Connect with us

Entertainment

New browser syncjacking cyberattack lets hackers take over your computer via Chrome

Hackers have discovered a new way to remotely take control of your computer — all through the Google Chrome web browser.

A report from cybersecurity company SquareX lays out the new multifaceted cyberattack, which the firm has dubbed “browser syncjacking.”

Chrome profile takeover

At the core of the attack is a social engineering element, as the malicious actor first must convince the user to download a Chrome extension. The Chrome extension is usually disguised as a helpful tool that can be downloaded via the official Chrome Store. It requires minimal permissions, further cementing its perceived legitimacy to the user. According to SquareX, the extension actually does usually work as advertised, in order to further disguise the source of the attack from the user.

Meanwhile, secretly in the background, the Chrome extension connects itself to a managed Google Workspace profile that the attacker has set up in advance. With the user now unknowingly signed into a managed profile, the attacker sends the user to a legitimate Google support page which is injected with modified content through the Chrome extension, telling the user they need to sync their profile.

When the user agrees to the sync, they unwittingly send all their local browser data, such as saved passwords, browsing history, and autofill information, to the hacker’s managed profile. The hacker can then sign into this managed profile on their own device and access all that sensitive information.

Mashable Light Speed

Chrome browser takeover

The attack up to this point already provides the hacker with enough material to commit fraud and other illicit activities. However, browser syncjacking provides the hacker with the capability to go even further.

Using the teleconferencing platform Zoom as an example, SquareX explains that using the malicious Chrome extension, the attacker can send the victim to an official yet modified Zoom webpage that urges the user to install an update. However, the Zoom download that’s provided is actually an executable file that installs a Chrome browser enrollment token from the hacker’s Google Workspace.

After this occurs, the hacker then has access to additional capabilities and can gain access to the user’s Google Drive, clipboard, emails, and more.

Device takeover

The browser syncjacking attack doesn’t stop there. The hacker can take one further step in order to not just take over the victim’s Chrome profile and Chrome browser, but also their entire device.

Through that same illicit download, such as the previously used Zoom update installer example, the attacker can inject a “registry entry to message native apps” by weaponizing Chrome’s Native Messaging protocol. By doing this, the attacker basically sets up a connection “between the malicious extension and the local binary.” Basically, it creates a flow of information between the hacker’s Chrome extension and your computer. Using this, the hacker can send commands to your device.

What can the hacker do from here? Pretty much anything they want. The attacker will have full access to the user’s computer files and settings. They can create backdoors into the system. They can steal data such as passwords, cryptocurrency wallets, cookies, and more. In addition, they can track the user by controlling their webcam, take screenshots, record audio, and monitor everything input into the device.

As you can see, browser syncjacking is nearly completely unrecognizable as an attack to most users. For now, the most important thing you can do to protect yourself from such a cyberattack is to be aware of what you download and only install trusted Chrome extensions.


source

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Entertainment

Best Mothers Day gifts: Show mom some love

Mother figures are the backbone of the world. Yours may be your biological mother, or maybe she’s your mother-in-law, your best friend’s mom, or simply someone whose motherly instinct has helped you through hard times.

Moms teach you the adulting necessities, give advice even if the problem is your fault, and above all, they put up with your shit and (almost) never complain.

The game plan here isn’t just to snag the last bouquet at CVS just so you’re not the kid who forgot Mother’s Day (but definitely also get flowers). And you don’t even need to spend a lot of money. (Peep our list of Mother’s Day gifts that cost less than $50. Want even more cheap gift ideas?

Skip the generic mugs and show your appreciation with a gift picked just for her: Whether it’s something to make a part of her life easier, something she’s mentioned wanting in passing, or simply something to make her feel like a damn queen, you can’t put a price on everything she’s done for you, but heartfelt gifts certainly help.

After all, they say “No matter how hard you try, you always end up like your mother.” But is that even a bad thing?


source

Continue Reading

Entertainment

Ban subscriptions and get Microsoft Office 2024 for life for just £121

TL;DR: Grab Microsoft Office 2024 Home and Business for PC or Mac for just £120.54 through June 1.


