Over 260,000 users installed fake AI Chrome extensions that used iframe injection to steal browser and Gmail data, exposing ...
More than 300 Chrome extensions were found to be leaking browser data, spying on users, or stealing user information.
在Koi Security详细披露的这起不寻常的供应链攻击中,未知攻击者声称获得了一个已被废弃的合法插件相关域名,用来托管虚假的微软登录页面,在此过程中窃取了超过4000个凭证。该网络安全公司将此活动代号命名为AgreeToSteal。