#extensions

:mastodon: deciodecio@infosec.exchange
2025-05-22

...et encore.
Depuis début 2024, un acteur malveillant diffuse des extensions Chrome fonctionnelles mais piégées via des faux sites imitant des services populaires (VPN, IA, crypto, etc.).
⬇️
Des sites frauduleux diffusent des extensions qui imitent ou détournent des outils légitimes comme :

🔹 FortiVPN (Fortinet)
🔹 DeepSeek (IA)
🔹 Google Analytics
🔹 Statistiques de sites web

Ces extensions semblent fiables, car elles s'appuient sur des services connus ou crédibles. En réalité, elles :

⚠️ Volent vos données
⚠️ Injectent du code malveillant
⚠️ Espionnent votre navigation
⚠️ Bypassent les protections du navigateur (CSP, sandbox…)

Exemples de faux domaines :
forti-vpn[.]com, sitestats[.]world, deepseek-ai[.]info…

[Liste complète + indicateurs (IOCs)]
👇
github.com/DomainTools/Securit

[source]
⬇️
"Hidden Threats of Dual-Function Malware Found in Chrome Extensions"
👇
dti.domaintools.com/dual-funct

[Dans les news infosec]
⬇️
"Data-stealing Chrome extensions impersonate Fortinet, YouTube, VPNs"
👇
bleepingcomputer.com/news/secu

#CyberVeille #Chrome #Extensions

2025-05-20

#BSI WID-SEC-2025-1107: [NEU] [hoch] TYPO3 #Extensions: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in verschiedenen TYPO3 Extensions ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen und um Cross-Site Scripting Angriffe durchzuführen.

wid.cert-bund.de/portal/wid/se

Diego Motadiegomota
2025-05-18

Mais uma extensão do gnome que eu acho essencial para o meu uso.

Trata-se de poder mudar de workspace com o scroll do mouse sem precisar apertar o botão "super/windows"

Funciona assim, quando eu quero alterar entre as workspaces eu apenas levo o cursor do mouse até a parte superior e uso o scroll do mouse

Nome da fonte: Panel Workspace Scroll

Link: extensions.gnome.org/extension

Valery's Volguevaleryvogue
2025-05-09

✨ Craving curls that stay defined and luscious all day long?
Check out my latest post: froodl.com/the-ultimate-curl-r 💁🏽‍♀️💦

Whether you’re rocking curly weaves, wigs, or your natural crown, this guide is packed with step-by-step tips to keep your curls juicy, frizz-free, and full of life. 🌸💫

🔁 Reblog if you love a good curl routine!

✨ Want flawless curls that actually last? Discover the secrets to keeping your extensions lush, defined, and full of life! Dive into the ultimate curl routine
2025-05-07

Есть ли жизнь на GitVerse? Расширения

Я давний пользователь GitHub. Можно сказать, что на моих глазах он вырос из самобытного GIT-хостинга до внушительной экосистемы для разработчиков под патронажем само́й Microsoft, и по факту стал индустриальным стандартом. Со временем я стал задаваться вопросом — можем ли мы в своей стране своими силами создать аналогичную экосистему? В которой нет проблем с платежами, не удаляют репозитории и аккаунты из-за поездки в Крым, где российские компании заказчики не опасаются хостить свои коммерческие проекты. В 2023 году я попробовал GitFlic, но не смог им пользоваться из-за нестабильной работы репозиториев. В 2025 году я решил попробовать GitVerse. Проекту уже больше года, и, скорее всего, он созрел для реального применения. В первую очередь меня интересует, есть ли у GitVerse потенциал стать не просто надёжным хостингом для GIT-репозиториев, а развиться в мощную экосистему, не просто повторить функционал GitHub в масштабе 1:43, а реализовать новое поколение индустриальных стандартов для совместного творчества разработчиков и других IT-специалистов.

habr.com/ru/articles/907732/

#сезон_open_source #gitverse #visual_studio #расширения #plugins #extensions #extension #plugin

Oto Šťávaalefunguju
2025-05-01

Alright, why does Firefox have an Extensions drop-down AND an Overflow menu, both of which can hide toolbar buttons so that they don't overcrowd the toolbar? And why can't I take extensions out of the Extensions drop-down while in the Customize Toolbar mode?

This one thing has been bothering me for a while now.

The right side of the Firefox toolbar, annotated with two arrows showing the Extensions menu and Overflow menu, which realistically should be a single button.
2025-04-29

I can't remember who recommended I try the uMatrix browser plugin. It's made by the same people who created uBlock.

If it was you... then thank you.

Now most of the sites I regularly use aren't "broken", it's kind of shocking how many random, tracking scripts many sites have nowadays.

Figuring out which ones are the "functional" scripts is sometimes tricky but the extra work is worth having less creepiness on the web.

FF: addons.mozilla.org/en-US/firef

Chr: chromewebstore.google.com/deta

#Extensions

2025-04-28

If you’re wondering: yes, we packed it with built-in tools.
Because you shouldn’t have to install 26 third-party extensions just to browse the way you want. 🛠️😄

#Vivaldi #Browser #Extensions #Tech #Apps #Software

N-gated Hacker Newsngate
2025-04-24

🚨 Devs are losing their minds because Microsoft decided to play a game of hide and seek with C/C++ in VS Code forks. 🕵️‍♂️ Meanwhile, The Register's website is so secure, it thinks you're a robot just for showing up. 🤖🔒
theregister.com/2025/04/24/mic

Hacker Newsh4ckernews
2025-04-24
Hacker Newsh4ckernews
2025-04-24

OpenVSX, which VSCode forks rely on for extensions, down for 24 hours

status.open-vsx.org/

2025-04-19

🚩 Chromium 135.x Turns Off Manifest V2 Extensions

It finally happened to me. I allowed my Chromium Web browser to update to version 135.0.7049.42 (Official Build) (64-bit) and it turned off a group of my older Manifest V2 extensions. Fortunately, using the Extensions page, I was able to re-enable them all... but I believe I read at some point in the future, this re-enablement feature will be removed.

#Chrome #Chrome135 #Chromium #Chromium135 #Extensions #Manifest #ManifestV2 #ManifestV3

Screenshot of Chromium Version 135.0.7049.42 (Official Build) 
(64-bit) with popup stating nine extensions were turned off.
2025-04-19

PostgreSQL Shared Libraries: Solving Python Extension Library Path Issues
Smoothly integrate Python extensions with PostgreSQL Shared Libraries, especially when using NumPy. Properly configuring the `shared_libraries` parameter prevents runtime errors by ensuring your database server can locate necessary libraries. Learn how to manage PostgreSQL Shared Libraries for robust Python extensions!
tech-champion.com/databas...

2025-04-18

Dozens of Chrome extensions contain secret functionality to track users, a security researcher has discovered.

#Chrome #extensions #privacy #cybersecurity

cnews.link/network-of-chrome-e

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst