SquareX Discloses Browser-Native Ransomware that Puts Millions at Risk
ID: afb2b087-63ce-5cd5-a945-ee3da89d5d97
STIX ID: report--afb2b087-63ce-5cd5-a945-ee3da89d5d97
Feed Name: Security Ledger
SquareX warns of an emergent "browser-native ransomware" that leverages browser-based authentication, malicious extensions/OAuth social engineering, and AI-driven automation to access, copy, delete, or lock enterprise cloud data without traditional file downloads—potentially evading EDR/antivirus. Demonstrations show attackers can reset passwords, exfiltrate files from Google Drive/Dropbox/OneDrive, and expand access via shared drives, prompting a recommendation for Browser Detection and Response (BDR) solutions to address client-side identity attacks in the browser.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
