A cute cover for a dangerous vulnerability. [Research Saturday]
CyberWire Daily18 Tammi 2025

A cute cover for a dangerous vulnerability. [Research Saturday]

Nati Tal, Head of Guardio Labs, sits down to share their work on “CrossBarking” — Exploiting a 0-Day Opera Vulnerability with a Cross-Browser Extension Store Attack. Guardio Labs has uncovered a critical vulnerability in the Opera browser, enabling malicious extensions to exploit Private APIs for actions like screen capturing, browser setting changes, and account hijacking. Highlighting the ease of bypassing extension store security, researchers demonstrated how a puppy-themed extension exploiting this flaw could infiltrate both Chrome and Opera's extension stores, potentially reaching millions of users. This case underscores the delicate balance between enhancing browser productivity and ensuring robust security measures, revealing the alarming tactics modern threat actors employ to exploit trusted platforms. The research can be found here: “CrossBarking” — Exploiting a 0-Day Opera Vulnerability with a Cross-Browser Extension Store Attack

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(3752)

Making cybercrime more difficult.

Making cybercrime more difficult.

The FBI lays out its new Cyber Strategy. CISA plans a federal cyber overhaul. Anthropic discloses another unauthorized AI intrusion. Treasury sanctions a Chinese-language cybercrime marketplace. Anoth...

10 Syys 28min

Clear your calendar, it’s Patch Tuesday.

Clear your calendar, it’s Patch Tuesday.

Patch Tuesday is a doozy. The Feds warn China-based AI companies are distilling U.S. AI models. A new ClickFix campaign goes straight for the browser. Smart TVs get nosy. Hackers gift themselves a $47...

9 Syys 30min

Worming its way through WeChat.

Worming its way through WeChat.

Researchers build a self-propagating attack against WeChat. Threat actors move toward multi-agent AI frameworks. N-able issues an emergency patch for a maximum-severity bug under active exploitation. ...

8 Syys 30min

This call may be monitored. [Special Edition]

This call may be monitored. [Special Edition]

In this Special Episode, Maria Varmazis and Dave Bittner are joined by friend of the show, Brandon Karpf, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese ...

7 Syys 38min

When hackers control the clock. [T-Minus: Space-Cyber Briefing]

When hackers control the clock. [T-Minus: Space-Cyber Briefing]

The accurate timing data from spacecraft has become an invaluable tool for nearly every critical infrastructure sector and a greater target for malicious actors. Host Maria Varmazis and ⁠Andy Davis⁠,...

6 Syys 23min

RMM-ber this ransomware. [Research Saturday]

RMM-ber this ransomware. [Research Saturday]

Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ...

5 Syys 19min

What the Flock?

What the Flock?

The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House’s offensive hacking plan raises legal questions. CISA offers a playbook for communicatin...

4 Syys 31min

Who’s watching the AI watchers?

Who’s watching the AI watchers?

A watchdog challenges the Trump administration’s secret frontier AI reviews. METR discloses two cyberattacks. Leaked documents reveal a Russian cyber training pipeline. Rogue ScreenConnect clients spr...

3 Syys 24min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
vallattomat
aikalisa
politiikan-puskaradio
rss-viihde-media
rss-ootsa-kuullut-tasta
ootsa-kuullut-tasta-2
rss-podme-livebox
otetaan-yhdet
rss-vaalirankkurit-podcast
tervo-halme
rss-voi-venaja
rss-asiastudio
rss-girls-finish-f1rst
rss-raha-talous-ja-politiikka
et-sa-noin-voi-sanoo-esittaa
rikosmyytit
popcorn-with-esko
rss-kaikki-uusiksi
rss-seksicast