• About TC
  • Affiliate Disclaimer
  • Privacy Policy
  • TOS
  • Contact
Wednesday, June 18, 2025
Techcratic
  • TC
  • AI
    Artificial Intelligence

    How Apollo Tyres is unlocking machine insights using agentic AI-powered Manufacturing Reasoner

    Artificial Intelligence

    Automatically Build AI Workflows with Magical AI

    Artificial Intelligence

    Amazon Nova Lite enables Bito to offer a free tier option for its AI-powered code reviews

    Artificial Intelligence

    Bridging the Gap: New Datasets Push Recommender Research Toward Real-World Scale

    Artificial Intelligence

    7 Python Errors That Are Actually Features

    Artificial Intelligence

    10 Awesome OCR Models for 2025

    Artificial Intelligence

    5 Error Handling Patterns in Python (Beyond Try-Except)

    Artificial Intelligence

    Top 5 Alternative Data Career Paths and How to Learn Them for Free

    Artificial Intelligence

    Implementing Machine Learning Pipelines with Apache Spark

  • Crypto
    Bitmex Co-Founder Arthur Hayes Has a Stark Prediction for ‘Circle Copycat’ Stocks

    Bitmex Co-Founder Arthur Hayes Has a Stark Prediction for ‘Circle Copycat’ Stocks

    Bitcoin Bull Cycle is Over: CryptoQuant CEO

    US Senate Passes First Major Stablecoin Regulation Bill

    Ripple and SEC Ask Court to Pause Appeals as They Fight to End XRP Case

    Ripple and SEC Ask Court to Pause Appeals as They Fight to End XRP Case

    Bitcoin Trades Near $102K Support as FOMC Triggers Selling

    Bitcoin Trades Near $102K Support as FOMC Triggers Selling

    Uniswap Surges 24% on $88B Volume, Targeting $12

    Pump.fun Accused of Stealing $741 M in Fees, Critics Warn

    Canada Approves First XRP Spot ETF on Toronto Stock Exchange

    Canada Approves First XRP Spot ETF on Toronto Stock Exchange

    Fold Announces $250M Equity Deal to Bolster Bitcoin Treasury

    Fold Announces $250M Equity Deal to Bolster Bitcoin Treasury

    Key BTC price levels to watch as fed rate cut hopes fade

    Key BTC price levels to watch as fed rate cut hopes fade

    Theminermag Bitcoin Mining Update: May/June 2025

    Theminermag Bitcoin Mining Update: May/June 2025

  • Cybersecurity
    Cybersecurity

    Critical RCE Bug Rated 9.9 CVSS in Backup & Replication

    Cybersecurity

    Hard-Coded ‘b’ Password in Sitecore XP Sparks Major RCE Risk in Enterprise Deployments

    Cybersecurity

    AI Agents Run on Secret Accounts — Learn How to Secure Them in This Webinar

    Cybersecurity

    How to Address the Expanding Security Risk

    Cybersecurity

    ConnectWise to Rotate ScreenConnect Code Signing Certificates Due to Security Risks

    Cybersecurity

    5 Lessons from River Island

    Cybersecurity

    INTERPOL Dismantles 20,000+ Malicious IPs Linked to 69 Malware Variants in Operation Secure

    Cybersecurity

    SinoTrack GPS Devices Vulnerable to Remote Vehicle Control via Default Passwords

    Cybersecurity

    Researchers Uncover 20+ Configuration Risks, Including Five CVEs, in Salesforce Industry Cloud

  • Deals
    2018 Apple iPad Pro (12.9-inch, Wi-Fi, 256GB) – Silver (Renewed)

    2018 Apple iPad Pro (12.9-inch, Wi-Fi, 256GB) – Silver (Renewed)

    MageGee SKY98 Mechanical Gaming Keyboard, 96% Gasket Hot Swappable Wired Custom Creamy…

    MageGee SKY98 Mechanical Gaming Keyboard, 96% Gasket Hot Swappable Wired Custom Creamy…

    Sceptre 27-inch FHD 1080p IPS Gaming LED Monitor up to 165Hz 144Hz 1ms DisplayPort HDMI,…

    Sceptre 27-inch FHD 1080p IPS Gaming LED Monitor up to 165Hz 144Hz 1ms DisplayPort HDMI,…

