Saturday, February 7, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Press Release GlobeNewswire

SquareX Researchers Expose OAuth Attack on Chrome Extensions Days Before Major Breach

December 30, 2024
in GlobeNewswire, Web3
Reading Time: 7 mins read
5
SHARES
243
VIEWS
Share on TwitterShare on LinkedInShare on Facebook

Screenshot 2024-12-30 150129

PALO ALTO, Calif., Dec. 30, 2024 (GLOBE NEWSWIRE) —

SquareX, an industry-first Browser Detection and Response (BDR) solution, leads the way in browser security. About a week ago, SquareX reported large-scale attacks targeting Chrome Extension developers aimed at taking over the Chrome Extension from the Chrome Store.

On December 25th, 2024, a malicious version of Cyberhaven’s browser extension was published on the Chrome Store that allowed the attacker to hijack authenticated sessions and exfiltrate confidential information. The malicious extension was available for download for more than 30 hours before being removed by Cyberhaven. The data loss prevention company declined to comment on the extent of the impact when approached by the press, but the extension had over 400,000 users on the Chrome Store at the time of the attack.

Unfortunately, the attack took place as SquareX’s researchers had identified a similar attack with a video demonstrating the entire attack pathway just a week before the Cyberhaven breach. The attack begins with a phishing email impersonating Chrome Store containing a supposed violation of the platform’s “Developer Agreement”, urging the receiver to accept the policies to prevent their extension from being removed from Chrome Store. Upon clicking on the policy button, the user gets prompted to connect their Google account to a “Privacy Policy Extension”, which grants the attacker access to edit, update and publish extensions on the developer’s account.

Screenshot 2024-12-30 150322

Fake Privacy Policy Extension requesting access to “edit, update or publish” the developer’s extension

Extensions have become an increasingly popular way for attackers to gain initial access. This is because most organizations have limited purview on what browser extensions their employees are using. Even the most rigorous security teams typically do not monitor subsequent updates once an extension is whitelisted.

SquareX has conducted extensive research and demonstrated at DEFCON 32, how MV3-compliant extensions can be used to steal video stream feeds, add a silent GitHub collaborator, and steal session cookies, among others. Attackers can create a seemingly harmless extension and later convert it into a malicious one post-installation or, as demonstrated in the attack above, deceive the developers behind a trusted extension to gain access to one that already has hundreds of thousands of users. In Cyberhaven’s case, attackers were able to steal company credentials across multiple websites and web apps through the malicious version of the extension.

Given that developer emails are publicly listed on Chrome Store, it is easy for attackers to target thousands of extension developers at once. These emails are typically used for bug reporting. Thus, even support emails listed for extensions from larger companies are usually routed to developers who may not have the level of security awareness required to find suspicion in such an attack. As per SquareX’s attack disclosure and the Cyberhaven breach that occurred within the span of less than two weeks, the company has strong reason to believe that many other browser extension providers are being attacked in the same way. SquareX urges companies and individuals alike to conduct a careful inspection before installing or updating any browser extensions.

SquareX team understands that it can be non-trivial to evaluate and monitor every single browser extension in the workforce amidst all the competing security priorities, especially when it comes to zero-day attacks. As demonstrated in the video, the fake privacy policy app involved in Cyberhaven’s breach was not even detected by any popular threat feeds.

SquareX’s Browser Detection and Response (BDR) solution takes this complexity off security teams by:

  • Blocking OAuth interactions to unauthorized websites to prevent employees from accidentally giving attackers unauthorized access to your Chrome Store account
  • Blocking and/or flagging any suspicious extension updates containing new, risky permissions
  • Blocking and/or flagging any suspicious extensions with a surge of negative reviews
  • Blocking and/or flagging installations of sideloaded extensions
  • Streamline all requests for extension installations outside the authorized list for quick approval based on company policy 
  • Full visibility on all extensions installed and used by employees across the organization

SquareX’s founder Vivek Ramachandran warns: “Identity attacks targeting browser extensions similar to this OAuth attack will only become more prevalent as employees rely on more browser-based tools to be productive at work. Similar variants of these attacks have been used in the past to steal cloud data from apps like Google Drive and One Drive and we will only see attackers get more creative in exploiting browser extensions. Companies need to remain vigilant and minimize their supply chain risk without hampering employee productivity by equipping them with the right browser native tools.”

