Chrome, Firefox browser extensions leaked millions of users' data

Agencies
July 20, 2019

Popular browser extensions like ad blockers have been caught harvesting personal data of millions of consumers who use Chrome and Firefox -- not only their browsing histories but also exposing tax returns, medical records, credit card information and other sensitive data in the public domain.

According to an independent cyber security researcher Sam Jadali, the data has been leaked to a fee-based company called Nacho Analytics that gives unlimited access to any websites analytics data.

The data could be purchased for as little as $10 to $50, said Jadali whose report was first described in Ars Technica late on Friday.

"This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.

"Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services" have been exposed, said the report.

The exposed data via eight browser extensions also include vehicle identification, numbers of recently bought automobiles, along with the names and addresses of the buyers.

Patient details, travel itineraries, Facebook Messenger attachments and Facebook photos, even private, are now available in the public domain.

Browser extensions - also known as plug-ins or add-ons - are apps that consumers can install to run alongside their browser for additional functionality.

The affected extensions were apps used by millions of people, including HoverZoom, SpeakIt!, and FairShare Unlock.

"The extensions have been remotely removed or disabled in consumers' browsers and are no longer available for download," said both Google and Firefox.

People who didn't download the extensions may also be affected.

"Nobody is immune to this. Even if you don't have any harmful extensions, the other people you interact with may have an extension on their computers that could be leaking the data you share with them," Jadali was quoted as saying.

Nacho Analytics, for example, promises to let people "see anyone's analytics account" and to provide "real-time web analytics for any website".

The company charges $49 per month, per domain, to monitor any of the top 5,000 most widely-trafficked websites.

The security expert has suggested users to delete all browser extensions they have installed in the past.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
February 9,2020

New Delhi, Feb 8: Arvind Kejriwal is set to return as Delhi chief minister and his Aam Aadmi Party (AAP) will virtually sweep the assembly elections, exit polls predicted Saturday.

As polling came to a close at 6 pm, with the Election Commission of India (ECI) projecting a voter turnout at 60.24% (as of 9:50 pm), a poll of polls covering 10 exit polls gave 52 seats to AAP, 17 to the Bharatiya Janata Party and one to the Indian National Congress.

The polls, which are sample surveys conducted among voters exiting polling booths, signalled that the Delhi voter responded to AAP’s campaign that focused on “kaam”, or getting work done.

Kejriwal, a former civil servant and activist who stormed into electoral politics with an anti-corruption campaign in 2013, led a campaign focusing on the development work his government did in Delhi, especially in education and healthcare, as well as sops such as lower electricity bills and free bus rides for women.

The exit polls gave AAP between 47 and 68 seats in the 70-member Assembly.

They predicted an absolute rout for Congress, which ruled Delhi for three terms between 1998 and 2013. The maximum seats to AAP were given by India Today TV-Axis exit poll, which predicted 59-68 seats for the party, while giving 2-11 for the BJP and none to the Congress.

If these figures hold, the results will come as a disappointment for the BJP, which had hoped its sweep in the Lok Sabha elections in 2019 would reflect in the assembly polls.

Delhi’s voter turnout saw a sharp fall over the 2015 elections. According to the Election Commission of India, voter turnout till 9 pm was projected at 60.24% — lower than 67.12% in 2015.

Traditionally, a lower voter turnout is read as a vote for the incumbent.

The voter turnout in Delhi has been similar during the Congress regime under Sheila Dikshit, when she won consecutive terms. In 2003, when Delhi voted a second time for the Dikshit government, the voter turnout was 53.42%, and a comparable 57.58% was the turnout in 2008.

Later, in two consecutive elections — 2013 and 2015 — voters turned out in big numbers to vote Dikshit out of power. In 2013, 65.63% of Delhi turned out and the percentage increased further to 67.12% in 2015.

