Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar.

Both this and ClaudeBleed need a rogue extension that can already… Continue reading Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

Posted in Uncategorized

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, an… Continue reading RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

Posted in Uncategorized

11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot

Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard.

“An attacker exploiting one of… Continue reading 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot

Posted in Uncategorized

Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks

Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them.

The way these wallets talk to websites and blockchain serve… Continue reading Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks

Posted in Uncategorized

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry.

The activity allows users to enumerate user accounts and validate stolen credentials in Mi… Continue reading OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

Posted in Uncategorized

Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads

xAI’s Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed.

A researcher publishing as cereblab, testing version 0.2.93, captured… Continue reading Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads

Posted in Uncategorized