More energized than ever after a week in Vegas Got the opportunity to give my first talk at summer camp which checks a box on my bucket list. Thankful for everyone I met, folks I got to catch up with, and the discussions that were had!
11.08.2025 19:20 β π 3 π 0 π¬ 0 π 0
the girlies β€οΈ @defcon.bsky.social @tracketpacer.bsky.social
#womenintech #networkengineer #softwareengineer #defcon
08.08.2025 18:52 β π 145 π 7 π¬ 1 π 1
Have you ever been sad that malicious extension got removed from the marketplace before you could finish your incident report so you're missing a ton of details? Recent screenshots are being added to all extensions so you can see what was listed before it was removed.
01.08.2025 15:16 β π 0 π 0 π¬ 0 π 0
Can't wait for Black Hat and Defcon next week! If you're around and want to meet up, please give me a shout!
31.07.2025 14:47 β π 1 π 0 π¬ 0 π 0
Secure Annex has been developing an MCP server to help folks understand browser extensions without having to install, download, or reverse them. Just ask questions about any extension and it will analyze enriched data while also digging files. If you're interested, get in touch!
29.07.2025 15:22 β π 1 π 0 π¬ 0 π 0
Don't get caught out with your installed extensions when new research starts dropping!
28.07.2025 14:47 β π 0 π 0 π¬ 0 π 0
Risky Business Weekly (799): Everyone's Sharepoint gets shelled
Risky Biz returns after two weeks off, and there sure is cybersecurity news to catch up on. Patrick Gray and Adam Boileau discuss:* Microsoft tried to make o...
Browser extensions scraping the web from your browser without you knowing? Deemed malware, many of these extensions have begun to be removed from extension marketplaces. Catch the rundown on the latest Risky Business
youtu.be/Xs3q4LG5yvg?...
25.07.2025 15:12 β π 0 π 0 π¬ 0 π 0
You can bet it will be solved when we figure out a way to show advertisements from your pacemaker
25.07.2025 01:40 β π 0 π 0 π¬ 1 π 0
Apparently it is no longer malware, nothing to see here
24.07.2025 15:58 β π 0 π 0 π¬ 0 π 0
Microsoft has flagged this package as malware, but it is apparently still listed in the VS Marketplace. What is the deal?
Interestingly the UUID of the package has changed so it got reposted after removing the malicious code?
marketplace.visualstudio.com/items?itemNa...
github.com/microsoft/vs...
24.07.2025 15:12 β π 0 π 0 π¬ 1 π 0
Perceptron Network, the largest extension using Mellowtel, has been removed by Google for malware. It loaded the scraper without opt-in on installation. Perceptron claims it is a mistake and is asks users to install manually now.
First identified here - secureannex.com/blog/mellow-...
23.07.2025 21:13 β π 0 π 0 π¬ 0 π 0
Removed from the VS Marketplace on 7/21, what I assume is a new variant of the ScreenConnect remote PowerShell executor. Instead of getting a script from a now known malicious domain, they seem to have pivoted to Discord webhook responses.
Extension -
dafsfsdsfdfsdf11.randomic-slaying-pog
23.07.2025 14:43 β π 0 π 0 π¬ 0 π 0
Software extension management model
A guide for managing software extensions installed in browsers and code editors
What stage of the software extension management model are you in? Visibility, evaluation, requests, or monitoring? What do you wish you could be doing better?
secureannex.com/blog/softwar...
22.07.2025 15:06 β π 0 π 0 π¬ 0 π 0
It has gotten incredibly hard to verify extension publishers in the Edge web store. There are no longer any links to support resources or signs that a publisher is who they say they are. For example, clicking on this owner just links to a basic privacy policy. How does that help?
18.07.2025 15:08 β π 0 π 1 π¬ 1 π 0
Yuuuuuummmm
18.07.2025 01:52 β π 1 π 0 π¬ 0 π 0
That is a lot of Salesforce access included in this browser extension for sale
15.07.2025 17:59 β π 1 π 0 π¬ 0 π 0
Two different extension developers complained on Mellowtel's Discord server about having their extensions banned by Mozilla after media coverage of the fact that ~1m systems are running extensions that use Mellowtel to route web scraping traffic through users' devices.