You wouldn’t keep paying for Netflix if you could own your favorite shows, right? So why are you still subscribing to Office apps you use every day? Microsoft 365’s price keeps going up, but there’s finally a way to break free — and it’ll cost you way less in the long run.

Microsoft Office 2024 is the answer you’ve been looking for. Instead of monthly payments, simply pay £120.54 once and be set for life (reg. £188.37). It’s that simple. And, yes, this lifetime download works for PC or Mac.

What’s included?

This license comes with: 

  • Word

  • Excel

  • PowerPoint

  • Outlook

  • OneNote 

The newest version of Microsoft Office is a little different from Microsoft 365. But just because you’re switching to a lifetime license doesn’t mean you’ll miss out on some of the most recent updates. Word and Excel both still have AI integrations for text suggestions and smart data analysis, and PowerPoint still has improved tools for recorded presentations. 

Once you’ve redeemed your purchase, you can install your apps on one computer. After that, they’re yours to use however you want. No more subscription fees or sudden price hikes to worry about. 

Why rent when you can own? 

Mashable Deals

Get a Microsoft Office lifetime license on sale for £120.54 with no coupon needed.

StackSocial prices subject to change.


source

Continue Reading

Entertainment

Wordle today: Answer, hints for May 9, 2025

Oh hey there! If you’re here, it must be time for Wordle. As always, we’re serving up our daily hints and tips to help you figure out today’s answer.

If you just want to be told today’s word, you can jump to the bottom of this article for today’s Wordle solution revealed. But if you’d rather solve it yourself, keep reading for some clues, tips, and strategies to assist you.

Where did Wordle come from?

Originally created by engineer Josh Wardle as a gift for his partner, Wordle rapidly spread to become an international phenomenon, with thousands of people around the globe playing every day. Alternate Wordle versions created by fans also sprang up, including battle royale Squabble, music identification game Heardle, and variations like Dordle and Quordle that make you guess multiple words at once

Wordle eventually became so popular that it was purchased by the New York Times, and TikTok creators even livestream themselves playing.

What’s the best Wordle starting word?

The best Wordle starting word is the one that speaks to you. But if you prefer to be strategic in your approach, we have a few ideas to help you pick a word that might help you find the solution faster. One tip is to select a word that includes at least two different vowels, plus some common consonants like S, T, R, or N.

What happened to the Wordle archive?

The entire archive of past Wordle puzzles was originally available for anyone to enjoy whenever they felt like it, but it was later taken down, with the website’s creator stating it was done at the request of the New York Times. However, the New York Times then rolled out its own Wordle Archive, available only to NYT Games subscribers.

Is Wordle getting harder?

It might feel like Wordle is getting harder, but it actually isn’t any more difficult than when it first began. You can turn on Wordle‘s Hard Mode if you’re after more of a challenge, though.

Here’s a subtle hint for today’s Wordle answer:

Gibberish.

Mashable Top Stories

Does today’s Wordle answer have a double letter?

There are no recurring letters.

Today’s Wordle is a 5-letter word that starts with…

Today’s Wordle starts with the letter T.

The Wordle answer today is…

Get your last guesses in now, because it’s your final chance to solve today’s Wordle before we reveal the solution.

Drumroll please!

The solution to today’s Wordle is…

TRIPE.

Don’t feel down if you didn’t manage to guess it this time. There will be a new Wordle for you to stretch your brain with tomorrow, and we’ll be back again to guide you with more helpful hints.

Are you also playing NYT Strands? See hints and answers for today’s Strands.

Reporting by Chance Townsend, Caitlin Welsh, Sam Haysom, Amanda Yeo, Shannon Connellan, Cecily Mauran, Mike Pearl, and Adam Rosenberg contributed to this article.

If you’re looking for more puzzles, Mashable’s got games now! Check out our games hub for Mahjong, Sudoku, free crossword, and more.

Not the day you’re after? Here’s the solution to yesterday’s Wordle.


source

Continue Reading