Saturday, June 28, 2025
  • Login
No Result
View All Result
ForexTV
  • News
    • Top Corporate News
    • Lifestyle
    • Technology
    • Financial Markets News
  • Small Business
    • Digital Marketing Blog
    • Small Business Best Practices
    • Small Business Strategy
      • Sales Strategies
      • Marketing Strategies
  • Business Finance
    • Small Business-Lending Trends
    • Debt Service Coverage Ratio (DSCR)
    • Business Credit
      • Business Credit Blog
      • Business Loans
      • Merchant Cash Advances
      • Business Line of Credit
      • What is Alternative Business Lending?
    • Resources
      • Debt Service Coverage Ratio (DSCR) Calculator
  • Currency Focus
    • Crypto Focus
      • Bitcoin (BTC)
      • Ethereum (ETH)
      • Tether
      • BNB
      • Cardano (Ada)
      • Ripple (XRP)
      • Solana (SOL)
      • Dogecoin (DOGE)
      • Polkadot (DOT)
      • Tron (TRX)
      • Shiba Inu (SHIB)
      • Litecoin (LTC)
    • EURO (EUR)
    • Japanese Yen (JPY)
    • Great British Pound (GBP)
    • Swiss Franc (CHF)
    • New Zealand Dollar (NZD)
    • Canadian Dollar (CAD)
    • Australian Dollar (AUD)
  • Resources
    • Economic Calendar
    • Trader Education
      • Candlestick Pattern Intro
    • Live Forex Rates/Charts
      • Live Rates
      • Live Charts
    • Forex Trader Tools
      • Pivot Point Calculator
      • Currency Converter
      • Global Statistic Resources
    • Trading Terms
      • Forex Glossary
      • Glossary of Retirement Industry Terms
    • CPI Tools
      • CPI Inflation Calculator
      • CPI Average Price Calculator
  • Marketing Services
    • Digital Marketing Services
    • Digital Marketing Consulting
    • Search Engine Optimization (SEO)
    • Online Content Marketing
    • Digital Marketing Blog
    • Inbound Marketing Services
    • Email Marketing
    • Digital Marketing Rates
  • News
    • Top Corporate News
    • Lifestyle
    • Technology
    • Financial Markets News
  • Small Business
    • Digital Marketing Blog
    • Small Business Best Practices
    • Small Business Strategy
      • Sales Strategies
      • Marketing Strategies
  • Business Finance
    • Small Business-Lending Trends
    • Debt Service Coverage Ratio (DSCR)
    • Business Credit
      • Business Credit Blog
      • Business Loans
      • Merchant Cash Advances
      • Business Line of Credit
      • What is Alternative Business Lending?
    • Resources
      • Debt Service Coverage Ratio (DSCR) Calculator
  • Currency Focus
    • Crypto Focus
      • Bitcoin (BTC)
      • Ethereum (ETH)
      • Tether
      • BNB
      • Cardano (Ada)
      • Ripple (XRP)
      • Solana (SOL)
      • Dogecoin (DOGE)
      • Polkadot (DOT)
      • Tron (TRX)
      • Shiba Inu (SHIB)
      • Litecoin (LTC)
    • EURO (EUR)
    • Japanese Yen (JPY)
    • Great British Pound (GBP)
    • Swiss Franc (CHF)
    • New Zealand Dollar (NZD)
    • Canadian Dollar (CAD)
    • Australian Dollar (AUD)
  • Resources
    • Economic Calendar
    • Trader Education
      • Candlestick Pattern Intro
    • Live Forex Rates/Charts
      • Live Rates
      • Live Charts
    • Forex Trader Tools
      • Pivot Point Calculator
      • Currency Converter
      • Global Statistic Resources
    • Trading Terms
      • Forex Glossary
      • Glossary of Retirement Industry Terms
    • CPI Tools
      • CPI Inflation Calculator
      • CPI Average Price Calculator
  • Marketing Services
    • Digital Marketing Services
    • Digital Marketing Consulting
    • Search Engine Optimization (SEO)
    • Online Content Marketing
    • Digital Marketing Blog
    • Inbound Marketing Services
    • Email Marketing
    • Digital Marketing Rates
No Result
View All Result
ForexTV
No Result
View All Result
ADVERTISEMENTS
club Felene

SquareX Researchers Expose OAuth Attack on Chrome Extensions Days Before Major Breach

by GlobeNewswire
December 30, 2024
in Top News
Reading Time: 5 mins read

Screenshot 2024-12-30 150129

PALO ALTO, Calif., Dec. 30, 2024 (GLOBE NEWSWIRE) —

SquareX, an industry-first Browser Detection and Response (BDR) solution, leads the way in browser security. About a week ago, SquareX reported large-scale attacks targeting Chrome Extension developers aimed at taking over the Chrome Extension from the Chrome Store.

On December 25th, 2024, a malicious version of Cyberhaven’s browser extension was published on the Chrome Store that allowed the attacker to hijack authenticated sessions and exfiltrate confidential information. The malicious extension was available for download for more than 30 hours before being removed by Cyberhaven. The data loss prevention company declined to comment on the extent of the impact when approached by the press, but the extension had over 400,000 users on the Chrome Store at the time of the attack.

