Please ensure Javascript is enabled for purposes of website accessibility

Powell, Citing Jobs Risk, Opens Door to Cuts but Doesn’t Commit

7 hours ago

Gaza City Officially in Famine, With Hunger Spreading, Says Global Hunger Monitor

8 hours ago

Gavin Newsom’s Redistricting Plan Is on Its Way to Voters. What You Need to Know

23 hours ago

CARB Executive Leader Rips Trump’s EPA for Seeking to Kill Proven Climate Science

1 day ago

California Lawmakers Advance First Two Bills in Democrats’ Redistricting Plan

1 day ago

Judge Rules Alina Habba Was Unlawfully Appointed as US Attorney in New Jersey

1 day ago

Gov. Gavin Newsom’s Latest Role Is Social Media Troll

1 day ago
Hackers Exploit Chrome Extensions, Exposing Millions to 2FA Bypass Attacks
News
By News
Published 8 months ago on
December 31, 2024

Chrome extension vulnerabilities leave millions at risk of 2FA bypass attacks, with hackers targeting multiple companies. (Shutterstock)

Share

Getting your Trinity Audio player ready...

Google Chrome users face potential security risks as hackers target browser extensions to bypass two-factor authentication (2FA), as reported by Forbes.

The attacks, which began in mid-December, have compromised several companies’ Chrome extensions, potentially affecting millions of users.

Christmas Eve Attack

One notable incident involved Cyberhaven, a data attack detection company.

On Christmas Eve, a phishing attack compromised an employee’s credentials, allowing hackers to publish a malicious version of their Chrome extension. Cyberhaven CEO Howard Ting stated, “We want to share the full details of the incident and steps we’re taking to protect our customers and mitigate any damage.”

The attack bypassed 2FA by capturing session cookies, which authenticate user sessions. This method allows attackers to reuse the stolen cookies and access accounts without needing the 2FA code.

Google’s Recommendations to Mitigate Risks

To mitigate risks, Google recommends using passkeys and security keys. Vivek Ramachandran, founder of SquareX, suggests implementing server-side restrictions on risky OAuth scopes and using client-side Browser Detection-Response tools.

Google’s Chrome security team employs both automated and manual reviews to check extensions before publication on the Chrome Web Store. They also continuously monitor published extensions. Despite these efforts, some malicious extensions still slip through.

Users can protect themselves by:
1. Checking installed extensions at “chrome://extensions”
2. Running a Chrome Safety Check
3. Enabling enhanced protection mode in Safe Browsing

According to a Google spokesperson, “Google research has shown that security keys provide stronger protection against automated bots, bulk phishing attacks, and targeted attacks than SMS, app-based one-time passwords, and other forms of traditional two-factor authentication.”

Read more at Forbes

RELATED TOPICS:

DON'T MISS

What Are Fresno Real Estate Experts Predicting for 2025 and Beyond?

DON'T MISS

First California EV Mandates Hit Automakers This Year. Most Are Not Even Close

DON'T MISS

Atwater Prison Inmate Charged for Threatening to Kill Prosecutor’s Family

DON'T MISS

Multiple Passengers Are Killed After Bus Crashes in Western New York

DON'T MISS

Fresno Firefighters Contain Cambridge Avenue Blaze, No Injuries Reported

DON'T MISS

With Major Heat Risk Forecast, This Is a Good Weekend to Stay Indoors in Fresno

DON'T MISS

Trump Says Intel Has Agreed to Deal for US to Take 10% Equity Stake

DON'T MISS

Epstein Associate Maxwell Says She Never Saw Trump Behave Inappropriately

DON'T MISS

Wrongly Deported Migrant Abrego to Be Released Soon, Lawyer Says

DON'T MISS

Remembering Ron McCary, Who Did It All for KMJ

DON'T MISS

I Was Preyed On for My VA Benefits. California Can Stop It

DON'T MISS

Texas Senate Debates Redistricting Bill, Is Expected to Pass It Easily

UP NEXT

Multiple Passengers Are Killed After Bus Crashes in Western New York

UP NEXT

Fresno Firefighters Contain Cambridge Avenue Blaze, No Injuries Reported

UP NEXT

With Major Heat Risk Forecast, This Is a Good Weekend to Stay Indoors in Fresno

UP NEXT

Trump Says Intel Has Agreed to Deal for US to Take 10% Equity Stake

UP NEXT

Epstein Associate Maxwell Says She Never Saw Trump Behave Inappropriately

UP NEXT

Wrongly Deported Migrant Abrego to Be Released Soon, Lawyer Says

UP NEXT

Remembering Ron McCary, Who Did It All for KMJ

UP NEXT

I Was Preyed On for My VA Benefits. California Can Stop It

UP NEXT

Texas Senate Debates Redistricting Bill, Is Expected to Pass It Easily

UP NEXT

Trump: DC Mayor Bowser Must Get Act Together or Won’t Be Mayor Anymore

With Major Heat Risk Forecast, This Is a Good Weekend to Stay Indoors in Fresno

2 hours ago

Trump Says Intel Has Agreed to Deal for US to Take 10% Equity Stake

3 hours ago

Epstein Associate Maxwell Says She Never Saw Trump Behave Inappropriately

3 hours ago

Wrongly Deported Migrant Abrego to Be Released Soon, Lawyer Says

3 hours ago

Remembering Ron McCary, Who Did It All for KMJ

3 hours ago

I Was Preyed On for My VA Benefits. California Can Stop It

4 hours ago

Texas Senate Debates Redistricting Bill, Is Expected to Pass It Easily

4 hours ago

Trump: DC Mayor Bowser Must Get Act Together or Won’t Be Mayor Anymore

4 hours ago

Community Shares Messages of Support for Joseph Castro While He Is in Hospice Care

4 hours ago

Bulldogs Hope to Make Kansas Dust in the Wind as Entz, Warner Debut

5 hours ago

Atwater Prison Inmate Charged for Threatening to Kill Prosecutor’s Family

A federal grand jury has indicted an Atwater prison inmate accused of threatening to kill the family of a federal prosecutor, U.S. Attorney ...

59 minutes ago

The crest of the United States Department of Justice (DOJ) is seen at their headquarters in Washington, D.C., U.S., May 10, 2021. REUTERS/Andrew Kelly/File photo
59 minutes ago

Atwater Prison Inmate Charged for Threatening to Kill Prosecutor’s Family

First responders work at the scene of a bus crash on the New York State Thruway about 30 miles east of Buffalo, N.Y., on Friday afternoon, Aug. 22, 2025. The tour bus traveling from Niagara Falls to New York City crashed on a highway outside Buffalo on Friday, killing multiple passengers, including at least one child, and leaving some people trapped beneath the vehicle, officials said. (Lauren Petracca/The New York Times)
1 hour ago

Multiple Passengers Are Killed After Bus Crashes in Western New York

On Friday, August 22, 2025, Fresno firefighters contained a house fire on East Cambridge Avenue, preventing major damage and reporting no injuries. (Fresno Fire)
1 hour ago

Fresno Firefighters Contain Cambridge Avenue Blaze, No Injuries Reported

Fresno heat hot heatwave High Humidity
2 hours ago

With Major Heat Risk Forecast, This Is a Good Weekend to Stay Indoors in Fresno

A smartphone with a displayed Intel logo is placed on a computer motherboard in this illustration taken March 6, 2023. (Reuters File)
3 hours ago

Trump Says Intel Has Agreed to Deal for US to Take 10% Equity Stake

Ghislaine Maxwell appears via video link during her arraignment hearing in Manhattan Federal Court, in the Manhattan borough of New York City, New York, U.S. July 14, 2020 in this courtroom sketch. (Reuters File)
3 hours ago

Epstein Associate Maxwell Says She Never Saw Trump Behave Inappropriately

Kilmar Abrego Garcia, a Salvadoran migrant who lived in the U.S. legally with a work permit and was erroneously deported to El Salvador, is seen wearing a Chicago Bulls hat, in this handout image obtained by Reuters on April 9, 2025. (Reuters File)
3 hours ago

Wrongly Deported Migrant Abrego to Be Released Soon, Lawyer Says

Ron McCary
3 hours ago

Remembering Ron McCary, Who Did It All for KMJ

Search

Help continue the work that gets you the news that matters most.

Send this to a friend