    Razer Enki X Essential Gaming Chair: All-Day Comfort – Built-in Lumbar Arch – Optimized…

    Razer Enki X Essential Gaming Chair: All-Day Comfort – Built-in Lumbar Arch – Optimized…

    MSI Thin 15.6 inch FHD 144Hz Gaming Laptop Intel Core i5-13420H NVIDIA GeForce RTX…

    MSI Thin 15.6 inch FHD 144Hz Gaming Laptop Intel Core i5-13420H NVIDIA GeForce RTX…

    Sonic’s Ultimate Genesis Collection (Platinum Hits) – Xbox 360 (Renewed)

    Sonic’s Ultimate Genesis Collection (Platinum Hits) – Xbox 360 (Renewed)

    Donkey Kong Country Returns (Renewed)

    Donkey Kong Country Returns (Renewed)

    Buffalo Games CHRONOLOGY – The Game Where You Make History – 20th Anniversary Edition

    Buffalo Games CHRONOLOGY – The Game Where You Make History – 20th Anniversary Edition

    Sprunki Plush Toys, Horror Games Plushies Toy for Fans, Soft Stuffed Animal Pillow…

    Sprunki Plush Toys, Horror Games Plushies Toy for Fans, Soft Stuffed Animal Pillow…

  • Gaming
    Maliketh Black Blade Build 2025 VS Main Bosses + DLC – Elden Ring Colossal Sword Build Patch 1.16

    Maliketh Black Blade Build 2025 VS Main Bosses + DLC – Elden Ring Colossal Sword Build Patch 1.16

    OGL BACKLASH As Dungeon And Dragons Movie Faces Boycott

    OGL BACKLASH As Dungeon And Dragons Movie Faces Boycott

    Overwatch 2 Season 17 is finally giving power back to the people by introducing map voting for quick play and competitive

    Overwatch 2 Season 17 is finally giving power back to the people by introducing map voting for quick play and competitive

    The Legend of Zelda: Breath of the Wild – Monya Toma Shrine Walkthrough [HD 1080P]

    The Legend of Zelda: Breath of the Wild – Monya Toma Shrine Walkthrough [HD 1080P]

    BOTW – Lynel Hunting II – Walkthrough 27, pt. 5

    BOTW – Lynel Hunting II – Walkthrough 27, pt. 5

    Top 4 SECRET Broken Black Myth: Wukong Builds (Most OP Builds That You Missed Out On)

    Top 4 SECRET Broken Black Myth: Wukong Builds (Most OP Builds That You Missed Out On)

    Is Baldur’s Gate 3 Worth the Hype?

    Is Baldur’s Gate 3 Worth the Hype?

    Could The Mario Movie Be What The Next Mario Game Is Like?! Open World Mario!?

    Could The Mario Movie Be What The Next Mario Game Is Like?! Open World Mario!?

    The Calisto Protocol -Non-Spoiler Review- (PS5)

    The Calisto Protocol -Non-Spoiler Review- (PS5)

  • Tesla
    Custom Fit Tesla Cybertruck 2024 2025 Sunshade Umbrella -100% Blackout Ratio Thickened…

    Custom Fit Tesla Cybertruck 2024 2025 Sunshade Umbrella -100% Blackout Ratio Thickened…

    KEEPER Portable Trunk Organizer, 19L, Car Organizers and Storage, Non-Slip Bottom,…

    KEEPER Portable Trunk Organizer, 19L, Car Organizers and Storage, Non-Slip Bottom,…

    ARKSEN 64 x 39 x 4 Inch Upgrade Universal Roof Rack – 250Lbs Capacity Heavy Duty Rooftop…

    ARKSEN 64 x 39 x 4 Inch Upgrade Universal Roof Rack – 250Lbs Capacity Heavy Duty Rooftop…

    2025 Upgrade Sunshade Roof for Tesla Model Y Accessories, [Graphene Cooling Tech & High…

    2025 Upgrade Sunshade Roof for Tesla Model Y Accessories, [Graphene Cooling Tech & High…

    Tesla (TSLA) is sitting on so much inventory it has to take over parking lots all over the US

    Tesla (TSLA) is sitting on so much inventory it has to take over parking lots all over the US

