惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
H
Hacker News: Front Page
Stack Overflow Blog
Stack Overflow Blog
B
Blog
I
InfoQ
GbyAI
GbyAI
T
The Blog of Author Tim Ferriss
F
Fortinet All Blogs
Y
Y Combinator Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
月光博客
月光博客
Hugging Face - Blog
Hugging Face - Blog
爱范儿
爱范儿
F
Full Disclosure
Hacker News - Newest:
Hacker News - Newest: "LLM"
Recent Announcements
Recent Announcements
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Jina AI
Jina AI
T
Tailwind CSS Blog
S
Secure Thoughts
P
Privacy International News Feed
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
L
LINUX DO - 最新话题
H
Hackread – Cybersecurity News, Data Breaches, AI and More
C
Cybersecurity and Infrastructure Security Agency CISA
Last Week in AI
Last Week in AI
W
WeLiveSecurity
Google Online Security Blog
Google Online Security Blog
P
Privacy & Cybersecurity Law Blog
D
DataBreaches.Net
Engineering at Meta
Engineering at Meta
Know Your Adversary
Know Your Adversary
P
Palo Alto Networks Blog
I
Intezer
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Project Zero
Project Zero
V2EX - 技术
V2EX - 技术
H
Heimdal Security Blog
博客园 - Franky
阮一峰的网络日志
阮一峰的网络日志
D
Darknet – Hacking Tools, Hacker News & Cyber Security
T
Troy Hunt's Blog
V
Vulnerabilities – Threatpost
H
Help Net Security
Martin Fowler
Martin Fowler
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
G
GRAHAM CLULEY
博客园 - 【当耐特】

