Think browser extensions are harmless? Think again. A multi-year campaign turned popular, trusted browser add-ons into full-blown spyware featuring remote code execution, session hijacking, token theft and real-time browsing surveillance.

If you’re managing enterprise security, audit all extensions now, enforce allow-lists, and treat them as part of your software supply chain.

Read the blog here: https://www.lmgsecurity.com/4-3-million-reasons-to-rethink-browser-extension-security/

#browserextensions #cyberrisk #threatintelligence #endpointsecurity #supplychainsecurity #identityprotection #enterpriseIT

4.3 Million Reasons to Rethink Browser Extension Security | LMG Security

ShadyPanda hijacked 4.3M browsers through trusted extensions. See how the attack worked and the steps your team needs to take to close this overlooked supply-chain gap.

LMG Security