    Tesla (TSLA) plans to pause production at Gigafactory Texas for second time in 2 months

    DEWALT CCS1 to NACS Fast Charging Adapter for All 2021 and Newer Tesla Models Excluding…

    DEWALT CCS1 to NACS Fast Charging Adapter for All 2021 and Newer Tesla Models Excluding…

    6PCS Trunk Mats & Frunk Mat & Backrest Mats for New 2025 2026 Tesla Model Y Juniper…

    6PCS Trunk Mats & Frunk Mat & Backrest Mats for New 2025 2026 Tesla Model Y Juniper…

    Tesla gives update on Tesla Semi factory, says on track for volume production in 2026

    Tesla gears up to start selling Tesla Semi electric truck in Europe

  • UFO
    Mind-Blowing Celebrity Encounters: Uncovering Unknown Stories and Unexpected Reactions

    Mind-Blowing Celebrity Encounters: Uncovering Unknown Stories and Unexpected Reactions

    Alien Abductions: Real Accounts and Theories #AlienAbductions #Extraterrestrial #Mystery #short

    Alien Abductions: Real Accounts and Theories #AlienAbductions #Extraterrestrial #Mystery #short

    ’UFO’ spotted by Beijing residents #shorts

    ’UFO’ spotted by Beijing residents #shorts

    Roswell Revisited

    Roswell Revisited

    The Bizarre Colares UFO Attack | Shocking Truth Behind Brazil's Biggest UFO Encounter

    The Bizarre Colares UFO Attack | Shocking Truth Behind Brazil's Biggest UFO Encounter

    The Alien Experiment | He saw Aliens #vigyanrecharge

    The Alien Experiment | He saw Aliens #vigyanrecharge

    UFO Completes 5 Orbits Around the Moon?! | Ancient Aliens | #Shorts

    UFO Completes 5 Orbits Around the Moon?! | Ancient Aliens | #Shorts

    A Pleiadian Contactee Describes His Experience

    A Pleiadian Contactee Describes His Experience

    Aidatain Outer Space Spaceship Tapestry Interior International Space Station Wall Hanging, Art Large Tapestry Spacecraft Backdrop 80″X 60″ Flannel for Bedroom Home Decor TFNAT0123

    Aidatain Outer Space Spaceship Tapestry Interior International Space Station Wall Hanging, Art Large Tapestry Spacecraft Backdrop 80″X 60″ Flannel for Bedroom Home Decor TFNAT0123

No Result
View All Result
  • TC
  • AI
    Artificial Intelligence

    How Apollo Tyres is unlocking machine insights using agentic AI-powered Manufacturing Reasoner

    Artificial Intelligence

    Automatically Build AI Workflows with Magical AI

    Artificial Intelligence

    Amazon Nova Lite enables Bito to offer a free tier option for its AI-powered code reviews

    Artificial Intelligence

    Bridging the Gap: New Datasets Push Recommender Research Toward Real-World Scale

    Artificial Intelligence

    7 Python Errors That Are Actually Features

    Artificial Intelligence

    10 Awesome OCR Models for 2025

    Artificial Intelligence

    5 Error Handling Patterns in Python (Beyond Try-Except)

    Artificial Intelligence

    Top 5 Alternative Data Career Paths and How to Learn Them for Free

    Artificial Intelligence

    Implementing Machine Learning Pipelines with Apache Spark

  • Crypto
    Bitmex Co-Founder Arthur Hayes Has a Stark Prediction for ‘Circle Copycat’ Stocks

    Bitmex Co-Founder Arthur Hayes Has a Stark Prediction for ‘Circle Copycat’ Stocks