Unfortunately, the attack took place as SquareX’s researchers had identified a similar attack with a video demonstrating the entire attack pathway just a week before the Cyberhaven breach. The attack begins with a phishing email impersonating Chrome Store containing a supposed violation of the platform’s “Developer Agreement”, urging the receiver to accept the policies to prevent their extension from being removed from Chrome Store. Upon clicking on the policy button, the user gets prompted to connect their Google account to a “Privacy Policy Extension”, which grants the attacker access to edit, update and publish extensions on the developer’s account.

Screenshot 2024-12-30 150322

Fake Privacy Policy Extension requesting access to “edit, update or publish” the developer’s extension

Extensions have become an increasingly popular way for attackers to gain initial access. This is because most organizations have limited purview on what browser extensions their employees are using. Even the most rigorous security teams typically do not monitor subsequent updates once an extension is whitelisted.

SquareX has conducted extensive research and demonstrated at DEFCON 32, how MV3-compliant extensions can be used to steal video stream feeds, add a silent GitHub collaborator, and steal session cookies, among others. Attackers can create a seemingly harmless extension and later convert it into a malicious one post-installation or, as demonstrated in the attack above, deceive the developers behind a trusted extension to gain access to one that already has hundreds of thousands of users. In Cyberhaven’s case, attackers were able to steal company credentials across multiple websites and web apps through the malicious version of the extension.

Given that developer emails are publicly listed on Chrome Store, it is easy for attackers to target thousands of extension developers at once. These emails are typically used for bug reporting. Thus, even support emails listed for extensions from larger companies are usually routed to developers who may not have the level of security awareness required to find suspicion in such an attack. As per SquareX’s attack disclosure and the Cyberhaven breach that occurred within the span of less than two weeks, the company has strong reason to believe that many other browser extension providers are being attacked in the same way. SquareX urges companies and individuals alike to conduct a careful inspection before installing or updating any browser extensions.

SquareX team understands that it can be non-trivial to evaluate and monitor every single browser extension in the workforce amidst all the competing security priorities, especially when it comes to zero-day attacks. As demonstrated in the video, the fake privacy policy app involved in Cyberhaven’s breach was not even detected by any popular threat feeds.

SquareX’s Browser Detection and Response (BDR) solution takes this complexity off security teams by:

  • Blocking OAuth interactions to unauthorized websites to prevent employees from accidentally giving attackers unauthorized access to your Chrome Store account
  • Blocking and/or flagging any suspicious extension updates containing new, risky permissions
  • Blocking and/or flagging any suspicious extensions with a surge of negative reviews
  • Blocking and/or flagging installations of sideloaded extensions
  • Streamline all requests for extension installations outside the authorized list for quick approval based on company policy 
  • Full visibility on all extensions installed and used by employees across the organization

SquareX’s founder Vivek Ramachandran warns: “Identity attacks targeting browser extensions similar to this OAuth attack will only become more prevalent as employees rely on more browser-based tools to be productive at work. Similar variants of these attacks have been used in the past to steal cloud data from apps like Google Drive and One Drive and we will only see attackers get more creative in exploiting browser extensions. Companies need to remain vigilant and minimize their supply chain risk without hampering employee productivity by equipping them with the right browser native tools.”

About SquareX:

SquareX helps organizations detect, mitigate, and threat-hunt client-side web attacks happening against their users in real-time.

SquareX’s industry-first Browser Detection and Response (BDR) solution, takes an attack-focused approach to browser security, ensuring enterprise users are protected against advanced threats like malicious QR Codes, Browser-in-the-Browser phishing, macro-based malware, and other web attacks encompassing malicious files, websites, scripts, and compromised networks.

With SquareX, enterprises can provide contractors and remote workers with secure access to internal applications, and enterprise SaaS, and convert the browsers on BYOD / unmanaged devices into trusted browsing sessions.

Contact

Head of PR

Junice Liew

SquareX

junice@sqrx.com

Photos accompanying this announcement are available at

https://www.globenewswire.com/NewsRoom/AttachmentNg/8c70ea64-f0ca-4fc4-9039-6f5b15a0adf2

https://www.globenewswire.com/NewsRoom/AttachmentNg/19691fe3-f330-4faf-ad88-7d0cb8a6359c

  • Author
  • Recent Posts
GlobeNewswire
GlobeNewswire
GlobeNewswire,is one of the world's largest newswire distribution networks, specializing in the delivery of corporate press releases financial disclosures and multimedia content to the media, investment community, individual investors and the general public.
GlobeNewswire
Latest posts by GlobeNewswire (see all)
  • ROSEN, SKILLED INVESTOR COUNSEL, Encourages DoubleVerify Holdings, Inc. Investors to Secure Counsel Before Important Deadline in Securities Class Action – DV - June 28, 2025
  • GradGuard Honors National Insurance Awareness Day by Awarding $15,000 in Scholarships to College Students - June 28, 2025
  • ROSEN, RECOGNIZED INVESTOR COUNSEL, Encourages Apple Inc. Investors to Secure Counsel Before Important Deadline in Securities Class Action – AAPL - June 28, 2025
ADVERTISEMENTS
americas favorite vodka

Related Posts

EUR/USD Forecast: Bulls Pause at 1.1750 Ahead of US Core PCE

by Forex Crunch
June 28, 2025
0

The EUR/USD forecast is bullish, with eyes on the 1.1800 level as the dollar weakens further. The EU’s optimistic fiscal...

