Zum Inhalt der Seite gehen

Suche

Beiträge, die mit CHROME getaggt sind


16 Chrome Extensions attacked in Large-Scale Credential Theft Scheme.

A attack campaign has compromised at least 16 Chrome browser extensions, exposing over 600k users to data & credential theft. This targeted extension publishers through phishing emails that mimicked official communications from the Chrome Web Store.

https://www.cyberhaven.com/blog/cyberhavens-chrome-extension-security-incident-and-what-were-doing-about-it

#google #chrome #it #security #privacy #engineer #media #tech #news
Cyberhaven, a IT-security firm specializing in data loss prevention, was among the impacted firms and the first to publicly disclose its compromise. The attack occurred on December 24 and involved phishing a company employee to gain access to their Chrome Web Store admin credentials. 

According to Cyberhaven, the attackers compromised the “single admin account for the Google Chrome Store” and managed to publish a malicious update to their popular Chrome extension. This update, deployed on Christmas Day, was designed to steal sensitive user data, including passwords, session tokens, Facebook account credentials and cookies.

The malicious extension, version 24.10.4, remained active for over 31 hours before being detected and removed from the Chrome Web Store. “Our security team detected this compromise at 11:54 PM UTC on December 25 and removed the malicious package within 60 minutes,” the company’s disclosure read.

Cyberhaven immediately released a legitimate update (version 24.10.5), hired Mandiant to develop an incident response plan and also notified federal law enforcement agencies for investigation. The company has confirmed that its systems, including CI/CD processes and code signing keys, were not compromised.


"Hackers have compromised several different companies' Chrome browser extensions in a series of intrusions dating back to mid-December, according to one of the victims and experts who have examined the campaign.

Among the victims was the California-based Cyberhaven, a data protection company that confirmed the breach in a statement to Reuters on Friday.

"Cyberhaven can confirm that a malicious cyberattack occurred on Christmas Eve, affecting our Chrome extension," the statement said. It cited public comments from cybersecurity experts. These comments, said Cyberhaven, suggested that the attack was "part of a wider campaign to target Chrome extension developers across a wide range of companies."

Cyberhaven added: "We are actively cooperating with federal law enforcement.""

https://www.reuters.com/technology/cybersecurity/data-loss-prevention-company-cyberhaven-hit-by-breach-statement-says-2024-12-27/

#CyberSecurity #GoogleChrome #Chrome #Cyberhaven


I used to trust #Microsoft more than other #bigtech platforms, mostly because I used #Excel a lot in my work.

I switched from #Chrome to #EdgeBrowser a long time ago for work (and use #Vivaldi for private stuff).

However I just had to set up my work profile in Edge again today, and Microsoft's #consent for #tracking has really gone to shit.

Look what they consider to now be 'Always Active' (i.e. not requiring consent):

[picture]Thread 1/3

#surveillancecapitalism #surveillanceadvertising


How to set up a mimimal/blank new tab page on Ungoogled Chromium that conforms to your system’s dark mode setting:

https://github.com/ungoogled-software/ungoogled-chromium/issues/1675#issuecomment-2490597528

PS. You can install Ungoogled Chromium easily on macOS using Homebrew:

```shell
brew install --cask eloston-chromium
```

For more macOS setup/configuration tips see my quick gist:

https://codeberg.org/aral/gists/src/branch/main/mac-setup.md

#ungoogledChromium #chromium #chrome #minimal #newTabPage #aesthetics #accessibility #privacy #configuration #web


#Google must sell #Chrome to end search monopoly, justice department argues in court filing

https://www.theguardian.com/technology/2024/nov/21/google-sell-chrome-us-court-filing-demand-competition-laws
Justice department urges court to force Google to share data with rivals as part of wide-ranging changes to end online giant’s monopoly on web searching


Tiens, un publi-reportage. Les chiens de garde vont avoir du travail avec cette affaire.
.
.
.
.
[Numerama] - Forcer #Google à vendre #Chrome est complètement absurde.

https://www.numerama.com/tech/1848088-forcer-google-a-vendre-chrome-est-completement-absurde.html

#GAFAM #lobbies
#RevueDePresse #Press


For those who want to read sites in Russian, Arabic, Spanish, French, German and many other languages.

@Theaitetos (Рцяэыоод) Extension for full-page translation, translates reasonably well.
Set up hotkey (F1...F12) for full-page translation.
#translation #extensions for #firefox or #chrome