A reported extension campaign tied to about 90,000 browser users shows how a utility add-on can become a quiet collection point for sensitive AI chats and account details.
A coordinated disruption of GlassWorm-linked command-and-control infrastructure highlights how supply-chain malware can live closest to the people who build software, not just the systems that run it.
A vast network of rogue Chrome extensions is siphoning Google tokens, hijacking Telegram accounts, and flooding users with ads-right under Google’s nose.
A critical bug in Chrome’s Gemini Live AI panel granted rogue extensions a backstage pass to your camera, mic, and files-no clicks required.
A new wave of browser extensions is quietly siphoning sensitive data from millions-posing an unprecedented threat to business and personal security.
Cybercriminals deploy fake ad blockers and browser crash warnings to deliver a stealthy new Python-based trojan into corporate networks.
Millions of users are unknowingly leaking sensitive corporate meeting data through popular browser add-ons linked to a China-based cybercrime operation.
Two rogue Visual Studio Code extensions secretly stole credentials, crypto wallets, and more-raising urgent questions about supply chain security in developer ecosystems.
Rogue Visual Studio Code add-ons have infiltrated Microsoft’s trusted ecosystem, planting sophisticated infostealers on unsuspecting developers’ machines.