home.social

#browsersecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #browsersecurity, aggregated by home.social.

fetched live
  1. What are the best #private #browsers in 2026?
    privacytests.org/

    Looks pretty exhaustive, but there are some errors.

    I use @Vivaldi

    PS, duckduckgo is american, and that means it is less safe for #Canadians to use due to things like FISA, the CLOUD act and the NSA.

    #privacy #security #safety #onlinesafety #BrowserSecurity #browser

  2. Malware hides in browsers as ad fraud outpaces detection: Confiant finds malware built inside browsers as MCP drops sessions, Brazil bans deepfake ads, Amazon bots dodge origin queries, and Time sells ads to bots. ppc.land/malware-hides-in-brow #Malware #AdFraud #CyberSecurity #BrowserSecurity #DigitalMarketing

  3. Malware hides in browsers as ad fraud outpaces detection: Confiant finds malware built inside browsers as MCP drops sessions, Brazil bans deepfake ads, Amazon bots dodge origin queries, and Time sells ads to bots. ppc.land/malware-hides-in-brow #Malware #AdFraud #CyberSecurity #BrowserSecurity #DigitalMarketing

  4. Firefox 152.0.6 and Chrome 150.0.7871.124/.125 resolve CRITICAL flaws. Firefox bugs (CVE-2026-15718, CVE-2026-15719) have public exploits, but no in-the-wild attacks. Patch ASAP. Chrome fixes 15 issues. radar.offseq.com/threat/critic #OffSeq #Vuln #PatchNow #BrowserSecurity

  5. Firefox 152.0.6 and Chrome 150.0.7871.124/.125 resolve CRITICAL flaws. Firefox bugs (CVE-2026-15718, CVE-2026-15719) have public exploits, but no in-the-wild attacks. Patch ASAP. Chrome fixes 15 issues. radar.offseq.com/threat/critic #OffSeq #Vuln #PatchNow #BrowserSecurity

  6. As ClickFix and social engineering attacks are ever growing and evolving into new forms while remaining the same at their core, Opera took the security of their users into their own hands and released a feature called "Paste Protect" that is an integral part of their browser to protect users against ClickFix type of attacks.

    Firefox and Chrome should take Opera’s approach as an example and implement something similar, since the vast majority of the web browser market belongs to Chrome, followed by Safari and Firefox, which both use their own rendering engine that is not based on Chromium.

    #WebBrowsers #Opera #OperaBrowser #Chrome #Firefox #BrowserSecurity

  7. As ClickFix and social engineering attacks are ever growing and evolving into new forms while remaining the same at their core, Opera took the security of their users into their own hands and released a feature called "Paste Protect" that is an integral part of their browser to protect users against ClickFix type of attacks.

    Firefox and Chrome should take Opera’s approach as an example and implement something similar, since the vast majority of the web browser market belongs to Chrome, followed by Safari and Firefox, which both use their own rendering engine that is not based on Chromium.

    #WebBrowsers #Opera #OperaBrowser #Chrome #Firefox #BrowserSecurity

  8. CVE-2026-15130 (HIGH): Chrome <150.0.7871.115 has an insufficient policy enforcement bug, letting remote attackers bypass site isolation with crafted HTML. No exploits reported. Check radar.offseq.com/threat/cve-20 for updates. #OffSeq #Chrome #BrowserSecurity #Vulnerability

  9. To bring back Brave’s "forgetful browsing" (remove all site data when closing a tab), I'm now using this extension in Helium: chromewebstore.google.com/deta

    Seems to work as advertised 👍🏻

    #browsers #BrowserSecurity

  10. To bring back Brave’s "forgetful browsing" (remove all site data when closing a tab), I'm now using this extension in Helium: chromewebstore.google.com/deta

    Seems to work as advertised 👍🏻

    #browsers #BrowserSecurity

  11. CVE-2026-14423: Type confusion in Chrome (pre-150.0.7871.46) enables sandbox escape via crafted HTML. HIGH severity — update Chrome ASAP to patch. Details: radar.offseq.com/threat/cve-20 #OffSeq #Chrome #Vuln #BrowserSecurity

  12. 🔍 New analysis: an Italian phishing campaign abusing Chrome Native Messaging to escape browser sandbox restrictions.

