Hidden in Plain Sight: How we followed one malicious extension to uncover a multi-extension…

Hidden in Plain Sight: How we followed one malicious extension to uncover a multi-extension…

Hidden in Plain Sight: How we followed one malicious extension to uncover a multi-extension campaignShort read for everyone: we found a malicious Chrome extension that stole login data from a crypto trading ...
Passkeys Pwned: Turning WebAuth Against Itself

Passkeys Pwned: Turning WebAuth Against Itself

Passkeys Pwned: Turning WebAuthn Against ItselfFor years, passwords have been the default way we prove our identity online. However, they have also been at the center of countless breaches as a result of ...
The Hidden Dangers of Browser Extensions: Where Google’s MV3 Still Fall Short

The Hidden Dangers of Browser Extensions: Where Google’s MV3 Still Fall Short

A recent Forbes article by Davey Winder discussed a brilliant publication by Stanford researchers Sheryl Hsu, Manda Tran and Aurore Fass. It was discovered nearly 350 million Chrome extensions installed had privacy ...
A neon sign flashes, “BUY”

Google Hates Ad Blockers: Manifest V3 Push Starts Today

We warned you. As of June 3, Google is following through on its threat to kill ad blockers. Privacy-focused Chrome extensions are living on borrowed time; developers must upgrade to the less ...
Security Boulevard
A 3D button with the Mozilla Firefox logo

Google to Force-Block Ad Blockers — Time to Get Firefox?

Manifest V3: Destiny. Huge advertising monopoly flexes muscles: “Manifest V2” extensions to be nuked, but “V3” cripples ad blockers ...
Security Boulevard
Chrome Extensions Warning — Millions of Users Infected

Chrome Extensions Warning — Millions of Users Infected

Malware Déjà Vu: Perhaps as many as 87 million victims—maybe more ...
Security Boulevard
extensions

Chrome Web Store FAIL: 300+ More Scam Browser Extensions

A researcher has found yet more malware in Google’s store. Something’s obviously not working ...
Security Boulevard
49 crypto-wallet pickpocketing browser extensions booted from the Chrome web store

49 crypto-wallet pickpocketing browser extensions booted from the Chrome web store

Hackers have been using Google Ads to target unsuspecting cryptocurrency investors into installing malicious browser extensions, with the aim of stealing passphrases and private keys and draining funds from their wallets. Harry ...
OAuth, XSS, Google WhiteSource Log4j Deepfence threat report

New Service Scans Chrome Extensions for Vulnerabilities and Privacy Risks

Over the past few years, hackers have increasingly abused Google Chrome extensions to steal people’s data, inject rogue ads into websites or hijack CPU power to mine cryptocurrency. Now, a new online ...
Security Boulevard
Automatic 4K/HD for Youtube extension pulled from Chrome Store for pop-up ad abuse

Automatic 4K/HD for Youtube extension pulled from Chrome Store for pop-up ad abuse

A popular browser extension has been removed by Google from the Chrome Web Store after it started spamming users with irritating pop-up advertisements. The “Automatic 4K/HD for Youtube” extension, used by over ...