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers Companies And H-1B Employees Endure Immigration Waits At Consulates 3 Easy Ways To Turn Anxiety Into Sustained Focus, By A Psychologist Here’s The Most Affordable Humanoid Robot You Can Buy Now UFC 327 Results: 5 Biggest Takeaways From A Wild Night In Miami UFC 327 Results, Bonus Winners, Highlights And Reactions Dana White Announces Huge New Fight For UFC White House Today’s NYT Strands Hints, Spangram, Answers: Sunday, April 12 (Get Ready) Tesla ‘Model 2’ Rises From The Ashes Today’s Wordle #1758 Hints And Answer For Sunday, April 12 NYT Pips Today: Hints, Answers And Walkthrough For Sunday, April 12 Tyson Fury Vs. Arslanbek Mahkmudov Results: Highlights and Reaction NYT Mini Crossword Today: Sunday, April 12 Hints And Answers How Shadow AI Culture Is Destroying Your Business Venture Capital Funds That Market Like Startups Win More Deals Conor Benn Vs. Regis Prograis Results: Highlights and Reaction Samsung’s Disappointing Price Update For Galaxy Phone Buyers Artemis Reached The Moon. The Grid Can Reach The 21st Century A Biologist Explains How Archerfish Shoot Down Prey. Hint: Their Aim Rivals Human Throwing Is It Time For Apple To Forget About The MacBook Air NYT Connections Hints Today: Sunday, April 12 Clues And Answers (#1036) Trump’s 2027 Budget To Reshape U.S. Environmental And Energy Policy CDC Delays Reporting Of COVID-19 Vaccine Benefits—Here’s What To Know Oura Has Designed A Solution To A Big Smart Ring Problem Netflix’s Best New Show Has A Near-Perfect 95% Rotten Tomatoes Score Coachella 2026 Is Being Taken Over By Creator Streams Quordle Hints Today: Sunday, April 12 Clues And Answers This Startup Wants To Use AI To Help Digitize History How To Get The Best Shield In ‘Crimson Desert’ Microsoft Venom Attack Targets C-Suite Executives ‘Maul: Shadow Lord’ Sets Even More Star Wars Rotten Tomatoes Records 3 Ways Happy Couples Argue Differently, By A Psychologist Success For Leapmotor Might Have Negatives For Stellantis New Names Surface As Potential Rogue And Wonder Woman In The MCU And DCU 4 Reasons Artemis Mission Matters Even If You Think It Is Wasteful Fast ‘Crimson Desert’ Patch Adds New Moves, Shield Hiding And One Great Feature Why Do Humans Blush? An Evolutionary Biologist Explains The Signal We Can’t Control Apple iPhone Fold: Striking Design Revealed In Leaked Photos Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update iOS 26.4.1 Release: Crucial iPhone Feature Update Arrives, But No Security Fix Fury vs. Makhmudov Full Card, Ring Walk Times and How to Watch Can’t Stand Liquid Glass? This New Hidden iPhone Setting Is A Game-Changer Test-Driving The 2026 Changan Deepal S05: Italian Style Made In China NSA Warning—Reboot Your Internet Router Now Ways That Human-AI Collaboration Slides People Into ‘AI Brain Fry’ And Cognitive Downturns Stop Using These Networks—Google, NSA And TSA Warn NASA Changes Moon Plan: Landing Now Depends On SpaceX Or Blue Origin Samsung Expands One UI 8.5 Beta To More Galaxy Owners The Evolution Of Programmable Hardware At Xilinx NYT Mini Today: Saturday, April 11 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Saturday, April 11 (You’re Putting Me On) Splashdown! NASA’s Artemis II Returns To Earth After Moon Mission Attention Is All You Need. The Human Kind Is Still The One That Counts Today’s Wordle #1757 Hints And Answer For Saturday, April 11 NYT Pips Today: Hints, Answers And Walkthrough For Saturday, April 11 Android Circuit: Galaxy S27 Pro Emerges, Honor 600 Pre-Order Offers, Pixel 11 Display Leaks Apple Loop: iPhone 18 Pro Leak, Urgent iOS Update, MacBook Neo Issues Morgan Stanley Has Mostly Positive Outlook On Tesla Robotaxi, FSD V15 Running Out Of AI Tokens Faster Than Ever? Here’s Why CoreWeave Shares Pop 13% After Anthropic Deal ‘Euphoria’ Season 3’s Rotten Tomatoes Score Crashes, Has Lost Key Player People Don’t Agree On What AI Can Do, But They Don’t Even Use The Same Product ‘Overwhelming’—Google Issues Gemini Update For Gmail Users NYT Connections Hints Today: Saturday, April 11 Clues And Answers (#1035) Quordle Hints Today: Saturday, April 11 Clues And Answers The Costly Dream Of Space-Based AI Infrastructure Can You See The Watcher In This ‘Daredevil: Born Again’ Shot? Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update You Just Watched The Backdoor Pilot For ‘The Pitt: Night Shift’ Are Nicotine Pouches Like Zyn And VELO Safe To Use? A Doctor Answers Human Resources (HR) Is The Key To AI Success Per WalkMe ( SAP)
Extensions Are The Next Enterprise Attack Surface
Tannu Jiwnani · 2026-05-04 · via Forbes - Innovation

Tannu Jiwnani is a cybersecurity leader focused on incident response, IAM and threat detection, with a passion for resilience and community.

getty


In most organizations, the browser has become the operating system for work, and extensions are the plug-ins that can quietly reshape it. They deliver productivity gains: translation, meeting notes, workflow automation and AI assistance.

However, the same one-click install experience that makes extensions feel frictionless also makes them easy to misuse. "Add to browser" can be a decision that silently expands your attack surface for months.​

In February 2026, BleepingComputer reported that researchers at LayerX found a coordinated campaign of malicious extensions called AiFrame that masqueraded as AI assistants. The set reached more than 300,000 users and was observed collecting credentials, browsing data and even email content. Users thought they were installing helpful tools but were actually authorizing code that could see and export what their browser could see.​

This pattern is what worries me most. Extensions rarely feel like "software," so they often bypass the skepticism users apply to apps, downloads or links. Yet extensions can run with privileged access to sessions, pages and identity flows exactly where enterprises concentrate their most sensitive work. Learning to evaluate extensions before installing them is now a baseline hygiene skill, and for security teams, it needs to be treated as a governance problem rather than just a user choice.

