A cyberattack campaign inserted malicious code into multiple Chrome browser extensions as far back as mid-December, Reuters reported yesterday. The code appeared designed to steal browser cookies and authentication sessions, targeting “specific social media advertising and AI platforms,” according to a blog post from Cyberhaven, one of the companies that was targeted.
Cyberhaven blames a phishing email for the attack, writing in a separate technical analysis post that the code appeared to specifically target Facebook Ads accounts. According to Reuters, security researcher Jaime Blasco believes the attack was “just random” and not targeting Cyberhaven specifically. He posted on X that he’d found VPN and AI extensions that contained the same malicious code that was inserted into Cyberhaven.
Other extensions possibly affected include Internxt VPN, VPNCity, Uvoice, and ParrotTalks, as Bleeping Computer writes.
Our team has confirmed a malicious cyberattack that occurred on Christmas Eve, affecting Cyberhaven's Chrome extension. Here's our post about the incident and the steps we're taking: https://t.co/VTBC73eWda
Our security team is available 24/7 to assist affected customers and…
Cyberhaven says hackers pushed an update (version 24.10.4) of its Cyberhaven data loss prevention extension containing the malicious code on Christmas Eve at 8:32PM ET. Cyberhaven says it discovered the code on December 25th at 6:54PM ET and removed it within an hour, but that the code was active until December 25th at 9:50PM ET. The company says it released a clean version in its 24.10.5 update.
Cyberhaven’s recommendations for companies that may be affected include that they check their logs for suspicious activity and revoke or rotate any passwords not using the FIDO2 multifactor authentication standard. Prior to publishing its posts, the company notified customers via an email that TechCrunch reported Friday morning.
Открыта регистрация на благотворительный «МедЗабег»
Невидимая угроза: как грязный воздух разрушает ЖКТ
«Я считал, что Анжелика в трусах, но она утверждала, что это шортики. И нас выгнали с собственной свадьбы!»: Леонид Агутин рассказал в «Шоу Воли» о своей провальной свадьбе с Анжеликой Варум
Подкаст "Женское дело. Лаборатория успеха" В гостях Ярославна Смирнова
Epic CEO Tim Sweeney takes his victory lap as Fortnite returns to the app store after nearly 5 years: 'Thanks to all of the folks who initially sided with Apple then later came around to the winning side'
Все изменения в Destiny Rising перед началом ЗБТ: общий уровень героев, гача-крутки и модификации
Регистрация на Supremacy: Warhammer 40,000 — стратегию от создателей Supremacy 1914
Most players 'know next to nothing about how games are made': New Blood devs sound off on gamedev misconceptions
ПРИЧЁМ ЗДЕСЬ ИЛОН МАСК? В ДЕЛЕ ГЕНЕРАЛА ИВАНА ПОПОВА КОСМИЧЕСКИЕ СЕРИИ СОВПАДЕНИЙ. СЕНСАЦИЯ! В.В. Путин, Дональд Трамп, Илон Маск. Россия, США, Европа могут улучшить отношения и здоровье общества?!
Тарифы в Москве: подорожание проезда, автоэвакуации и стройматериалов с июня
Редкий детеныш черепахи вылупился в Московском зоопарке: вес всего 18 граммов
Музеи Москвы: 1,8 млн экспонатов будут оцифрованы к 2026 году