home.social

#cyberhaven — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyberhaven, aggregated by home.social.

fetched live
  1. Regarding the recent Cyberhaven related Chrome plugin compromises, was a threat actor ever identified?

    I have searched and have not found any attribution.

    #cyberhaven #iran #foxkitten #chrome #incidentresponse #threatactor #threatintel

  2. Isn’t this a way to mitigate 0-day vulnerabilities? Enable auto-update for your browser? #cyberhaven #phishing #google #googlechrome

    OneLogin had a similar incident a few months ago where an inadvertent Chrome browser extension update took out their entire SSO service for almost two days. At one point they had “all OneLogin engineers working on it”

    Seems insane that both attack vectors were related to something most people don’t even use or care about: browser extensions. If you haven’t already, do an audit/cleanup of your browser extensions 😅

    Something I learned a while ago was most (if not all) technology service interruptions are either one of two things (or both): a failed process, or human error. Seems like this (and the OneLogin outage) were the latter 😑 🤦‍♂️

  3. Isn’t this a way to mitigate 0-day vulnerabilities? Enable auto-update for your browser? #cyberhaven #phishing #google #googlechrome

    OneLogin had a similar incident a few months ago where an inadvertent Chrome browser extension update took out their entire SSO service for almost two days. At one point they had “all OneLogin engineers working on it”

    Seems insane that both attack vectors were related to something most people don’t even use or care about: browser extensions. If you haven’t already, do an audit/cleanup of your browser extensions 😅

    Something I learned a while ago was most (if not all) technology service interruptions are either one of two things (or both): a failed process, or human error. Seems like this (and the OneLogin outage) were the latter 😑 🤦‍♂️

  4. Did you think the "Featured" badge on Chrome Web Store means the browser extension is reasonably secure to install? Well, it didn't stop the 200k users of YesCaptcha assistant from getting infected in the incident.

    "34 Popular Chrome extensions impacting over 2.6 million users were found to be compromised and manipulated to exfil cookies and user passwords and other data from the browser. Many of the extensions are still live." extensiontotal.com/cyberhaven-

  5. Did you think the "Featured" badge on Chrome Web Store means the browser extension is reasonably secure to install? Well, it didn't stop the 200k users of YesCaptcha assistant from getting infected in the #Cyberhaven incident.

    "34 Popular Chrome extensions impacting over 2.6 million users were found to be compromised and manipulated to exfil cookies and user passwords and other data from the browser. Many of the extensions are still live." extensiontotal.com/cyberhaven-

    #Chrome #browser #malware

  6. Did you think the "Featured" badge on Chrome Web Store means the browser extension is reasonably secure to install? Well, it didn't stop the 200k users of YesCaptcha assistant from getting infected in the #Cyberhaven incident.

    "34 Popular Chrome extensions impacting over 2.6 million users were found to be compromised and manipulated to exfil cookies and user passwords and other data from the browser. Many of the extensions are still live." extensiontotal.com/cyberhaven-

    #Chrome #browser #malware

  7. Did you think the "Featured" badge on Chrome Web Store means the browser extension is reasonably secure to install? Well, it didn't stop the 200k users of YesCaptcha assistant from getting infected in the #Cyberhaven incident.

    "34 Popular Chrome extensions impacting over 2.6 million users were found to be compromised and manipulated to exfil cookies and user passwords and other data from the browser. Many of the extensions are still live." extensiontotal.com/cyberhaven-

    #Chrome #browser #malware

  8. Did you think the "Featured" badge on Chrome Web Store means the browser extension is reasonably secure to install? Well, it didn't stop the 200k users of YesCaptcha assistant from getting infected in the #Cyberhaven incident.

    "34 Popular Chrome extensions impacting over 2.6 million users were found to be compromised and manipulated to exfil cookies and user passwords and other data from the browser. Many of the extensions are still live." extensiontotal.com/cyberhaven-

    #Chrome #browser #malware

  9. La firme de cybersécurité Cyberhaven se fait pirater son extension Chrome dlvr.it/TH4jx0 #cybersécurité #Cyberhaven

  10. La firme de cybersécurité Cyberhaven se fait pirater son extension Chrome dlvr.it/TH4jx0 #cybersécurité #Cyberhaven

  11. La firme de cybersécurité Cyberhaven se fait pirater son extension Chrome dlvr.it/TH4jx0 #cybersécurité #Cyberhaven

  12. La firme de cybersécurité Cyberhaven se fait pirater son extension Chrome dlvr.it/TH4jx0 #cybersécurité #Cyberhaven

  13. La firme de cybersécurité Cyberhaven se fait pirater son extension Chrome dlvr.it/TH4jx0 #cybersécurité #Cyberhaven

  14. I happen to be talking about , which is kind of a hot topic right now - thanks to this incident on the browser extension: medium.com/extensiontotal/when

  15. #Cyberhaven has revealed their Chrome extension was briefly compromised

    Cyberhaven alerted its customers of the breach on Dec 24, 2024. Their admin account for the Chrome store was compromised through phishing, and the attackers published an extension that stole sensitive info from users.