    Bitcoin Bull Cycle is Over: CryptoQuant CEO

    US Senate Passes First Major Stablecoin Regulation Bill

    Ripple and SEC Ask Court to Pause Appeals as They Fight to End XRP Case

    Ripple and SEC Ask Court to Pause Appeals as They Fight to End XRP Case

    Bitcoin Trades Near $102K Support as FOMC Triggers Selling

    Bitcoin Trades Near $102K Support as FOMC Triggers Selling

    Uniswap Surges 24% on $88B Volume, Targeting $12

    Pump.fun Accused of Stealing $741 M in Fees, Critics Warn

    Canada Approves First XRP Spot ETF on Toronto Stock Exchange

    Canada Approves First XRP Spot ETF on Toronto Stock Exchange

    Fold Announces $250M Equity Deal to Bolster Bitcoin Treasury

    Fold Announces $250M Equity Deal to Bolster Bitcoin Treasury

    Key BTC price levels to watch as fed rate cut hopes fade

    Key BTC price levels to watch as fed rate cut hopes fade

    Theminermag Bitcoin Mining Update: May/June 2025

    Theminermag Bitcoin Mining Update: May/June 2025

  • Cybersecurity
    Cybersecurity

    Critical RCE Bug Rated 9.9 CVSS in Backup & Replication

    Cybersecurity

    Hard-Coded ‘b’ Password in Sitecore XP Sparks Major RCE Risk in Enterprise Deployments

    Cybersecurity

    AI Agents Run on Secret Accounts — Learn How to Secure Them in This Webinar

    Cybersecurity

    How to Address the Expanding Security Risk

    Cybersecurity

    ConnectWise to Rotate ScreenConnect Code Signing Certificates Due to Security Risks

    Cybersecurity

    5 Lessons from River Island

    Cybersecurity

    INTERPOL Dismantles 20,000+ Malicious IPs Linked to 69 Malware Variants in Operation Secure

    Cybersecurity

    SinoTrack GPS Devices Vulnerable to Remote Vehicle Control via Default Passwords

    Cybersecurity

    Researchers Uncover 20+ Configuration Risks, Including Five CVEs, in Salesforce Industry Cloud

  • Deals
    2018 Apple iPad Pro (12.9-inch, Wi-Fi, 256GB) – Silver (Renewed)

    2018 Apple iPad Pro (12.9-inch, Wi-Fi, 256GB) – Silver (Renewed)

    MageGee SKY98 Mechanical Gaming Keyboard, 96% Gasket Hot Swappable Wired Custom Creamy…

    MageGee SKY98 Mechanical Gaming Keyboard, 96% Gasket Hot Swappable Wired Custom Creamy…

    Sceptre 27-inch FHD 1080p IPS Gaming LED Monitor up to 165Hz 144Hz 1ms DisplayPort HDMI,…

    Sceptre 27-inch FHD 1080p IPS Gaming LED Monitor up to 165Hz 144Hz 1ms DisplayPort HDMI,…

    Razer Enki X Essential Gaming Chair: All-Day Comfort – Built-in Lumbar Arch – Optimized…

    Razer Enki X Essential Gaming Chair: All-Day Comfort – Built-in Lumbar Arch – Optimized…

    MSI Thin 15.6 inch FHD 144Hz Gaming Laptop Intel Core i5-13420H NVIDIA GeForce RTX…

    MSI Thin 15.6 inch FHD 144Hz Gaming Laptop Intel Core i5-13420H NVIDIA GeForce RTX…

    Sonic’s Ultimate Genesis Collection (Platinum Hits) – Xbox 360 (Renewed)

    Sonic’s Ultimate Genesis Collection (Platinum Hits) – Xbox 360 (Renewed)

    Donkey Kong Country Returns (Renewed)

    Donkey Kong Country Returns (Renewed)

    Buffalo Games CHRONOLOGY – The Game Where You Make History – 20th Anniversary Edition

    Buffalo Games CHRONOLOGY – The Game Where You Make History – 20th Anniversary Edition

    Sprunki Plush Toys, Horror Games Plushies Toy for Fans, Soft Stuffed Animal Pillow…

    Sprunki Plush Toys, Horror Games Plushies Toy for Fans, Soft Stuffed Animal Pillow…

  • Gaming
    Maliketh Black Blade Build 2025 VS Main Bosses + DLC – Elden Ring Colossal Sword Build Patch 1.16

    Maliketh Black Blade Build 2025 VS Main Bosses + DLC – Elden Ring Colossal Sword Build Patch 1.16

    OGL BACKLASH As Dungeon And Dragons Movie Faces Boycott

    OGL BACKLASH As Dungeon And Dragons Movie Faces Boycott

    Overwatch 2 Season 17 is finally giving power back to the people by introducing map voting for quick play and competitive

    Overwatch 2 Season 17 is finally giving power back to the people by introducing map voting for quick play and competitive

