Chrome, Firefox browser extensions leaked millions of users' data

Agencies
July 20, 2019

Popular browser extensions like ad blockers have been caught harvesting personal data of millions of consumers who use Chrome and Firefox -- not only their browsing histories but also exposing tax returns, medical records, credit card information and other sensitive data in the public domain.

According to an independent cyber security researcher Sam Jadali, the data has been leaked to a fee-based company called Nacho Analytics that gives unlimited access to any websites analytics data.

The data could be purchased for as little as $10 to $50, said Jadali whose report was first described in Ars Technica late on Friday.

"This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.

"Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services" have been exposed, said the report.

The exposed data via eight browser extensions also include vehicle identification, numbers of recently bought automobiles, along with the names and addresses of the buyers.

Patient details, travel itineraries, Facebook Messenger attachments and Facebook photos, even private, are now available in the public domain.

Browser extensions - also known as plug-ins or add-ons - are apps that consumers can install to run alongside their browser for additional functionality.

The affected extensions were apps used by millions of people, including HoverZoom, SpeakIt!, and FairShare Unlock.

"The extensions have been remotely removed or disabled in consumers' browsers and are no longer available for download," said both Google and Firefox.

People who didn't download the extensions may also be affected.

"Nobody is immune to this. Even if you don't have any harmful extensions, the other people you interact with may have an extension on their computers that could be leaking the data you share with them," Jadali was quoted as saying.

Nacho Analytics, for example, promises to let people "see anyone's analytics account" and to provide "real-time web analytics for any website".

The company charges $49 per month, per domain, to monitor any of the top 5,000 most widely-trafficked websites.

The security expert has suggested users to delete all browser extensions they have installed in the past.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 11,2024

hospital.jpg

Mangaluru: In a deeply tragic turn of events, a 28-year-old woman named Ranjitha, who had recently given birth but tragically lost her newborn, ended her life by suicide on Monday. She reportedly leapt from the fourth-floor window of Lady Goschen Hospital’s luggage room.

Ranjitha, whose strength and resilience had carried her through a difficult pregnancy, was scheduled for discharge on Monday. Her journey to Lady Goschen Hospital began on October 24, when she was transferred from Karkala. She was a high-risk patient, battling both hypertension and diabetes. At the time of her admission, she was just 27 weeks pregnant.

Due to the complexities of her health, doctors made the difficult decision to perform an emergency C-section on October 30. She delivered a baby girl, premature and weighing only 960 grams. The newborn was immediately moved to the Neonatal Intensive Care Unit, where doctors did all they could. Despite these efforts, the baby passed away on November 3.

Ranjitha’s sorrow was profound. She stayed under hospital care even after her initial recovery and was preparing to go home on November 9. She had even requested a couple more days at the hospital, seeking time perhaps to cope with her unimaginable grief.

On the day of her discharge, a discharge card ready and her family eagerly waiting to take her home, Ranjitha reportedly made her way to the luggage room in the early hours. There, standing on a cot placed for patients' family members, she climbed to a window and fell from the fourth floor. Despite the attempts of another visitor to intervene, tragedy was inevitable. She was rushed to Government Wenlock Hospital, where doctors confirmed the worst—she was no more.

Dr. Durgaparasad M R, the Medical Superintendent at Lady Goschen Hospital, shared his grief and spoke of the ongoing investigation. A post-mortem is to be conducted, and the local Tahsildar will complete the necessary inquest procedures. Ranjitha’s exact reasons for taking this step are yet to be confirmed, though the weight of her recent losses paints a sorrowful picture.

If you or anyone you know is struggling emotionally, please remember that help is available. Reach out to mental health experts who can provide support and guidance. The toll-free helpline number 9152987821 is available to assist anyone in distress.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 21,2024

adani.jpg

Shares of Adani Group companies lost about $28 billion in market value in morning trade on Thursday after US prosecutors charged the billionaire chairman of the Indian conglomerate in an alleged bribery and fraud scheme.

Gautam Adani's flagship company Adani Enterprises tumbled 23 per cent, while Adani Ports, Adani Total Gas, Adani Green, Adani Power, Adani Wilmar and Adani Energy Solutions, ACC , Ambuja Cements and NDTV fell between 20 per cent and 90 per cent.

Adani group's 10 listed stocks had a total market capitalisation of about $141 billion at 0534 GMT, compared to $169.08 billion on Tuesday.

US authorities said Adani and seven other defendants, including his nephew Sagar Adani, agreed to pay about $265 million in bribes to Indian government officials to obtain contracts expected to yield $2 billion of profit over 20 years, and develop India's largest solar power plant project.

Adani Green in a statement on Thursday said the US Justice Department had issued a criminal indictment against board members Gautam Adani and Sagar Adani and the Securities and Exchange Commission had issued a civil complaint against them.

The US Justice Department also included Adani Green board member Vneet Jaain in the criminal indictment, it said.

Adani Green's units had decided not to proceed with the proposed US dollar denominated bond offerings due to developments, it added.

"Investors will shy away from Adani Group stocks ... and that's what this sharp selling is signifying," said Saurabh Jain, assistant vice president of retail equities research at SMC Global Securities.

"This could hurt the credibility of the group and maybe borrowing costs will rise," he said.

The indictment comes nearly two years after US shortseller Hindenburg Research alleged that Adani had improperly used tax havens and was involved in stock manipulation, allegations the conglomerate denied.

Also in early Asian trading on Thursday, Adani dollar bonds slumped, with prices down 3c-5c on bonds for Adani Ports and Special Economic Zone. The falls were the largest since the Adani Group came under a short-seller attack in February 2023.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 15,2024

iranarmy.jpg

Iran’s Islamic Revolution Guards Corps (IRGC) has killed or captured 69 terrorists linked to the Israeli spy agency Mossad during a major counterterrorism drill in the country's southeast, its spokesman says.  

General Ahmad Shafaei, the spokesman for the “Martyrs of Security” drill, said Friday that a total of 23 terrorists have been killed and another 46 arrested in various clean-up operations ever since the IRGC Ground Force launched it in the Sistan and Baluchestan province on November 1.

Seven terrorists have also turned themselves in during the period.

“The undeniable fact about terrorists is that they rely on arrogant powers, particularly the intelligence service of the wicked and vicious Zionist regime," Shafaei said.

“Unfortunately, weapons and munitions at terrorists’ disposal are among the most sophisticated ones in the world. This accounts for their heavy dependence.” 

The official stated that several members of the disbanded terror teams were non-Iranian nationals, who had been hired by foreign intelligence agencies to carry out acts of sabotage and terror inside Iran.

In a most recent operation, six terrorists were arrested and four others were eliminated, three of whom were non-Iranians, he added. 

On October 26, ten members of Iran's law enforcement forces were killed in a terrorist attack in the Gohar Kuh district of Taftan in the Sistan and Baluchestan province.

The so-called Jaish al-Adl terrorist group claimed responsibility for the assault, which was one of the deadliest in the province in recent months.

The group has carried out numerous terrorist attacks in Iran, primarily in Sistan and Baluchestan.

Its tactics include the abduction of border guards as well as targeting civilians and police stations within the province to incite chaos and disorder.

In January, Iran launched a military operation during which the headquarters of the Pakistan-based terrorist group was targeted in missile strikes, destroying its infrastructure.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.