#session-token-theft

[ follow ]
Information security
fromSecurityWeek
3 days ago

Chrome, Edge Extensions Caught Stealing ChatGPT Sessions

Malicious browser extensions stole ChatGPT session tokens by injecting content scripts into chatgpt.com, exfiltrating authorization headers and user data to remote servers.
fromThe Hacker News
1 month ago

A Browser Extension Risk Guide After the ShadyPanda Campaign

A threat group dubbed ShadyPanda spent seven years playing the long game, publishing or acquiring harmless extensions, letting them run clean for years to build trust and gain millions of installs, then suddenly flipping them into malware via silent updates. In total, about 4.3 million users installed these once-legitimate add-ons, which suddenly went rogue with spyware and backdoor capabilities. This tactic was essentially a browser extension supply-chain attack. The ShadyPanda operators even earned featured and verified badges in the official Chrome Web Store and Microsoft Edge Add-ons site for some extensions, reinforcing user confidence. Because extension updates happen automatically in the background, the attackers were able to push out malicious code without users noticing a thing.
Information security
fromThe Hacker News
4 months ago

When Browsers Become the Attack Surface: Rethinking Security for Scattered Spider

As enterprises continue to shift their operations to the browser, security teams face a growing set of cyber challenges. In fact, over 80% of security incidents now originate from web applications accessed via Chrome, Edge, Firefox, and other browsers. One particularly fast-evolving adversary, Scattered Spider, has made it their mission to wreak havoc on enterprises by specifically targeting sensitive data on these browsers.
Information security
[ Load more ]