    Users are advised to update to latest Cyberhaven Chrome extension, and to rotate credentials

    #cybersecurity

    bleepingcomputer.com/news/secu

  16. "Hackers have compromised several different companies' Chrome browser extensions in a series of intrusions dating back to mid-December, according to one of the victims and experts who have examined the campaign.

    Among the victims was the California-based Cyberhaven, a data protection company that confirmed the breach in a statement to Reuters on Friday.

    "Cyberhaven can confirm that a malicious cyberattack occurred on Christmas Eve, affecting our Chrome extension," the statement said. It cited public comments from cybersecurity experts. These comments, said Cyberhaven, suggested that the attack was "part of a wider campaign to target Chrome extension developers across a wide range of companies."

    Cyberhaven added: "We are actively cooperating with federal law enforcement.""

    reuters.com/technology/cyberse

    #CyberSecurity #GoogleChrome #Chrome #Cyberhaven

  17. "Hackers have compromised several different companies' Chrome browser extensions in a series of intrusions dating back to mid-December, according to one of the victims and experts who have examined the campaign.

    Among the victims was the California-based Cyberhaven, a data protection company that confirmed the breach in a statement to Reuters on Friday.

    "Cyberhaven can confirm that a malicious cyberattack occurred on Christmas Eve, affecting our Chrome extension," the statement said. It cited public comments from cybersecurity experts. These comments, said Cyberhaven, suggested that the attack was "part of a wider campaign to target Chrome extension developers across a wide range of companies."

    Cyberhaven added: "We are actively cooperating with federal law enforcement.""

    reuters.com/technology/cyberse

    #CyberSecurity #GoogleChrome #Chrome #Cyberhaven

  18. "Hackers have compromised several different companies' Chrome browser extensions in a series of intrusions dating back to mid-December, according to one of the victims and experts who have examined the campaign.

    Among the victims was the California-based Cyberhaven, a data protection company that confirmed the breach in a statement to Reuters on Friday.

    "Cyberhaven can confirm that a malicious cyberattack occurred on Christmas Eve, affecting our Chrome extension," the statement said. It cited public comments from cybersecurity experts. These comments, said Cyberhaven, suggested that the attack was "part of a wider campaign to target Chrome extension developers across a wide range of companies."

    Cyberhaven added: "We are actively cooperating with federal law enforcement.""

    reuters.com/technology/cyberse

    #CyberSecurity #GoogleChrome #Chrome #Cyberhaven

  19. "Hackers have compromised several different companies' Chrome browser extensions in a series of intrusions dating back to mid-December, according to one of the victims and experts who have examined the campaign.

    Among the victims was the California-based Cyberhaven, a data protection company that confirmed the breach in a statement to Reuters on Friday.

    "Cyberhaven can confirm that a malicious cyberattack occurred on Christmas Eve, affecting our Chrome extension," the statement said. It cited public comments from cybersecurity experts. These comments, said Cyberhaven, suggested that the attack was "part of a wider campaign to target Chrome extension developers across a wide range of companies."

    Cyberhaven added: "We are actively cooperating with federal law enforcement.""

    reuters.com/technology/cyberse

    #CyberSecurity #GoogleChrome #Chrome #Cyberhaven

  20. "Hackers have compromised several different companies' Chrome browser extensions in a series of intrusions dating back to mid-December, according to one of the victims and experts who have examined the campaign.

    Among the victims was the California-based Cyberhaven, a data protection company that confirmed the breach in a statement to Reuters on Friday.

    "Cyberhaven can confirm that a malicious cyberattack occurred on Christmas Eve, affecting our Chrome extension," the statement said. It cited public comments from cybersecurity experts. These comments, said Cyberhaven, suggested that the attack was "part of a wider campaign to target Chrome extension developers across a wide range of companies."

    Cyberhaven added: "We are actively cooperating with federal law enforcement.""

    reuters.com/technology/cyberse

    #CyberSecurity #GoogleChrome #Chrome #Cyberhaven