@techlifeweb Ah that's a shame
11.07.2025 13:39 β π 0 π 1 π¬ 0 π 0
YouTube video by Matt Johansen
what the hell is going on with extensions turning into malware?
Fantastic rundown and behavioral analysis of the recent software extension events from @mattjay.com.
www.youtube.com/watch?v=o9XB...
11.07.2025 19:02 β π 2 π 0 π¬ 0 π 0
-Hafnium APT member arrested in Italy
-VenusTech and Salt Typhoon leaks
-Russian drone volunteer group gets hacked
-Satanlock shuts down and leaks all victim data.
-Browser extensions hijacked for web scraping botnet
Podcast: risky.biz/RBNEWS449/
Newsletter: news.risky.biz/risky-bullet...
09.07.2025 06:19 β π 18 π 7 π¬ 1 π 0
Jfc
09.07.2025 01:16 β π 1 π 0 π¬ 1 π 0
Even if you didn't see the iframe loaded, you can inspect your browser console to see the requests made on your behalf. The iframe even takes the loaded content and returns it back to a Mellowtel domain and a Lambda function for further processing.
08.07.2025 19:28 β π 0 π 0 π¬ 1 π 0
How is this easily done? Well Mellowtel removes security headers which prevent this using the "declarativeNetRequest" permissions putting users at risk!
08.07.2025 19:28 β π 0 π 0 π¬ 1 π 0
the content script which injects a hidden iframe into your current webpage and load the requested website.
Did you catch it?
08.07.2025 19:28 β π 0 π 0 π¬ 1 π 0
With the websocket open, instructions begin to stream into the extension from server. These instructions generally consist of URLs and how they should be loaded by the extension. There seems to be some connectivity check done by the service worker before passing the URL to...
08.07.2025 19:28 β π 0 π 0 π¬ 1 π 0
The first thing the library does is measure your bandwidth so it knows if you have a reliable connection or not for their requests. Once completed, it creates a websocket connection to a callback server.
08.07.2025 19:28 β π 0 π 0 π¬ 1 π 0
Dad, husband. Love gaming, tech, dev and security. NOC Goon @ DEF CON.
Sometimes I tell people things about technology. Former sysadmin, CISSP, MCSE, MCSA, etc.
Spaces, neovim, tmux, and BSD.
Security at a Bright Orange AI Walkie Talkie Company.
~ personal profile ~ (rants about leadership, privacy, and security)
Looking for Internet Catharsis? https://linktr.ee/mattdomko
Hacking/crime/privacy journalist. Author of DARK WIRE, buy here: https://www.hachettebookgroup.com/titles/joseph-cox/dark-wire/9781541702691/#preorder Co-founder of 404 Media. Signal: joseph.404 Email: joseph@404media.co
I like to read about #cybersecurity #dfir #bbq #biking
linktr.ee/drewhjelm
Hugo dad of 4 | InfoSec @elastic | hockey dad | general nerd
Webdev dabbler. Infosec fan. Django, React, Go.
Push all the buttons until something works.
Founder of Damn Vulnerable Web App (DVWA)
Founder of WPScan (acquired by Automattic)
Check out my new project! https://kevintel.com
IT and Security at GreyNoise.
Straight up hot garbage behind the keyboard.
Blue Team, Red Team, Detection Engineering, I've been doing it a while
Infosec: I like to build things and chase rabbits
I am likely going to focus more on what I do outside of work on here rather than be Infosec focused...
Outside of work:
- astrophotography
- hardware hacking
- ham radio
- cars
- guitar
- cats
- potato
The workflow and AI orchestration platform loved by security-minded teams.
Try our always-free Community Edition: http://tines.com/community-edition
Aspiring enthusiast. Security Researcher @ Tines.com. Leftist interested in cyber security, AI and sustainability. All views my own. He / him.
Flipping tables and dropping unicode everywhere
(β―Β°β‘Β°)β―οΈ΅ β»ββ» Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©Ν©ΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊΜΊ
Jan 10-12, 2025
Washington, D.C.
Less π« Than Ever
This account is mostly used to push information. Got questions? Email us at info @ shmoocon.org.
He/Him, #Isles, infosec DFIR + CTI, straight edge, EHM DB and EA NHL rosters guy. LEGO enthusiast
CISO, SANS Technology Institute Alumni
Security Engineering, DFIR, and Death Metal