Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: extensions Clear Filter

'WhiteCobra' floods VSCode market with crypto-stealing extensions

A threat actor named WhiteCobra has targeting VSCode, Cursor, and Windsurf users by planting 24 malicious extensions in the Visual Studio marketplace and the Open VSX registry. The campaign is ongoing as the threat actor continuously uploads new malicious code to replace the extensions that are removed. In a public post, core Ethereum developer Zak Cole described how his wallet was drained after using a seemingly legitimate extension (contractshark.solidity-lang) for Cursor code editor. Cole

The Buyer’s Guide to Browser Extension Management

While most enterprises lock down endpoints, harden networks, and scan for vulnerabilities, one of the riskiest vectors often slips through unmonitored: browser extensions. These small, user-installed applications can execute privileged code, access sensitive DOM elements, intercept network requests, and even exfiltrate data, all within the context of enterprise-approved browsers. Keep Aware’s new Buyer’s Guide to Browser Extension Management explores how security and IT leaders can achieve comp

Why you should delete your browser extensions right now - or do this to stay safe

Elyse Betters Picaro / ZDNET Follow ZDNET: Add us as a preferred source on Google. ZDNET's key takeaways Malicious browser extensions are a widespread problem. Even vetted extensions can be dangerous. Here's what you should do to avoid issues. Koi Security investigated a single malicious extension used as a color picker and found it had infected 2.3 million users on Chrome and Edge. Cybernews reported in 2024 that more than 350 million people downloaded insecure browsers during a two-year

Wave of 150 crypto-draining extensions hits Firefox add-on store

A malicious campaign dubbed 'GreedyBear' has snuck onto the Mozilla add-ons store, targeting Firefox users with 150 malicious extensions and stealing an estimated $1,000,000 from unsuspecting victims. The campaign, discovered and documented by Koi Security, impersonates cryptocurrency wallet extensions from well-known platforms such as MetaMask, TronLink, and Rabby. These extensions are uploaded in a benign form initially, to be accepted by Firefox, and accumulate fake positive reviews. At a

Show HN: A Raycast-compatible launcher for Linux

Raycast for Linux An open-source, Raycast-inspired launcher for Linux. For more background on this project, I have a post here. Disclaimer: This is a hobby project and is not affiliated with, nor endorsed by, the official Raycast team. ✨ Features This launcher aims to recreate most of Raycast's core features on Linux: Extensible Command Palette : The core of the application. Search for and launch applications, run commands, execute quicklinks, and more. : The core of the application. Sear

The zero-day that could've compromised every Cursor and Windsurf user

A security researcher from Koi Security stumbled upon a critical zero-day buried deep in the infrastructure powering today’s AI coding tools. Had it been exploited, a non-sophisticated attacker could’ve hijacked over 10 million machines with a single stroke. AI coding assistants like Cursor and Windsurf have exploded in popularity, promising supercharged productivity for developers around the world. Behind their sleek interfaces lies a shared foundation: community-built VS Code forks and an ope

Browser extensions turn nearly 1 million browsers into website-scraping bots

Extensions installed on almost 1 million devices have been overriding key security protections to turn browsers into engines that scrape websites on behalf of a paid service, a researcher said. The 245 extensions, available for Chrome, Firefox, and Edge, have racked up nearly 909 million downloads, John Tuckner of SecurityAnnex reported. The extensions serve a wide range of purposes, including managing bookmarks and clipboards, boosting speaker volumes, and generating random numbers. The common

Malicious Chrome extensions with 1.7M installs found on Web Store

Almost a dozen malicious extensions with 1.7 million downloads in Google's Chrome Web Store could track users, steal browser activity, and redirect to potentially unsafe web addresses. Most of the add-ons provide the advertised functionality and pose as legitimate tools like color pickers, VPNs, volume boosters, and emoji keyboards. Researchers at Koi Security, a company providing a platform for security self-provisioned software, discovered the malicious extensions in Chrome Web Store and rep

Dozens of fake wallet add-ons flood Firefox store to drain crypto

More than 40 fake extensions in Firefox’s official add-ons store are impersonating popular cryptocurrency wallets from trusted providers to steal wallet credentials and sensitive data. Some of the extensions pretend to be wallets from Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, and MyMonero, and include malicious code that sends stolen information to attacker-controlled servers. Fake wallet extensions on the Firefox add-ons store Source: BleepingComputer Researchers at Koi

Gemini Live looks like it’s getting ready to work with all your favorite apps (APK teardown)

Rita El Khoury / Android Authority TL;DR Back in May, Google announced the first wave of Gemini Live extension support. Initial extensions for Maps, Calendar, Keep, and Tasks are slowly starting to hit users. Beyond these, we’ve uncovered a large list of Live extensions that appear to be in development. Gemini Live has been both technically impressive and quite a bit of fun to interact with, right from the get-go; the combination of Gemini’s powerful models and a naturally flowing conversati

New Firefox Add-On Policies

We’ve updated Add-on policies for addons.mozilla.org (AMO). Here’s a summary of the changes and their impact on AMO’s publishing process. Our main objective was to simplify and clarify Add-on policies for the developer community. The following policy updates will take effect on 4 August, 2025. “Closed group” prohibition lifted Closed group extensions are typically intended for internal or private use among a relatively small group of users. In the past AMO did not allow closed group extensions

Google just made it way easier to use Chrome extensions on Android — here’s how

Mishaal Rahman / Android Authority TL;DR Google is developing a new version of Chrome for Android that supports extensions, and recent builds show significant progress. It’s now possible to install Chrome extensions directly from the Chrome Web Store, and they will persist even after restarting the browser. The feature is still experimental and intended for future Android-powered PCs, but anyone can sideload the APK to try it now. While Google Chrome is by far the most popular browser on And

Trump gives TikTok another ban extension

is a senior policy reporter at The Verge, covering the intersection of Silicon Valley and Capitol Hill. She spent 5 years covering tech policy at CNBC, writing about antitrust, privacy, and content moderation reform. For the third time, President Donald Trump has extended the deadline for TikTok to spin out from its Chinese parent company or face a US ban. As White House Press Secretary Karoline Leavitt confirmed in a statement Tuesday, Trump signed an executive order on Thursday extending the

OxCaml - a set of extensions to the OCaml programming language.

Let’s talk about what this means! OxCaml’s extensions are meant to make OCaml a great language for performance engineering. Performance engineering requires control, and we want that control to be: Safe. Safety is a critical feature for making programmers more productive, and for shipping correct code. Languages that are pervasively unsafe are too hard to use correctly. Convenient. We want to provide control without bewildering programmers, or drowning them in endless annotations. To achieve

Google Chrome disables uBlock Origin for some in Manifest v3 rollout

Google continues its rollout of gradually disabling uBlock Origin and other Manifest V2-based extensions in the Chrome web browser as part of its efforts to push users to Manifest V3-based extensions. For those unaware, Manifest V3 is Chrome's latest extension specification and is designed to limit extension access to user network requests, block developers from utilizing remote content, and improve overall performance. While Manifest V3 is supposed to benefit end users, it comes at the cost o