    Attack chain:

    Invoice phishing → obfuscated JS → DLL sideloading → malicious Chrome extension → Native Messaging Host → PowerShell execution.

    Legitimate technologies chained together to turn Chrome into a backdoor.

    📌 d3lab.net/breaking-out-of-chro

    #ThreatIntelligence #Chrome #BrowserSecurity #MalwareAnalysis #CTI #CyberSecurity

  13. 🔍 New analysis: an Italian phishing campaign abusing Chrome Native Messaging to escape browser sandbox restrictions.

    Attack chain:

    Invoice phishing → obfuscated JS → DLL sideloading → malicious Chrome extension → Native Messaging Host → PowerShell execution.

    Legitimate technologies chained together to turn Chrome into a backdoor.

    📌 d3lab.net/breaking-out-of-chro

    #ThreatIntelligence #Chrome #BrowserSecurity #MalwareAnalysis #CTI #CyberSecurity

  14. 🛡️ Chrome & Firefox updates fix CRITICAL & HIGH memory safety vulns (use-after-free, memory corruption). Risk: RCE & sandbox escape. No active exploits. Update Chrome (>=149.0.7827.155/.156) & Firefox (>=152) ASAP! radar.offseq.com/threat/chrome #OffSeq #BrowserSecurity #Infosec

  15. CRITICAL: Browsers are now the front line for AI security. AI-driven phishing & shadow AI tool use evade blocklists, causing data leaks & account takeovers. No patch — deploy browser-layer telemetry for detection & control. radar.offseq.com/threat/why-th #OffSeq #AIsecurity #BrowserSecurity #Infosec

  16. FROST: Wie eine Browser-API zur Spionageschnittstelle wird

    Forscher der TU Graz haben gezeigt, dass Websites über eine Standard-Browserfunktion die SSD-Zugriffszeiten eines Nutzers messen und daraus ableiten können, welche Seiten er besucht und welche Anwendungen er öffnet – ohne jede Benutzerinteraktion und ohne dass der Nutzer es bemerkt.

    all-about-security.de/frost-wi

    #api #browsersecurity

  17. ChatGPT Exposes Users to Prompt Injection Attacks via Browser Content

    Researchers have uncovered a vulnerability in ChatGPT that leaves users open to prompt injection attacks, where malicious content is embedded into web pages and then summarized by the AI system as legitimate information. This loophole could put users at risk of falling prey to spoofed security alerts and other online…

    osintsights.com/chatgpt-expose

    #PromptInjectionAttacks #Chatgpt #AiSecurity #BrowserSecurity #EmergingThreats

  18. Oh, look! Yet another 🔒 "revolutionary" tool promising to keep your secrets safe by encrypting files right in your browser. Because nothing screams secure like trusting your sensitive data to a JavaScript cryptography carnival 🎪. Enjoy the thrill of zero uploads and endless settings tweaks while hoping no one ever breaches your fortress of browser-based solitude. 😂🔐
    secvant.com/ #browsersecurity #encryption #jokes #dataprivacy #techhumor #HackerNews #ngated

  19. Oh, look! Yet another 🔒 "revolutionary" tool promising to keep your secrets safe by encrypting files right in your browser. Because nothing screams secure like trusting your sensitive data to a JavaScript cryptography carnival 🎪. Enjoy the thrill of zero uploads and endless settings tweaks while hoping no one ever breaches your fortress of browser-based solitude. 😂🔐
    secvant.com/ #browsersecurity #encryption #jokes #dataprivacy #techhumor #HackerNews #ngated

  20. Google Exposes Unfixed Chromium Flaw Details

    A security researcher just blew the whistle on a glaring Chromium flaw that Google thought was fixed - but still works, putting tens of thousands of users at risk of a botnet attack. The exploit, first reported in 2022, allows malicious websites to remotely execute JavaScript on unsuspecting devices.

    osintsights.com/google-exposes

    #Chromium #ZeroDay #SupplyChain #EmergingThreats #BrowserSecurity

  21. Microsoft Alters Edge to Mitigate Password Exposure Risk

    Microsoft is taking a major step to boost password security in its Edge browser, rolling out a defense-in-depth change to mitigate the risk of password exposure. This update will be applied across all supported Edge versions, prioritizing a swift rollout to protect users.

