#BrowserSecurity

nemo™ 🇺🇦nemo@mas.to
2025-07-11

Nearly a million browsers have been compromised by 245 malicious extensions, secretly turning users into web scraping bots and disabling key security protections 😱🔒. Major privacy risks exposed—review your extensions now! Read more: techradar.com/pro/security/nea #Cybersecurity #BrowserSecurity #Privacy #newz

OS-SCIos_sci
2025-07-05

A new maturity model for browser security addresses the critical blind spot in enterprise protection. With 85% of work happening in browsers, it's time to secure the last mile of enterprise risk.

dub.sh/5QfEzPD

Offensive Sequenceoffseq@infosec.exchange
2025-07-03

🚨 CRITICAL: CVE-2025-34090 hits Chrome 127—local attackers can hijack COM CLSIDs, forcing fallback to weak cookie encryption. Risk: session/cookie theft without SYSTEM access. Monitor for patches, audit COM paths, and tighten endpoint controls. radar.offseq.com/threat/cve-20 #OffSeq #Chrome #Vuln #BrowserSecurity

Critical threat: CVE-2025-34090: CWE-426 Untrusted Search Path in Google Chrome
2025-07-02

🚨 Google patches Chrome zero-day CVE-2025-6554 exploited in the wild 🛠️. A type confusion flaw in V8 could allow remote code execution via crafted HTML. Update now!
#BrowserSecurity #ZeroDayAlert 🌐🔧

thehackernews.com/2025/07/goog

TechnoTenshi :verified_trans: :Fire_Lesbian:technotenshi@infosec.exchange
2025-06-24

Researcher demonstrates a software-only attack on WebAuthn by forging passkey signatures via Chrome's DevTools protocol. PoC bypasses security prompts, automates login, and exposes weak RP validation.

nullpt.rs/forging-passkeys

#WebAuthn #FIDO2 #BrowserSecurity #Passkeys

PPC Landppcland
2025-06-22

ICYMI: DuckDuckGo expands browser scam protection against fake sites: DuckDuckGo's browser now guards against investment scams and fake tech support alongside existing phishing defenses. ppc.land/duckduckgo-expands-br

PPC Landppcland
2025-06-21

DuckDuckGo expands browser scam protection against fake sites: DuckDuckGo's browser now guards against investment scams and fake tech support alongside existing phishing defenses. ppc.land/duckduckgo-expands-br

BiyteLümbiytelum
2025-06-17

💡Fun fact: Your computer’s battery status API can be used to track you.

Some websites ping battery levels to create a unique fingerprint, even in incognito mode. It’s subtle, creepy—and real.

🛡️ Quick fixes:
• Chrome: Install “Disable Battery API” extension
• Use Brave (built-in protection) or Firefox (already blocks this)

Cam Cookscrum_log
2025-06-10

Given Mozilla's implosion, you might want to take a serious look at LibreWolf.

I've been using the flat hub version for a long time and it's all I want from a browser.

librewolf.net/

2025-06-03

Mozilla is stepping up its browser security game—a new system now sniffs out malicious crypto extensions before anyone’s wallet gets hit. Curious how it all works?

thedefendopsdiaries.com/mozill

#mozilla
#cryptocurrency
#browsersecurity
#malicioussoftware
#cybersecurity

BiyteLümbiytelum
2025-06-02

“Save my info for next time?” Sounds helpful—until it isn’t.

Autofill settings in your browser can accidentally drop your address, phone, or credit card into phishing forms that look legit.

📌 Turn off autofill in your browser settings.
📌 Always type sensitive info manually.
📌 Don’t trust every form with your details.

nemo™ 🇺🇦nemo@mas.to
2025-05-30

🚨 Apple Safari users beware! A stealthy Browser-in-the-Middle (BitM) attack exploits Safari’s fullscreen mode lack of clear indicators, enabling phishing scams that steal credentials undetected. Stay vigilant with login prompts & avoid suspicious redirects! 🔒🕵️‍♂️ #CyberSecurity #PhishingAlert #Safari #BrowserSecurity #InfoSec cyberinsider.com/apple-safari- #newz

2025-05-29

Safari users, take notice: hackers are turning the fullscreen mode you trust into a tool for stealing your login details. Ever wondered if that “seamless” display could hide a trap? Read up on how this attack works and what you can do to stay safe.

thedefendopsdiaries.com/unders

#fullscreenattack
#safarivulnerability
#cybersecurity
#browsersecurity
#bitmattacks

2025-05-15

Google Chrome’s latest flaw (CVE-2025-4664) could let hackers swipe your sensitive data via crafty HTML tricks. Are you updated enough to stay safe?

thedefendopsdiaries.com/unders

#googlechrome
#cve20254664
#cybersecurity
#browsersecurity
#chromiumvulnerability

2025-05-14

Google Chrome is taking a bold step to keep you safer online by blocking admin-level launches. Could this be the game changer in fighting cyber threats? Dive in to find out.

thedefendopsdiaries.com/google

#googlechrome
#cybersecurity
#browsersecurity
#elevatedpermissions
#malwareprotection

2025-05-12

Almost every employee's browser might be a ticking time bomb. With extensions accessing sensitive data, our everyday tools could be our weakest link. Could your workday clicks be putting critical info at risk? Read on to find out.

thedefendopsdiaries.com/the-ub

#browsersecurity
#cyberthreats
#enterpriseextensions
#dataprotection
#cybersecuritytips

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst