Close Menu
TechZappi

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    OpenAI Prepares Astra, a New AI Model Built to Find and Exploit Cybersecurity Flaws

    September 2, 2026

    Apple Maps Adopts ‘Lake America’ Name in U.S. Following Google

    September 2, 2026

    Florida and Texas Take Steps to Remove Flock Surveillance Cameras

    September 2, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Vimeo Pinterest YouTube
    TechZappi
    Subscribe Login
    • Home
    • AI

      OpenAI Prepares Astra, a New AI Model Built to Find and Exploit Cybersecurity Flaws

      September 2, 2026

      Gemini’s Growing Feature List Highlights a Bigger AI Branding Problem

      August 27, 2026

      Google’s Gemini Reaches 1 Billion Monthly Users as AI Adoption Accelerates

      August 11, 2026

      Rippling Turns Its AI Spending Problem Into a New Employee ROI Tool

      August 7, 2026

      Anthropic Reveals AI Security Tests Accidentally Compromised Three Real-World Organizations

      July 31, 2026
    • Technology
      1. AI
      2. Cybersecurity
      3. Crypto
      4. App
      5. Security
      6. View All

      OpenAI Prepares Astra, a New AI Model Built to Find and Exploit Cybersecurity Flaws

      September 2, 2026

      Gemini’s Growing Feature List Highlights a Bigger AI Branding Problem

      August 27, 2026

      Google’s Gemini Reaches 1 Billion Monthly Users as AI Adoption Accelerates

      August 11, 2026

      Rippling Turns Its AI Spending Problem Into a New Employee ROI Tool

      August 7, 2026

      Florida and Texas Take Steps to Remove Flock Surveillance Cameras

      September 2, 2026

      Alabama opens probe into OpenAI after Hugging Face AI breach

      August 24, 2026

      Hackers Target U.S. Financial Firms With Fake IT Calls and Extortion Threats

      August 6, 2026

      CareCloud Data Breach Impacts Hundreds of Thousands as Stolen Medical Records Come to Light

      July 31, 2026

      Binance to Restrict Transactions With HTX and 10 Other Crypto Platforms

      August 14, 2026

      Robinhood Acquires Bitstamp for $200M to Bolster Crypto Presence

      July 18, 2024

      CoinDCX Expands Globally with Acquisition of BitOasis

      July 4, 2024

      IRS Finalizes New Regulations for Crypto Tax Reporting

      July 4, 2024

      Apple Maps Adopts ‘Lake America’ Name in U.S. Following Google

      September 2, 2026

      Instagram introduces First Draft to speed up Reels editing

      August 25, 2026

      Mesh Brings Its Personal CRM to Android

      August 12, 2026

      Google Wallet Adds Parent-Controlled Spending Accounts for Kids

      August 6, 2026

      The Best Antivirus Software in 2026 – Tested, Ranked, and Worth Your Money

      April 7, 2026

      Kaspersky to Cease US Operations and Lay Off Employees Following Government Ban

      July 17, 2024

      Data Breach Exposes Millions of mSpy Customers’ Data

      July 12, 2024

      HealthEquity Describes Data Breach as an ‘Isolated Incident’

      July 4, 2024

      OpenAI Prepares Astra, a New AI Model Built to Find and Exploit Cybersecurity Flaws

      September 2, 2026

      Apple Maps Adopts ‘Lake America’ Name in U.S. Following Google

      September 2, 2026

      Florida and Texas Take Steps to Remove Flock Surveillance Cameras

      September 2, 2026

      Gemini’s Growing Feature List Highlights a Bigger AI Branding Problem

      August 27, 2026
    • Contact
    TechZappi
    Home » Hackers Hijack Chrome Extension to Steal Passwords and Sessions
    Cybersecurity

    Hackers Hijack Chrome Extension to Steal Passwords and Sessions

    December 27, 20242 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity startup Cyberhaven has reported a significant breach involving its Chrome browser extension, which was exploited by hackers to steal user credentials and session tokens. The incident, described as a potential supply-chain attack, was disclosed in an email to affected customers.

    The breach occurred when attackers compromised a company account to release a malicious update (version 24.10.4) to Cyberhaven’s Chrome extension on December 25. The update allowed the theft of sensitive user data, including authenticated sessions and cookies, which could be exploited to access accounts without needing passwords or two-factor authentication. Cyberhaven detected the issue later that day, removed the malicious extension from the Chrome Web Store, and released a secure version (24.10.5) shortly after.