Gold Outlook: $3,300 Pounced Amid Risk-on, Eyes on Core PCE

by Forex Crunch
June 28, 2025
0

Gold outlook remains fragile amid risk-on flows and dollar recovery. Mixed US data and a cautious Fed may keep the...

ROSEN, SKILLED INVESTOR COUNSEL, Encourages DoubleVerify Holdings, Inc. Investors to Secure Counsel Before Important Deadline in Securities Class Action – DV

by GlobeNewswire
June 28, 2025
0

NEW YORK, June 28, 2025 (GLOBE NEWSWIRE) -- WHY: Rosen Law Firm, a global investor rights law firm, reminds purchasers...

GradGuard Honors National Insurance Awareness Day by Awarding $15,000 in Scholarships to College Students

by GlobeNewswire
June 28, 2025
0

Each student will receive $3,000 to help offset tuition, books, housing, or other college-related expenses. GradGuard's 2025 Scholarship Recipients Congratulations...

ROSEN, RECOGNIZED INVESTOR COUNSEL, Encourages Apple Inc. Investors to Secure Counsel Before Important Deadline in Securities Class Action – AAPL

by GlobeNewswire
June 28, 2025
0

NEW YORK, June 28, 2025 (GLOBE NEWSWIRE) -- WHY: Rosen Law Firm, a global investor rights law firm, announces the...

Press Ranger Named Best PR Software by TechCommuters

by GlobeNewswire
June 28, 2025
0

Press Ranger Celebrates Prestigious Recognition as Best PR Software Press Ranger is an AI-powered PR tool that simplifies campaign management...

Next Post

Palm Henri Unveils Redesigned Website to Highlight Baltimore Interior Decorator Services

Please login to join discussion

Latest Posts

  • EUR/USD Forecast: Bulls Pause at 1.1750 Ahead of US Core PCE June 28, 2025
  • Gold Outlook: $3,300 Pounced Amid Risk-on, Eyes on Core PCE June 28, 2025
  • ROSEN, SKILLED INVESTOR COUNSEL, Encourages DoubleVerify Holdings, Inc. Investors to Secure Counsel Before Important Deadline in Securities Class Action – DV June 28, 2025
  • GradGuard Honors National Insurance Awareness Day by Awarding $15,000 in Scholarships to College Students June 28, 2025
  • ROSEN, RECOGNIZED INVESTOR COUNSEL, Encourages Apple Inc. Investors to Secure Counsel Before Important Deadline in Securities Class Action – AAPL June 28, 2025
  • About Us
  • Advertise
  • Careers
  • Contact
Privacy Policy / Terms and Conditions

© 2024 ForexTV.com

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish.Accept Cookie Policy
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
No Result
View All Result
  • News
    • Top Corporate News
    • Lifestyle
    • Technology
    • Financial Markets News
  • Small Business
    • Digital Marketing Blog
    • Small Business Best Practices
    • Small Business Strategy
      • Sales Strategies
      • Marketing Strategies
  • Business Finance
    • Small Business-Lending Trends
    • Debt Service Coverage Ratio (DSCR)
    • Business Credit
      • Business Credit Blog
      • Business Loans
      • Merchant Cash Advances
      • Business Line of Credit
      • What is Alternative Business Lending?
    • Resources
      • Debt Service Coverage Ratio (DSCR) Calculator
  • Currency Focus
    • Crypto Focus
      • Bitcoin (BTC)
      • Ethereum (ETH)
      • Tether
      • BNB
      • Cardano (Ada)
      • Ripple (XRP)
      • Solana (SOL)
      • Dogecoin (DOGE)
      • Polkadot (DOT)
      • Tron (TRX)
      • Shiba Inu (SHIB)
      • Litecoin (LTC)
    • EURO (EUR)
    • Japanese Yen (JPY)
    • Great British Pound (GBP)
    • Swiss Franc (CHF)
    • New Zealand Dollar (NZD)
    • Canadian Dollar (CAD)
    • Australian Dollar (AUD)
  • Resources
    • Economic Calendar
    • Trader Education
      • Candlestick Pattern Intro
    • Live Forex Rates/Charts
      • Live Rates
      • Live Charts
    • Forex Trader Tools
      • Pivot Point Calculator
      • Currency Converter
      • Global Statistic Resources
    • Trading Terms
      • Forex Glossary
      • Glossary of Retirement Industry Terms
    • CPI Tools
      • CPI Inflation Calculator
      • CPI Average Price Calculator
  • Marketing Services
    • Digital Marketing Services
    • Digital Marketing Consulting
    • Search Engine Optimization (SEO)
    • Online Content Marketing
    • Digital Marketing Blog
    • Inbound Marketing Services
    • Email Marketing
    • Digital Marketing Rates

© 2024 ForexTV.com