Tootfinder

Opt-in global Mastodon full text search. Join the index!

@veit@mastodon.social
2026-02-16 08:59:51

The security company LayerX has found a critical vulnerability in Anthropic’s Claude Desktop Extensions (DXT). A manipulated Google Calendar entry can execute arbitrary code on the computer without any user interaction. Although the vulnerability received the highest possible severity rating of 10 out of 10 on the common CVSS, Anthropic does not intend to fix the problem for the time being:

@kubikpixel@chaos.social
2026-04-16 05:05:07

«Über 100 Erweiterungen — Schädliche Chrome-Extensions greifen Nutzerdaten ab:
Im Chrome Web Store verbreiten Cyberkriminelle über 100 schädliche Erweiterungen, die Nutzerkonten und Daten stehlen. Die Tools sind Teil einer koordinierten Kampagne mit gemeinsamer Infrastruktur.»
Ein Argument mehr um Chrome zu vermeiden und egal auf welchem Browser nicht blind jegliche Plugins nutzen. Seit Jahr(zent)en ein Thema.
😈

@Sustainable2050@mastodon.energy
2026-04-06 16:38:04

Every time you visit LinkedIn in Chrome, a hidden routine silently probes your browser for more than 6,000 installed extensions, collects 48 hardware and software characteristics about your device, encrypts the resulting fingerprint, and attaches it to every API request you make during your session.

@zachleat@zachleat.com
2026-04-17 14:25:58

are folks actually using this feature? seems like a wild risk of security exposure to give it unfettered access to all of your web sessions/tokens claude.com/claude-for-chrome
thinking about how this interacts with password manager browser extensions that automatically log-in to various site…

@johnleonard@mastodon.social
2026-04-07 12:38:00

Professional networking platform LinkedIn has been quietly collecting detailed information about users' devices and installed browser extensions, a new security report has alleged.

@burningbecks@social.tchncs.de
2026-04-12 12:03:07

« WebinarTV is actively scraping and redistributing both public and private Zoom webinars without knowledge or consent of organizers. Initial access is typically gained through third-party browser extensions such as AI-powered transcription or auto-join tools »
cyberalberta.ca/zo…

@shaun@mastodon.xyz
2026-02-08 16:13:07

We need one of those cloud-to-butt browser extensions that replaces every occurrence of “AI” with “artificial insemination”
#cloud #butt #ai

@digitalnaiv@mastodon.social
2026-04-07 17:08:03

LinkedIn. Netzwerk für Business-Kasper — und offenbar auch stiller Datenstaubsauger.
🔴 Wer sich verifiziert, gibt Reisepass Biometrie an ein US-Unternehmen weiter. Haftung bei Datenpanne: 50 Dollar.
🔴 Und bei jedem Besuch scannt LinkedIn deinen Chrome-Browser — 6.000 Extensions, ohne dein Wissen. Klage läuft am LG München.

@chrislowles@mastodon.social
2026-02-07 06:53:38

I pray for the devs of browser extensions that have active audiences, shits gotta be exhausting.

@deepthoughts10@infosec.exchange
2026-01-25 23:34:18

RE: mastodon.social/@campuscodi/11
Catalin makes a good point here: if you can, you should try to actively manage the browser extensions your business users are allowed to install. There are multiple ways to do this on Windows, u…