Cybersecurity firm's Chrome extension hijacked to steal users' data
ID: acc89b05-0ea7-5eac-ace0-30b7ab657aa7
STIX ID: report--acc89b05-0ea7-5eac-ace0-30b7ab657aa7
Feed Name: Bleeping Computer
Multiple Chrome extensions were compromised via injected malicious code that exfiltrated authenticated sessions, cookies, and other browser data to attacker-controlled infrastructure after a Chrome Web Store administrator account was phished; confirmed affected extensions include Cyberhaven and numerous others with collective downloads in the hundreds of thousands. Users are advised to update or remove affected extensions, rotate credentials and API tokens, clear browser data, and review logs for signs of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