    The Legend of Zelda: Breath of the Wild – Monya Toma Shrine Walkthrough [HD 1080P]

    The Legend of Zelda: Breath of the Wild – Monya Toma Shrine Walkthrough [HD 1080P]

    BOTW – Lynel Hunting II – Walkthrough 27, pt. 5

    BOTW – Lynel Hunting II – Walkthrough 27, pt. 5

    Top 4 SECRET Broken Black Myth: Wukong Builds (Most OP Builds That You Missed Out On)

    Top 4 SECRET Broken Black Myth: Wukong Builds (Most OP Builds That You Missed Out On)

    Is Baldur’s Gate 3 Worth the Hype?

    Is Baldur’s Gate 3 Worth the Hype?

    Could The Mario Movie Be What The Next Mario Game Is Like?! Open World Mario!?

    Could The Mario Movie Be What The Next Mario Game Is Like?! Open World Mario!?

    The Calisto Protocol -Non-Spoiler Review- (PS5)

    The Calisto Protocol -Non-Spoiler Review- (PS5)

  • Tesla
    Custom Fit Tesla Cybertruck 2024 2025 Sunshade Umbrella -100% Blackout Ratio Thickened…

    Custom Fit Tesla Cybertruck 2024 2025 Sunshade Umbrella -100% Blackout Ratio Thickened…

    KEEPER Portable Trunk Organizer, 19L, Car Organizers and Storage, Non-Slip Bottom,…

    KEEPER Portable Trunk Organizer, 19L, Car Organizers and Storage, Non-Slip Bottom,…

    ARKSEN 64 x 39 x 4 Inch Upgrade Universal Roof Rack – 250Lbs Capacity Heavy Duty Rooftop…

    ARKSEN 64 x 39 x 4 Inch Upgrade Universal Roof Rack – 250Lbs Capacity Heavy Duty Rooftop…

    2025 Upgrade Sunshade Roof for Tesla Model Y Accessories, [Graphene Cooling Tech & High…

    2025 Upgrade Sunshade Roof for Tesla Model Y Accessories, [Graphene Cooling Tech & High…

    Tesla (TSLA) is sitting on so much inventory it has to take over parking lots all over the US

    Tesla (TSLA) is sitting on so much inventory it has to take over parking lots all over the US

    Tesla (TSLA) plans to pause production at Gigafactory Texas for second time in 2 months

    DEWALT CCS1 to NACS Fast Charging Adapter for All 2021 and Newer Tesla Models Excluding…

    DEWALT CCS1 to NACS Fast Charging Adapter for All 2021 and Newer Tesla Models Excluding…

    6PCS Trunk Mats & Frunk Mat & Backrest Mats for New 2025 2026 Tesla Model Y Juniper…

    6PCS Trunk Mats & Frunk Mat & Backrest Mats for New 2025 2026 Tesla Model Y Juniper…

    Tesla gives update on Tesla Semi factory, says on track for volume production in 2026

    Tesla gears up to start selling Tesla Semi electric truck in Europe

  • UFO
    Mind-Blowing Celebrity Encounters: Uncovering Unknown Stories and Unexpected Reactions

    Mind-Blowing Celebrity Encounters: Uncovering Unknown Stories and Unexpected Reactions

    Alien Abductions: Real Accounts and Theories #AlienAbductions #Extraterrestrial #Mystery #short

    Alien Abductions: Real Accounts and Theories #AlienAbductions #Extraterrestrial #Mystery #short

    ’UFO’ spotted by Beijing residents #shorts

    ’UFO’ spotted by Beijing residents #shorts

    Roswell Revisited

    Roswell Revisited

    The Bizarre Colares UFO Attack | Shocking Truth Behind Brazil's Biggest UFO Encounter

    The Bizarre Colares UFO Attack | Shocking Truth Behind Brazil's Biggest UFO Encounter

    The Alien Experiment | He saw Aliens #vigyanrecharge

    The Alien Experiment | He saw Aliens #vigyanrecharge

    UFO Completes 5 Orbits Around the Moon?! | Ancient Aliens | #Shorts

    UFO Completes 5 Orbits Around the Moon?! | Ancient Aliens | #Shorts

    A Pleiadian Contactee Describes His Experience

    A Pleiadian Contactee Describes His Experience

    Aidatain Outer Space Spaceship Tapestry Interior International Space Station Wall Hanging, Art Large Tapestry Spacecraft Backdrop 80″X 60″ Flannel for Bedroom Home Decor TFNAT0123