    Cyberhaven, which specializes in data-loss prevention and protecting against cyberattacks, has approximately 400,000 corporate users for its browser extension. Its clientele includes major companies such as Motorola, Reddit, Snowflake, law firms, and health insurance providers. However, the company declined to disclose how many customers were affected.

    In the email to customers, Cyberhaven advised users to revoke and reset all passwords and API tokens while reviewing activity logs for suspicious behavior. The email also warned that session tokens and cookies stolen by attackers could bypass standard security measures. However, the company did not specify whether credentials saved in the Chrome browser should also be updated.

    The compromised account used to publish the malicious update was identified as the “single admin account for the Google Chrome Store.” Cyberhaven did not clarify how this account was breached or detail the security policies in place at the time. The company has since initiated a thorough review of its security practices and plans to implement stronger safeguards.

    To investigate the incident, Cyberhaven has enlisted the support of Mandiant, an incident response firm, and is cooperating with federal law enforcement.

    Cyberhaven’s breach appears to be part of a broader campaign targeting Chrome extension developers. Jaime Blasco, co-founder and CTO of Nudge Security, noted that multiple extensions, some with tens of thousands of users, were affected by similar attacks earlier this year. These breaches included extensions related to AI, productivity, and VPNs.

    Blasco suggested that attackers opportunistically targeted extensions based on compromised developer credentials, rather than specifically focusing on Cyberhaven. The identity of the group behind the campaign remains unknown, and other impacted companies have yet to be identified.

    cybersecurity
    Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
    Previous ArticleApp Downloads Decline Slightly in 2024 as Consumer Spending Surges to $127 Billion
    Next Article Nonprofit Challenges OpenAI’s Shift to For-Profit Model
    admin
    • Website

    Related Posts

    OpenAI Prepares Astra, a New AI Model Built to Find and Exploit Cybersecurity Flaws

    September 2, 2026

    Apple Maps Adopts ‘Lake America’ Name in U.S. Following Google

    September 2, 2026

    Florida and Texas Take Steps to Remove Flock Surveillance Cameras

    September 2, 2026

    Gemini’s Growing Feature List Highlights a Bigger AI Branding Problem

    August 27, 2026
    Leave A Reply Cancel Reply

    Our Picks

    OpenAI Prepares Astra, a New AI Model Built to Find and Exploit Cybersecurity Flaws

    September 2, 2026

    Apple Maps Adopts ‘Lake America’ Name in U.S. Following Google

    September 2, 2026

    Florida and Texas Take Steps to Remove Flock Surveillance Cameras

    September 2, 2026

    Gemini’s Growing Feature List Highlights a Bigger AI Branding Problem

    August 27, 2026
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    AI

    OpenAI Prepares Astra, a New AI Model Built to Find and Exploit Cybersecurity Flaws

    September 2, 2026

    OpenAI is preparing to release Astra, a new AI model that the company says can…

    Apple Maps Adopts ‘Lake America’ Name in U.S. Following Google

    September 2, 2026

    Florida and Texas Take Steps to Remove Flock Surveillance Cameras

    September 2, 2026

    Gemini’s Growing Feature List Highlights a Bigger AI Branding Problem

    August 27, 2026

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

      About Us
      About Us

      TechZappi is your go-to source for the latest tech news, digital trends, and innovation stories. We cover topics ranging from AI and apps to cybersecurity and online tools, helping readers stay informed about what’s happening in the technology world.

      Our Picks

      OpenAI Prepares Astra, a New AI Model Built to Find and Exploit Cybersecurity Flaws

      September 2, 2026

      Apple Maps Adopts ‘Lake America’ Name in U.S. Following Google

      September 2, 2026

      Florida and Texas Take Steps to Remove Flock Surveillance Cameras

      September 2, 2026

      Subscribe to Updates

      Get the latest creative news from Techzappi about Ai, Apps and Cybersecurity.

        Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
        • Home
        • AI
        • App
        • Cybersecurity
        © 2026 TechZappi. All Rights Reserved. Privacy Policy | Terms Of Service

        Type above and press Enter to search. Press Esc to cancel.

        Sign In or Register

        Welcome Back!

        Login to your account below.

        Lost password?