    osintsights.com/microsoft-alte

    #BrowserSecurity #PasswordExposure #MicrosoftEdge #Defenseindepth #Proofofconcept

  22. Akamai Bolsters AI Browser Security with $205M LayerX Acquisition

    Akamai is taking browser security to the next level with its $205 million acquisition of LayerX, a cutting-edge startup that's changing the game with its innovative approach to securing interactions between users and applications. By integrating LayerX's technology, Akamai is bolstering its security stack to protect the…

    osintsights.com/akamai-bolster

    #BrowserSecurity #Ai #ZeroTrustNetworkArchitecture #Microsegmentation #Ztna

  23. Claude AI Extension Flaw Enables Cross-Plugin Hijacking

    A security flaw in the Claude AI Chrome extension could put users at risk, as it allows other browser extensions to issue commands to Claude without verification. This vulnerability creates a backdoor for hackers to hijack the AI model, warns LayerX senior researcher Aviad Gispan.

    osintsights.com/claude-ai-exte

    #ClaudeAiExtensionFlaw #CrosspluginHijacking #BrowserSecurity #Vulnerability #Llm

  24. 📚🚀 Oh, how dare a webpage reveal that your browser's been gossiping all along! 🤭 Thanks, Rise Up Labs, for informing us—without asking—about the sky we missed while we were busy staring at this digital snoop-fest, Vol. IV. Bravo, Matt, for teaching us that our devices are blabbermouths, one millisecond at a time. 😂👏
    sinceyouarrived.world/taken #digitalprivacy #browsersecurity #techhumor #dataawareness #RiseUpLabs #HackerNews #ngated

  25. 📚🚀 Oh, how dare a webpage reveal that your browser's been gossiping all along! 🤭 Thanks, Rise Up Labs, for informing us—without asking—about the sky we missed while we were busy staring at this digital snoop-fest, Vol. IV. Bravo, Matt, for teaching us that our devices are blabbermouths, one millisecond at a time. 😂👏
    sinceyouarrived.world/taken #digitalprivacy #browsersecurity #techhumor #dataawareness #RiseUpLabs #HackerNews #ngated

  26. Microsoft Edge Exposes Saved Passwords in Plaintext

    Microsoft Edge's password management has a concerning vulnerability: it loads all saved passwords into browser memory in plaintext at startup, making it easier for hackers to steal credentials on compromised systems. This is in stark contrast to other Chromium-based browsers like Google Chrome and Brave, which only decrypt…

    osintsights.com/microsoft-edge

    #BrowserSecurity #CredentialTheft #PlaintextPasswords #MicrosoftEdge #ChromiumbasedBrowsers

  27. Microsoft Edge Exposes Saved Passwords in Cleartext

    Storing passwords in plain text poses a significant risk, especially in shared environments, as a security researcher recently discovered that Microsoft Edge saves decrypted credentials in its memory, making them vulnerable to exposure. This flaw allows saved passwords to be accessible even when they're not in use.

    osintsights.com/microsoft-edge

    #BrowserSecurity #MicrosoftEdge #PasswordExposure #CleartextStorage #EmergingThreats

  28. ⚠️ Extensions hijack sessions instead of just stealing data At least 12 fake #TikTok downloader extensions inject scripts to capture Facebook session cookies, enabling full account takeover without credentials across Chrome and Edge installs. #ransomNews #BrowserSecurity #SessionHijacking

  29. New by me: Secure Browsers Push Zero Trust Past the Login Screen

    I wrote about why secure browsers matter beyond just getting a user signed in. If modern work happens in the browser, then trust decisions, session controls, and data protections need to keep happening there too.

    kylereddoch.me/blog/secure-bro

    #Cybersecurity #Infosec #ZeroTrust #BrowserSecurity

  30. 😆 Oh, the irony! To learn about cutting-edge defense innovation, please enable JavaScript—because, clearly, the true fortresses of the modern age are browser settings. 🔒🍪
    israeltechinsider.com/p/inside #defenseinnovation #browsersecurity #irony #moderntech #HackerNews #ngated

  31. Best Browser for Privacy and Security

    Online privacy matters. Choosing the right browser can help protect your personal data and browsing activity.

    #privacy #cybersecurity #browsersecurity #infosec #internet