Skip to main content

62 malicious Chrome extensions

·1 min

62 malicious Chrome extensions have found ways around Google’s ban on remote code execution. They’re linked to Phoenix Invicta, Technosense Media, and notably, Sweet VPN. These extensions inject ads and could compromise user data.

Phoenix Invicta, once known as Funteq Inc., has a convoluted corporate setup, with ties to the US, Hong Kong, and operations in Ukraine. They use techniques like manipulating the declarativeNetRequest API to execute remote code, despite Google’s restrictions.

Google’s reaction has been inconsistent; some extensions were removed after being flagged, but similar ones remain active. This situation underscores ongoing security concerns in the Chrome Web Store, highlighting the need for more robust monitoring and enforcement by Google.

Write-up: https://palant.info/2025/01/20/malicious-extensions-circumvent-googles-remote-code-ban/

Related

Unused Domain? Add These DNS Records

·7 mins
Why would an unused domain even need any resources records? # It’s common for domains to go unused. Sometimes they’re purchased for a potential idea or project. Other times, it’s to protect a name or trademark, or maybe they’re meant for use internally on a protected and private network. But the internet does weird stuff and sometimes there are steps that should be taken even if these domains aren’t being used.

This was the event to attend if you're in or around Arkansas and looking for motivated professionals coming into IT and

This was the event to attend if you’re in or around Arkansas and looking for motivated professionals coming into IT and cyber. We definitely needed more small and medium enterprises from our community represented. I was honored to help and to represent Central States Manufacturing, Inc. And while I don’t have an open role right now, I have a great pool of folks to stay in contact with, follow their journey, assist along the way, and hopefully hire when I do.