Every story tagged Data Harvesting, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
1 story · open in the command center
Security researchers discovered 108 malicious Chrome extensions with approximately 20,000 total downloads that inject ads and harvest user data, all communicating with the same command-and-control server indicating a coordinated operation. These extensions disguised themselves as legitimate utility tools and many remain active in the Chrome Web Store, posing significant credential theft and data privacy risks to enterprise users. This incident underscores the broader supply chain security vulnerabilities in browser extensions, following similar high-profile cases, and highlights a critical blind spot in enterprise security policies that typically focus on application whitelisting but often overlook browser extension governance.