    Aidatain Outer Space Spaceship Tapestry Interior International Space Station Wall Hanging, Art Large Tapestry Spacecraft Backdrop 80″X 60″ Flannel for Bedroom Home Decor TFNAT0123

No Result
View All Result
Techcratic
No Result
View All Result
Home Cybersecurity

Popular Chrome Extensions Leak API Keys, User Data via HTTP and Hardcoded Credentials

Cyber Security by Cyber Security
June 5, 2025
in Cybersecurity
Reading Time: 7 mins read
124 6
A A
0

info@thehackernews.com (The Hacker News)
2025-06-05 11:53:00
thehackernews.com

Jun 05, 2025Ravie LakshmananBrowser Security / Online Safety

Cybersecurity researchers have flagged several popular Google Chrome extensions that have been found to transmit data in HTTP and hard-code secrets in their code, exposing users to privacy and security risks.

“Several widely used extensions […] unintentionally transmit sensitive data over simple HTTP,” Yuanjing Guo, a security researcher in the Symantec’s Security Technology and Response team, said. “By doing so, they expose browsing domains, machine IDs, operating system details, usage analytics, and even uninstall information, in plaintext.”

The fact that the network traffic is unencrypted also means that they are susceptible to adversary-in-the-middle (AitM) attacks, allowing malicious actors on the same network such as a public Wi-Fi to intercept and, even worse, modify this data, which could lead to far more serious consequences.

Cybersecurity

The list of identified extensions are below –

  • SEMRush Rank (extension ID: idbhoeaiokcojcgappfigpifhpkjgmab) and PI Rank (ID: ccgdboldgdlngcgfdolahmiilojmfndl), which call the URL “rank.trellian[.]com” over plain HTTP
  • Browsec VPN (ID: omghfjlpggmjjaagoclmmobgdodcjboh), which uses HTTP to call an uninstall URL at “browsec-uninstall.s3-website.eu-central-1.amazonaws[.]com” when a user attempts to uninstall the extension
  • MSN New Tab (ID: lklfbkdigihjaaeamncibechhgalldgl) and MSN Homepage, Bing Search & News (ID: midiombanaceofjhodpdibeppmnamfcj), which transmit a unique machine identifier and other details over HTTP to “g.ceipmsn[.]com”
  • DualSafe Password Manager & Digital Vault (ID: lgbjhdkjmpgjgcbcdlhkokkckpjmedgc), which constructs an HTTP-based URL request to “stats.itopupdate[.]com” along with information about the extension version, user’s browser language, and usage “type”

“Although credentials or passwords do not appear to be leaked, the fact that a password manager uses unencrypted requests for telemetry erodes trust in its overall security posture,” Guo said.

Symantec said it also identified another set of extensions with API keys, secrets, and tokens directly embedded in the JavaScript code, which an attacker could weaponize to craft malicious requests and carry out various malicious actions –

  • Online Security & Privacy extension (ID: gomekmidlodglbbmalcneegieacbdmki), AVG Online Security (ID: nbmoafcmbajniiapeidgficgifbfmjfo), Speed Dial [FVD] – New Tab Page, 3D, Sync (ID: llaficoajjainaijghjlofdfmbjpebpa), and SellerSprite – Amazon Research Tool (ID: lnbmbgocenenhhhdojdielgnmeflbnfb), which expose a hard-coded Google Analytics 4 (GA4) API secret that an attacker could use to bombard the GA4 endpoint and corrupt metrics

  • Equatio – Math Made Digital (ID: hjngolefdpdnooamgdldlkjgmdcmcjnc), which embeds a Microsoft Azure API key used for speech recognition that an attacker could use to inflate the developer’s costs or exhaust their usage limits

  • Awesome Screen Recorder & Screenshot (ID: nlipoenfbbikpbjkfpfillcgkoblgpmj) and Scrolling Screenshot Tool & Screen Capture (ID: mfpiaehgjbbfednooihadalhehabhcjo), which expose the developer’s Amazon Web Services (AWS) access key used to upload screenshots to the developer’s S3 bucket

  • Microsoft Editor – Spelling & Grammar Checker (ID: gpaiobkfhnonedkhhfjpmhdalgeoebfa), which exposes a telemetry key named “StatsApiKey” to log user data for analytics

  • Antidote Connector (ID: lmbopdiikkamfphhgcckcjhojnokgfeo), which incorporates a third-party library called InboxSDK that contains hard-coded credentials, including API keys.

