Annex Security's Avatar

Annex Security

@secureannex.com

Helping protect organizations from malicious browser extensions https://annex.security

22
Followers
1
Following
3
Posts
03.12.2024
Joined
Posts Following

Latest posts by Annex Security @secureannex.com

Preview
Buying browser extensions for fun and profit An investigation into buying access to browsers through extensions

I acquired a Chrome extension for $5 and began redirecting the browsing traffic of existing users to whatever I wanted.

While doing so, I caught an ownership transfer of an extension with 400,000 installs that folks should be aware of.

www.secureannex.com/blog/buying-...

18.03.2025 13:58 ๐Ÿ‘ 23 ๐Ÿ” 11 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 1
Post image

Begin by watching the list of extensions your organization has installed. When a change occurs, a notification will be instantly sent to a webhook. This could be your SIEM, SOAR, or even just a Slack channel. Two extensions can be monitored by all organizations.

19.02.2025 21:39 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

No longer will teams be caught surprised by extensions changing silently, these proactive notifications give the ability to react in real time.

19.02.2025 21:39 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

Just released to all users... Monitoring!

Monitoring was built to notify teams when a browser extension's disposition changes. Aspects like ownership swaps, version updates, analysis verdict, web store visibility, and more to come!

19.02.2025 21:39 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0