About SquareX:

SquareX helps organizations detect, mitigate, and threat-hunt client-side web attacks happening against their users in real-time.

SquareX’s industry-first Browser Detection and Response (BDR) solution, takes an attack-focused approach to browser security, ensuring enterprise users are protected against advanced threats like malicious QR Codes, Browser-in-the-Browser phishing, macro-based malware, and other web attacks encompassing malicious files, websites, scripts, and compromised networks.

With SquareX, enterprises can provide contractors and remote workers with secure access to internal applications, and enterprise SaaS, and convert the browsers on BYOD / unmanaged devices into trusted browsing sessions.

Contact

Head of PR

Junice Liew

SquareX

junice@sqrx.com

Photos accompanying this announcement are available at

https://www.globenewswire.com/NewsRoom/AttachmentNg/8c70ea64-f0ca-4fc4-9039-6f5b15a0adf2

https://www.globenewswire.com/NewsRoom/AttachmentNg/19691fe3-f330-4faf-ad88-7d0cb8a6359c

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.

ShareTweet1ShareSendShare2
Previous Post

Strengthening Digitalist Group Plc’s balance sheet position and conversion of convertible bonds into capital loans 

Next Post

Linklogis Officially Launches AI Agent, Capitalizing on Emerging Growth Opportunities in the AI Industry

Related Posts

Healthcare Analytics Market Poised for Rapid Expansion as Data-Driven Intelligence Becomes Central to Cost Control and Care Quality

Healthcare Analytics Market by Type (Predictive, Diagnostic), Application (Claim, RCM, Fraud, Precision Health, RWE, Imaging, Supply Chain, Workforce, Population Health), End User (Payer, Hospital, ACO, ASC), AI, Market Insights, Trends - Forecast to 2030The global Healthcare Analytics Market is entering a high-growth phase as healthcare organizations worldwide intensify their focus...

Read moreDetails

Develop Travel Booking System and Mobile Apps – Grow Online Travel Business

Provab develops next-gen travel booking engines for travel agencies and tour operators. It offers B2C, B2B and back office systems with flights, hotels, transfers, car rental and holiday packages modules.Developing a modern travel agency software platform helps travel agencies digitize their operations and offer seamless online booking experiences to customers....

Read moreDetails

Shoals Technologies Group Secures Key Initial Win with the ITC to Protect U.S. Energy Innovation

PORTLAND, Tenn., Feb. 06, 2026 (GLOBE NEWSWIRE) -- Shoals Technologies Group, Inc. (“Shoals”) (Nasdaq: SHLS), a global leader in electrical infrastructure solutions for the energy transition market, announced today that the U.S. International Trade Commission (“ITC”) has issued a favorable initial determination in Shoals’ patent infringement complaint against Voltage, LLC...

Read moreDetails

Veeco Stockholders Approve Merger with Axcelis

PLAINVIEW, N.Y., Feb. 06, 2026 (GLOBE NEWSWIRE) -- Veeco Instruments Inc. (Nasdaq: VECO) (“Veeco”) today announced that its stockholders have voted to approve all proposals related to the Company’s pending merger (the “Merger”) with Axcelis Technologies, Inc. (Nasdaq: ACLS) (“Axcelis”) at its Special Meeting of Stockholders (“Special Meeting”). The final...

Read moreDetails

Hemex Health Receives FDA Breakthrough Device Designation for Gazelle® Hb Variant Test

PORTLAND, Ore., Feb. 06, 2026 (GLOBE NEWSWIRE) -- Hemex Health, a medical diagnostics company focused on decentralized testing for blood-based conditions, today announced that the U.S. Food and Drug Administration (FDA) has granted Breakthrough Device Designation to its Gazelle® Hb Variant Test. The FDA’s Breakthrough Devices Program is intended to...

Read moreDetails

Renewal Fuels, Inc. (OTC: RNWF), Operating as American Fusion, Appoints Dr. John E. Brandenburg, Ph.D. as Chief Technology Officer

SOUTHLAKE, Texas, Feb. 06, 2026 (GLOBE NEWSWIRE) -- Renewal Fuels, Inc. (OTC: RNWF) (“RNWF” “American Fusion” or the “Company”), announced today the appointment of Dr. John E. Brandenburg, Ph.D., as Chief Technology Officer of Kepler Fusion Technologies, effective immediately. Dr. Brandenburg is a senior plasma physicist with more than four...

