions acting as a crypto wallet drainer across Chrome and Edge, exposing up to 80,000 users in one case. Related Posts: PackClient RAT: New C2 Framework Sold on Telegram Amatera Password Stealer Abuses Service Workers and Smart Contracts Miraak Post Exploitation Framework Adopts Database C2 The post Malicious Browser Extensions Drain Crypto Wallets appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Chrome Manifest V2 Removal: Legacy Extensions Are Now Gone Do Son
    The Chrome Manifest V2 removal is complete: Google has purged all legacy MV2 extensions from the Web Store, the final step of its MV3 migration. Related Posts: Darwin-VM Enables Apple Silicon Security Research Apple OpenAI Lawsuit Escalates Over AI Trade Secrets Anthropic Bolsters Security After Claude AI Escapes The post Chrome Manifest V2 Removal: Legacy Extensions Are Now Gone appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • 77 Malicious Firefox Extensions Steal Crypto Wallet Secrets and Credentials Do Son
    Socket tracked 77 malicious Firefox extensions that steal crypto wallet secrets and credentials. See how the Offside Wallet Theft Factory works. Related Posts: Grandoreiro Banking Trojan Returns With a DLL Sideloading Campaign Clop Deploys Custom Web Shell in PTC Windchill Extortion Attacks WordlistLoader Delivers Amatera Stealer Through ClearFake Campaigns The post 77 Malicious Firefox Extensions Steal Crypto Wallet Secrets and Credentials appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Windows 11 Tests Customizable Right-Click Context Menu to Cut App Clutter Do Son
    Microsoft is testing a customizable right-click context menu in Windows 11, letting users collapse app extensions and restore classic menu styling. Related Posts: Microsoft 365 on Windows 10 Enters Feature Freeze as Microsoft Pushes Windows 11 Upgrades Microsoft Defender Causes VLC Playback Issues Impending End of Support for Windows 10 LTSC 2021 The post Windows 11 Tests Customizable Right-Click Context Menu to Cut App Clutter appeared first on Daily CyberSecurity.
     

77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data

10 de Agosto de 2026, 11:52

Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to supply-chain risk.

The post 77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data appeared first on TechRepublic.

Chrome to Block Policy-Abusing Extensions on Personal Devices

4 de Agosto de 2026, 11:43

Google is developing Chrome protections that could block policy-installed extensions from hijacking New Tab pages and search settings on personal devices.

The post Chrome to Block Policy-Abusing Extensions on Personal Devices appeared first on TechRepublic.

82 Chrome Extensions Found Selling User Data, 6.5 Million Users Affected

LayerX research finds 82 Chrome extensions collecting and selling user data, affecting at least 6.5 million users through disclosed but concerning practices.
  • ✇Arstechnica
  • Browser extensions turn nearly 1 million browsers into website-scraping bots Dan Goodin
    Extensions installed on almost 1 million devices have been overriding key security protections to turn browsers into engines that scrape websites on behalf of a paid service, a researcher said. The 245 extensions, available for Chrome, Firefox, and Edge, have racked up nearly 909,000 downloads, John Tuckner of SecurityAnnex reported. The extensions serve a wide range of purposes, including managing bookmarks and clipboards, boosting speaker volumes, and generating random numbers. The common thre
     

Browser extensions turn nearly 1 million browsers into website-scraping bots

9 de Julho de 2025, 17:08

Extensions installed on almost 1 million devices have been overriding key security protections to turn browsers into engines that scrape websites on behalf of a paid service, a researcher said.

The 245 extensions, available for Chrome, Firefox, and Edge, have racked up nearly 909,000 downloads, John Tuckner of SecurityAnnex reported. The extensions serve a wide range of purposes, including managing bookmarks and clipboards, boosting speaker volumes, and generating random numbers. The common thread among all of them: They incorporate MellowTel-js, an open source JavaScript library that allows developers to monetize their extensions.

Intentional weakening of browsing protections

Tuckner and critics say the monetization works by using the browser extensions to scrape websites on behalf of paying customers, which include AI startups, according to MellowTel founder Arsian Ali. Tuckner reached this conclusion after uncovering close ties between MellowTel and Olostep, a company that bills itself as "the world's most reliable and cost-effective Web scraping API." Olostep says its service “avoids all bot detection and can parallelize up to 100K requests in minutes.” Paying customers submit the locations of browsers they want to access specific webpages. Olostep then uses its installed base of extension users to fulfill the request.

Read full article

Comments

  • ✇Arstechnica
  • Time to check if you ran any of these 33 malicious Chrome extensions Dan Goodin
    As many of us celebrated the year-end holidays, a small group of researchers worked overtime tracking a startling discovery: At least 33 browser extensions hosted in Google’s Chrome Web Store, some for as long as 18 months, were surreptitiously siphoning sensitive data from roughly 2.6 million devices. The compromises came to light with the discovery by data loss prevention service Cyberhaven that a Chrome extension used by 400,000 of its customers had been updated with code that stole their sen
     

Time to check if you ran any of these 33 malicious Chrome extensions

3 de Janeiro de 2025, 09:15

As many of us celebrated the year-end holidays, a small group of researchers worked overtime tracking a startling discovery: At least 33 browser extensions hosted in Google’s Chrome Web Store, some for as long as 18 months, were surreptitiously siphoning sensitive data from roughly 2.6 million devices.

The compromises came to light with the discovery by data loss prevention service Cyberhaven that a Chrome extension used by 400,000 of its customers had been updated with code that stole their sensitive data.

’Twas the night before Christmas

The malicious extension, available as version 24.10.4, was available for 31 hours, from December 25 at 1:32 AM UTC to Dec 26 at 2:50 AM UTC. Chrome browsers actively running Cyberhaven during that window would automatically download and install the malicious code. Cyberhaven responded by issuing version 24.10.5, and 24.10.6 a few days later.

Read full article

Comments

© Getty Images

❌
❌