Why Browser Extensions Are A Growing Security Risk

Extensions run in the same place where we do our most valuable work: email, collaboration tools, cloud consoles and business applications. Once installed, they can read page content, observe activity and interact with web apps. These capabilities are powerful when used responsibly but risky when abused.

Attackers exploit the fact that malicious extensions can look identical to legitimate ones. They mimic AI assistants, translation tools, productivity apps and even security utilities, often building credibility through branding and install counts. According to BleepingComputer, fake AI extensions have been designed to capture webpage content, including sensitive data and email information.

Being in the official store doesn't necessarily mean an extension is safe.

The Rise Of AI-Themed Extension Attacks

The AI boom has become an effective delivery vehicle for browser based threats. Users want AI features everywhere, and an "AI sidebar" promising instant productivity is an easy sell with little installation friction.

Attackers exploit this demand by disguising malicious extensions as AI assistants or productivity tools. In the AiFrame campaign, the extensions didn't run AI locally. Instead, they loaded content from remote servers while collecting user data in the background. That architecture also allowed operators to change behavior server-side without shipping a new extension version for review.

As AI features become standard, we should expect "AI-branded" extensions to remain a high-confidence lure for attackers.

​What Malicious Extensions Can Actually Do

The permissions you grant define the capabilities of an extension. With the wrong permissions or the wrong publisher, an extension can behave like a surveillance and data-exfiltration agent inside your most trusted workflows.

OWASP Cheat sheet highlights that browser extensions can introduce serious security risks when they request excessive permissions, expose sensitive data or inject scripts into webpages. Vulnerabilities such as permission overreach, data leakage and code injection can allow extensions to access browsing activity, sensitive user information or modify webpage behavior and effectively turn everyday browsing into a potential attack path.

In the AiFrame campaign, a subset of extensions would read message content directly from the page and send it to attacker-controlled infrastructure. Because this happens inside the browser session, it can evade controls that focus only on the network perimeter.​

Red Flags To Watch For Before Installing An Extension​

Extensions can be useful, but leaders should evaluate them like any software with privileged access. A few quick checks can reduce much of the risk:

1. Excessive Permissions: If an extension asks to read or change data across all websites, treat it as a warning sign. Broad access is rarely necessary and increases risk.

2. Unknown Or Unverified Publishers: Verify who created the extension. Legitimate developers usually have a clear company identity, website and support channels.

3. Unclear Ownership Or Data Practices: If you can't quickly determine who owns the extension or how it handles user data, assume additional risk.

4. New Extensions With High Install Counts: Be cautious of recently released extensions that suddenly show large numbers of installs. Popularity can be artificially inflated.

5. Generic AI Or Productivity Claims: Vague descriptions focused on marketing rather than explaining permissions, data use or processing should raise concerns.

6. Suspicious Reviews: Use reviews as a signal. Multiple reports of pop-ups, broken pages, unexpected logouts or unusual data requests are good reasons to pause.

What Security Teams Should Consider

For enterprises, extensions create an uncomfortable gap between "shadow IT" and "privileged code." Employees install them to solve real problems, but those installs often happen outside of formal review, inventory and risk management.

Security teams should consider controls such as:

• Allow lists that restrict installs to approved extensions
• Browser security monitoring to detect suspicious extension behavior
• Targeted user education on extension specific risks
• Periodic reviews of installed extensions and their permissions

In identity-driven environments, this matters even more. Tokens, sessions and sensitive workflows increasingly live in the browser. If the browser session is compromised, attackers can gain access to cloud services, collaboration platforms and internal applications without "breaking in" the way defenders expect.

A Simple Rule

Most security failures aren't the result of one dramatic moment. They're the result of small, convenient choices repeated over time. Installing an extension takes seconds, but the access it gains can persist for months or years across every site and session you use.

The next time you see "add to browser," pause. A 30-second permissions check today can prevent an incident response tomorrow​.


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?