Across constituencies, Matia Mahal in Central Delhi registered the highest voter turnout of 68.36%, whereas Bawana assembly constituency in North district saw the lowest turnout at 41.95%. Among districts, North East district registered the highest (62.75%) voter turnout, while the lowest turnout was recorded in South East district (54.15%), according to the ECI app.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 3,2020

New Delhi, Mar 3: Delhi's Tihar Prison authorities had made all necessary preparations for the hanging of four convicts in the Nirbhaya gangrape-and-murder case which was scheduled for Tuesday, officials said Monday.

However, on Monday evening, a city court deferred the hanging till further orders.

Postponing the execution, Additional Sessions Judge Dharmender Rana said the hanging cannot be carried out pending disposal of Pawan Gupta's mercy plea before the President, observing any condemned convict must not meet his "Creator" with grievance against courts for not acting fairly on the opportunity to exhaust legal remedies.

"We had made all the necessary arrangements for the execution of the four convicts which was scheduled for Tuesday at 6 AM. Now, the execution has been postponed and we are waiting for the further order by the court," a senior jail official said.

The hanging of the four men -- Mukesh Kumar Singh (32), Vinay Kumar Sharma (26), Akshay Kumar Singh (31) and Pawan -- who are lodged in Tihar jail, was fixed for March 3 in Tihar jail on a court order.

"We had checked the ropes. Hangman was called and dummy executions were carried out," another senior jail official said.

Barring Pawan, the other three had in the previous weeks moved curative petitions and mercy pleas which were all dismissed.

The first date of execution -- January 22 -- fixed on January 7 was postponed by the court to February 1. But on January 31, the court indefinitely postponed the hanging. On February 17, the court again issued fresh date for execution of death warrants for March 3 at 6 AM.

The court in its orders observed that the four convicts cannot be hanged since a mercy plea of one or the other convict was pending.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
January 10,2020

Indian enterprises were flooded with a whopping 14.6 crore malware threats in 2019 - a growth of 48 per cent (year-on-year) compared to 2018, a new report said on Friday.

Manufacturing, BFSI (banking, financial services and insurance), education, healthcare, IT/ITES, and the government were the most at-risk industries in the country, said the report from Seqrite, the enterprise arm of Pune-based IT security firm Quick Heal Technologies.

Interestingly, almost a quarter (23 per cent) of the threats were identified through 'Signatureless behaviour-based' detection by Seqrite, indicating how a growing number of cybercriminals were deploying new or previously unknown threat vectors to compromise enterprise security.

"With the latest Seqrite annual threat report, we want to empower CIOs, CISOs, business leaders and all key public stakeholders with the insights they need to combat the growing complexity of the threat landscape," said Sanjay Katkar, Joint Managing Director and CTO, Quick Heal Technologies.

The most prominent trend was the drastic increase in the volume, intensity, and sophistication of cyber-attack campaigns targeting Indian enterprises in 2019.

The rapid integration of IoT devices, BYOD (bring your own device), and third-party APIs into enterprise networks has created newer security vulnerabilities that might go unnoticed until a major breach occurs.

Threat researchers at Seqrite observed several large-scale advanced persistent threats (APT) attacks deployed against organisations in the government sector.

"The entry of nation-states and organised cybercrime cells into the fray is expected to add more complication to this situation and will require Indian government bodies and corporate enterprises to shore up their cyber defence strategies in 2020 and beyond," the report noted.

More alarming, however, was the continued lack of security awareness amongst enterprises and government organisations.

"Unsecured Remote Desktop Protocol (RDP) and Server Message Block (SMB) protocols continued to be targeted through brute-force attacks," said the report.

Spear phishing attack campaigns leveraging Office exploits and infected macros were also used extensively by cybercriminals to gain access to enterprise networks and steal critical data.

"India's digital journey depends on ensuring robust cybersecurity for all stakeholders within the enterprise ecosystem," said Katkar.

The sharp spike should be a cause of concern for CIOs and CISOs in the country, especially given the growing digital penetration within their enterprise networks.

"With network vulnerabilities and potential entry points increasing at a rapid pace, threat actors are expected to leverage artificial intelligence (AI) capabilities to power their malware campaigns in the future to capitalise on newer attack vectors," the report added.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.