Read moreDetails

ZKP Crypto’s $5M Giveaway Becomes Crypto’s Biggest Story While ADA & SHIB Maintain Support Levels!

DUBAI, United Arab Emirates, Feb. 06, 2026 (GLOBE NEWSWIRE) -- Market momentum has cooled, reducing appetite for rapid price chases. Traders now focus closely on behavior at critical levels across major assets. Confirmation outweighs excitement in this measured environment. Recent Cardano news shows ADA defending the $0.33 to $0.34 support...

Read moreDetails

SWAG SILVER Launches Initial Exchange Offering on Coinstore:SWAG SILVER is an RWA-based digital asset backed by 18.5 million ounces of verified U.S. silver

Coinstore has announced the official IEO of SWAG SILVER’s native token -SWAGS($SWAGS) on its spot trading platform. The token is set to be listed as SWAGS/USDT pair, and will begin trading on the 31th of January 2026, with the private sale live on January 28th. Built on Ethereum and pegged...

Read moreDetails

Sonata Software consolidated PAT (before exceptional item) grew by 6.1% QoQ and 21.4 % YoY.

Consistent quarterly interim dividend of INR 1.25 per share.BENGALURU, India, Feb. 6, 2026 /PRNewswire/ -- Sonata Software (NSE: SONATSOFTW) (BSE: 532221), a leading Modernization Engineering Company, today reported its unaudited financial results for the Quarter ended December 31, 2025. in ₹ CroresDescriptionFor the Quarter ended For the nine months ended31-Dec-2530-Sep-25QoQ31-Dec-24YoY31-Dec-2531-Dec-24YoYRevenuesInternational IT...

Read moreDetails

HCLTech Named to Fortune’s World’s Most Admired Companies 2026 List

NEW YORK and NOIDA, India, Feb. 6, 2026 /PRNewswire/ -- HCLTech, (NSE: HCLTECH) (BSE: HCLTECH) a leading global technology company, has been named to Fortune magazine's 2026 World's Most Admired Companies list, recognizing its consistent performance, technology-led innovation and commitment to long-term value creation for clients, employees and stakeholders. "This...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Middle East Gaming Market Size to Hit USD 42.6 Billion by 2033 | Grow CAGR by 10.77%

    6 shares
    Share 2 Tweet 2
  • Meet DynaTech Systems at the AI Agent & Copilot Summit NA 2026

    6 shares
    Share 2 Tweet 2
  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    149 shares
    Share 60 Tweet 37
  • Carbon Removal Credit (CRC) Launches Carbon Asset NFT Framework: Giving Every Tonne of Carbon a Digital Identity

    5 shares
    Share 2 Tweet 1
  • Top Cross-Chain DeFi Solutions to Watch by 2025

    78 shares
    Share 31 Tweet 20
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • Healthcare Analytics Market Poised for Rapid Expansion as Data-Driven Intelligence Becomes Central to Cost Control and Care Quality
  • Develop Travel Booking System and Mobile Apps – Grow Online Travel Business
  • Shoals Technologies Group Secures Key Initial Win with the ITC to Protect U.S. Energy Innovation
  • Veeco Stockholders Approve Merger with Axcelis
  • Hemex Health Receives FDA Breakthrough Device Designation for Gazelle® Hb Variant Test

RSS Latest on Block3Wire

  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age
  • Cathedra Bitcoin Announces Leasing of 2.5-MW Bitcoin Mining Facility
  • Global Web3 Payments Leader, Banxa, Announces Integration With Metis to Usher In Next Wave of Cryptocurrency Users
  • Dexalot Launches First Hybrid DeFi Subnet on Avalanche

RSS Latest on Meta3Wire

  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
  • MetatronAI.com Unveils Revolutionary AI-Chat Features and Interface Upgrades
  • Purely.website – Disruptive new platform combats rising web hosting costs
  • WEMADE and Metagravity Sign Strategic Alliance MOU to Collaborate on Blockchain Games for the Metaverse
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Whitepaper | Tokenomics

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Media Portfolio: Block3Wire | Meta3Wire

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!
Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News
  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.