• Home
  • About Us
  • Services
    • Global Risk Intelligence
    • Trust & Safety
  • Resources
  • Contact Us
  • Home
  • About Us
  • Services
    • Global Risk Intelligence
    • Trust & Safety
  • Resources
  • Contact Us
Home Global Current Affairs

Hackers Infiltrate Chrome Extensions December

Arpita Roy by Arpita Roy
December 30, 2024
in Global Current Affairs
Reading Time: 2 mins read
2
Hackers Infiltrate Chrome Extensions December
25
VIEWS
Share on FacebookShare on TwitterLinkedinWhatsapp

According to the reports on Monday (30 December), hackers successfully infiltrated several Chrome extensions in December by injecting malicious code through compromised admin accounts, gained via phishing attacks. Cyberhaven revealed its Chrome extension was breached on December 24, specifically targeting Facebook Ads users. Other impacted extensions include ParrotTalks, Uvoice, and VPNCity, as reported by Nudge Security.

The attackers aimed to steal sensitive user data, such as access tokens, user IDs, cookies, and login credentials for specific platforms. Cyberhaven’s analysis uncovered that the malicious code included a mouse click listener, enabling attackers to assist with bypassing two-factor authentication (2FA) using stored user IDs.

Cyberhaven detected the breach on December 25 and quickly removed the malicious version of its extension within an hour. The company released a clean version and informed customers on December 26, advising them to revoke and rotate credentials. Prompt action was recommended to prevent further exploitation of stolen data.

This incident highlights the importance of cybersecurity for browser extensions and user accounts. Users are advised to stay vigilant by keeping software updated and rotating passwords frequently. Cyberhaven’s response serves as a reminder for companies to act swiftly to minimize the impact of such breaches.

References

  • Hackers Exploit Chrome Extensions with Phishing Attacks Targeting User Data
  • Hackers Hijacked 16 Chrome Extensions to Inject Malicious Code
Tags: 2FAChromeCurrent AffairsCyber IncidentsCyber Incidents 2024Cyber SecurityCyber ThreatCyberhavenFacebookGoogle ChromeHackersNudge SecurityOSINTopediaParrotTalkstwo-factor authenticationUvoiceVPNCity
Arpita Roy

Arpita Roy

A Master’s of Business Administration holder, with a diploma in Interior Designing, and over 10 years of corporate experience in various fields (including Sales, Real Estate, Content Writing, Management, Global Risk Intel, and Operations). Skilled in the field of sales and all types of Internet-based Open Source and Web Intelligence.

Comments 2

  1. tlovertonet says:
    1 year ago

    Some genuinely wonderful blog posts on this site, appreciate it for contribution.

    Reply
  2. registrati su binance says:
    11 months ago

    Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

New York
London
Tel Aviv
Sydney
New Delhi

Mitigating Threats! Intelligence on the Go…

Facebook Twitter Instagram Whatsapp Linkedin Youtube

Company

  • Terms & Conditions
  • Privacy Policy
  • Contact Us

OSINTopedia Infotech Private Limited

Registered under MCA 

contact@osintopedia.com

  • 24.869814, 92.355049

Copyright © 2023   osintopedia.com | Powered by osintopedia.com

OSINTopedia
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
New Letter

hi this is just a sample plz ignore this popup