Cyberhaven reports hack that led to malicious Chrome extension update

techcrunch.com December 27, 2024, 08:01 PM UTC

Cyberhaven, a data-loss prevention startup, reported a cyberattack that allowed hackers to publish a malicious update to its Chrome extension. This update could steal sensitive information, including passwords and session tokens, from users. The attack occurred on December 25, when hackers compromised a company account to release the harmful extension. Cyberhaven quickly removed the malicious version and released a legitimate update. The company is reviewing its security practices and has hired an incident response firm. Cyberhaven indicated that this incident is part of a broader campaign targeting Chrome extension developers. Other extensions may have also been compromised, but details on the extent of the attacks and responsible parties remain unclear.


With a significance score of 3.6, this news ranks in the top 21% of today's 18482 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 8000 minimalists.