49 crypto-wallet pickpocketing browser extensions booted from the Chrome web store

Hackers have been using Google Ads to target unsuspecting cryptocurrency investors into installing malicious browser extensions, with the aim of stealing passphrases and private keys and draining funds from their wallets.
Read more in my article on the… Continue reading 49 crypto-wallet pickpocketing browser extensions booted from the Chrome web store

Whoops! LastPass accidentally deleted its browser extension from the Chrome store. But it’s back now

Someone at LastPass must be feeling 5!ck as a p4rr0t right now, after human error meant that its browser extension was accidentally deleted from the Chrome web store.
Although an embarrassing goof, it’s something of a storm in a teacup security-w… Continue reading Whoops! LastPass accidentally deleted its browser extension from the Chrome store. But it’s back now

LastPass users automatically updated to fix security vulnerability in browser extension

Popular password manager LastPass says that it has fixed a vulnerability in its Chrome and Opera browser extensions that could have potentially seen an attacker steal the username and password previously filled-in by the software.
Continue reading LastPass users automatically updated to fix security vulnerability in browser extension

How a Surf Loving Aussie Developed Sonatype’s Most Popular Extension

The first thing you need to know about Sonatype is this: the rumors are true.
The post How a Surf Loving Aussie Developed Sonatype’s Most Popular Extension appeared first on Security Boulevard.
Continue reading How a Surf Loving Aussie Developed Sonatype’s Most Popular Extension

Chrome extension devs must drop deceptive installation tactics

After announcing its intention to limit third-party developers’ access to Chrome’s webRequest API, which is used by many ad-blocking extensions to filter out content, Google has followed up with announcements for a few more changes meant &#… Continue reading Chrome extension devs must drop deceptive installation tactics

Should you trust that Chrome extension? Use CRXcavator to decide

Duo Security has released CRXcavator, a tool that can help end users and enterprises make an informed decision about installing a specific Chrome extension. About CRXcavator CRXcavator was created as an internal tool by Duo’s Corporate Security Enginee… Continue reading Should you trust that Chrome extension? Use CRXcavator to decide

Automatic 4K/HD for YouTube extension pulled from Chrome Store for pop-up ad abuse

A popular browser extension has been removed by Google from the Chrome Web Store after it started spamming users with irritating pop-up advertisements.
Read more in my article on the Hot for Security blog.
Continue reading Automatic 4K/HD for YouTube extension pulled from Chrome Store for pop-up ad abuse

Google Chrome extension warns if your password has been leaked

Google has released an optional extension for its Chrome browser that will trigger a visual warning if it determines you are using a username/password combination that it knows to be unsafe.
Read more in my article on the Tripwire State of Security blog.
Continue reading Google Chrome extension warns if your password has been leaked