  • Watch2Gether (ID: cimpffimgeipdhnhjohpbehjkcdpjolg), which exposes a Tenor GIF search API key

  • Trust Wallet (ID: egjidjbpglichdcondbcbdnbeeppgdph), which exposes an API key associated with the Ramp Network, a Web3 platform that offers wallet developers a way to let users buy or sell crypto directly from the app

  • TravelArrow – Your Virtual Travel Agent (ID: coplmfnphahpcknbchcehdikbdieognn), which exposes a geolocation API key when making queries to “ip-api[.]com”

Attackers who end up finding these keys could weaponize them to drive up API costs, host illegal content, send spoofed telemetry data, and mimic cryptocurrency transaction orders, some of which could see the developer’s ban getting banned.

Adding to the concern, Antidote Connector is just one of over 90 extensions that use InboxSDK, meaning the other extensions are susceptible to the same problem. The names of the other extensions were not disclosed by Symantec.

Cybersecurity

“From GA4 analytics secrets to Azure speech keys, and from AWS S3 credentials to Google-specific tokens, each of these snippets demonstrates how a few lines of code can jeopardize an entire service,” Guo said. “The solution: never store sensitive credentials on the client side.”

Developers are recommended to switch to HTTPS whenever they send or receive data, store credentials securely in a backend server using a credentials management service, and regularly rotate secrets to further minimize risk.

The findings show how even popular extensions with hundreds of thousands of installations can suffer from trivial misconfigurations and security blunders like hard-coded credentials, leaving users’ data at risk.

“Users of these extensions should consider removing them until the developers address the insecure [HTTP] calls,” the company said. “The risk is not just theoretical; unencrypted traffic is simple to capture, and the data can be used for profiling, phishing, or other targeted attacks.”

“The overarching lesson is that a large install base or a well-known brand does not necessarily ensure best practices around encryption. Extensions should be scrutinized for the protocols they use and the data they share, to ensure users’ information remains truly safe.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



Source Link


Upgrade your audio game with the Logitech for Creators Blue Yeti USB Microphone. With over 33,730 ratings and an impressive 4.6 out of 5 stars, it’s no wonder this is an Amazon’s Choice product. Recently, 5K+ units were purchased in the past month.

Available in five stunning colors: Teal, Silver, Pink Dawn, Midnight Blue, and Blackout, this microphone is perfect for creators looking to produce exceptional audio. Priced at only $84.99, it’s a deal you can’t afford to miss.

Elevate your recordings with clear broadcast-quality sound and explore your creativity with enhanced effects, advanced modulation, and HD audio samples. Order now for just $84.99 on Amazon!


Start your free Amazon Prime trial
today and unlock unlimited streaming and more!

Help Power Techcratic’s Future – Scan To Support

If Techcratic’s content and insights have helped you, consider giving back by supporting the platform with crypto. Every contribution makes a difference, whether it’s for high-quality content, server maintenance, or future updates. Techcratic is constantly evolving, and your support helps drive that progress.

As a solo operator who wears all the hats, creating content, managing the tech, and running the site, your support allows me to stay focused on delivering valuable resources. Your support keeps everything running smoothly and enables me to continue creating the content you love. I’m deeply grateful for your support, it truly means the world to me! Thank you!

BITCOIN

Bitcoin Logo

Bitcoin QR Code

bc1qlszw7elx2qahjwvaryh0tkgg8y68enw30gpvge

Scan the QR code with your crypto wallet app

DOGECOIN

Dogecoin Logo

Dogecoin QR Code

D64GwvvYQxFXYyan3oQCrmWfidf6T3JpBA

Scan the QR code with your crypto wallet app

ETHEREUM

Ethereum Logo

Ethereum QR Code

0xe9BC980DF3d985730dA827996B43E4A62CCBAA7a

Scan the QR code with your crypto wallet app

Please read the Privacy and Security Disclaimer on how Techcratic handles your support.

