home.social

#cyberhaven — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyberhaven, aggregated by home.social.

  1. Regarding the recent Cyberhaven related Chrome plugin compromises, was a threat actor ever identified?

    I have searched and have not found any attribution.

    #cyberhaven #iran #foxkitten #chrome #incidentresponse #threatactor #threatintel

  2. Isn’t this a way to mitigate 0-day vulnerabilities? Enable auto-update for your browser? #cyberhaven #phishing #google #googlechrome

    OneLogin had a similar incident a few months ago where an inadvertent Chrome browser extension update took out their entire SSO service for almost two days. At one point they had “all OneLogin engineers working on it”

    Seems insane that both attack vectors were related to something most people don’t even use or care about: browser extensions. If you haven’t already, do an audit/cleanup of your browser extensions 😅

    Something I learned a while ago was most (if not all) technology service interruptions are either one of two things (or both): a failed process, or human error. Seems like this (and the OneLogin outage) were the latter 😑 🤦‍♂️

  3. Isn’t this a way to mitigate 0-day vulnerabilities? Enable auto-update for your browser? #cyberhaven #phishing #google #googlechrome

    OneLogin had a similar incident a few months ago where an inadvertent Chrome browser extension update took out their entire SSO service for almost two days. At one point they had “all OneLogin engineers working on it”

    Seems insane that both attack vectors were related to something most people don’t even use or care about: browser extensions. If you haven’t already, do an audit/cleanup of your browser extensions 😅

    Something I learned a while ago was most (if not all) technology service interruptions are either one of two things (or both): a failed process, or human error. Seems like this (and the OneLogin outage) were the latter 😑 🤦‍♂️

  4. Did you think the "Featured" badge on Chrome Web Store means the browser extension is reasonably secure to install? Well, it didn't stop the 200k users of YesCaptcha assistant from getting infected in the #Cyberhaven incident.

    "34 Popular Chrome extensions impacting over 2.6 million users were found to be compromised and manipulated to exfil cookies and user passwords and other data from the browser. Many of the extensions are still live." extensiontotal.com/cyberhaven-

    #Chrome #browser #malware

  5. Did you think the "Featured" badge on Chrome Web Store means the browser extension is reasonably secure to install? Well, it didn't stop the 200k users of YesCaptcha assistant from getting infected in the #Cyberhaven incident.

    "34 Popular Chrome extensions impacting over 2.6 million users were found to be compromised and manipulated to exfil cookies and user passwords and other data from the browser. Many of the extensions are still live." extensiontotal.com/cyberhaven-

    #Chrome #browser #malware

  6. Did you think the "Featured" badge on Chrome Web Store means the browser extension is reasonably secure to install? Well, it didn't stop the 200k users of YesCaptcha assistant from getting infected in the incident.

    "34 Popular Chrome extensions impacting over 2.6 million users were found to be compromised and manipulated to exfil cookies and user passwords and other data from the browser. Many of the extensions are still live." extensiontotal.com/cyberhaven-

  7. Did you think the "Featured" badge on Chrome Web Store means the browser extension is reasonably secure to install? Well, it didn't stop the 200k users of YesCaptcha assistant from getting infected in the #Cyberhaven incident.

    "34 Popular Chrome extensions impacting over 2.6 million users were found to be compromised and manipulated to exfil cookies and user passwords and other data from the browser. Many of the extensions are still live." extensiontotal.com/cyberhaven-

    #Chrome #browser #malware

  8. Did you think the "Featured" badge on Chrome Web Store means the browser extension is reasonably secure to install? Well, it didn't stop the 200k users of YesCaptcha assistant from getting infected in the #Cyberhaven incident.

    "34 Popular Chrome extensions impacting over 2.6 million users were found to be compromised and manipulated to exfil cookies and user passwords and other data from the browser. Many of the extensions are still live." extensiontotal.com/cyberhaven-

    #Chrome #browser #malware

  9. La firme de cybersécurité Cyberhaven se fait pirater son extension Chrome dlvr.it/TH4jx0 #cybersécurité #Cyberhaven

  10. La firme de cybersécurité Cyberhaven se fait pirater son extension Chrome dlvr.it/TH4jx0 #cybersécurité #Cyberhaven

  11. La firme de cybersécurité Cyberhaven se fait pirater son extension Chrome dlvr.it/TH4jx0 #cybersécurité #Cyberhaven

  12. La firme de cybersécurité Cyberhaven se fait pirater son extension Chrome dlvr.it/TH4jx0 #cybersécurité #Cyberhaven

  13. La firme de cybersécurité Cyberhaven se fait pirater son extension Chrome dlvr.it/TH4jx0 #cybersécurité #Cyberhaven

  14. I happen to be talking about , which is kind of a hot topic right now - thanks to this incident on the browser extension: medium.com/extensiontotal/when