Disclaimer: As an Amazon Associate, Techcratic may earn from qualifying purchases.

Tags: Cybersecurity
Share161ShareTweet101
Previous Post

Advertising strategies are changing with AI and data analysis tools

Next Post

3PCS Car Micro Squeegee Curves Slot Tint Tool Set, Auto Vinyl Wrap Tool Kit, 3 in 1…

Cyber Security

Cyber Security

Explore the critical updates and expert insights in cybersecurity. Stay protected and informed with the latest trends, threats, and solutions in the world of digital security. Find the latest articles here at Techcratic.

Related Posts

Cybersecurity
Cybersecurity

Critical RCE Bug Rated 9.9 CVSS in Backup & Replication

June 18, 2025
1.3k
Cybersecurity
Cybersecurity

Hard-Coded ‘b’ Password in Sitecore XP Sparks Major RCE Risk in Enterprise Deployments

June 17, 2025
1.3k
Cybersecurity
Cybersecurity

AI Agents Run on Secret Accounts — Learn How to Secure Them in This Webinar

June 12, 2025
1.3k
Cybersecurity
Cybersecurity

How to Address the Expanding Security Risk

June 12, 2025
1.3k
Cybersecurity
Cybersecurity

ConnectWise to Rotate ScreenConnect Code Signing Certificates Due to Security Risks

June 12, 2025
1.3k
Cybersecurity
Cybersecurity

5 Lessons from River Island

June 11, 2025
1.3k
Cybersecurity
Cybersecurity

INTERPOL Dismantles 20,000+ Malicious IPs Linked to 69 Malware Variants in Operation Secure

June 11, 2025
1.3k
Cybersecurity
Cybersecurity

SinoTrack GPS Devices Vulnerable to Remote Vehicle Control via Default Passwords

June 11, 2025
1.3k
Load More
Next Post
3PCS Car Micro Squeegee Curves Slot Tint Tool Set, Auto Vinyl Wrap Tool Kit, 3 in 1…

3PCS Car Micro Squeegee Curves Slot Tint Tool Set, Auto Vinyl Wrap Tool Kit, 3 in 1...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Tech Resources

  • 30 Second Tech ™
  • AI
  • App Zone ™
  • Apple
  • Ars Technica
  • CNET
  • ComputerWorld
  • Crypto News
  • Cybersecurity
  • Endgadget
  • Forbes
  • Fossbytes
  • Gaming
  • GeekWire
  • Gizmodo
  • Google News
  • Hacker News
  • Harvard Tech
  • I Like Cats ™
  • I Like Dogs ™
  • LifeHacker
  • MacRumors
  • Macworld
  • Mashable
  • Microsoft
  • MIT Tech
  • PC World
  • Photofocus
  • Physics
  • Random Tech
  • Retro Rewind ™
  • Robot Report
  • SiliconANGLE
  • SlashGear
  • Smartphone
  • StackSocial
  • Tech Art
  • Tech Careers
  • Tech Deals
  • Techcratic ™
  • TechCrunch
  • Techdirt
  • TechRepublic
  • Techs Got To Eat ™
  • TechSpot
  • Tesla
  • The Verge
  • TNW
  • Trusted Reviews
  • UFO
  • VentureBeat
  • Visual Capitalist
  • Wired
  • ZDNet

Tech News

  • 30 Second Tech ™
  • AI
  • Apple Insider
  • Ars Technica
  • CNET
  • ComputerWorld
  • Crypto News
  • Cybersecurity
  • Endgadget
  • ExtremeTech
  • Fossbytes
  • Gaming
  • GeekWire
  • Gizmodo

Tech News

  • Harvard Tech
  • MacRumors
  • Macworld
  • Mashable
  • Microsoft
  • MIT Tech
  • Physics
  • PC World
  • Random Tech
  • Retro Rewind ™
  • SiliconANGLE
  • SlashGear
  • Smartphone
  • StackSocial
  • Tech Careers

Tech News​

  • Tech Art
  • TechCrunch
  • Techdirt
  • TechRepublic
  • Techs Got To Eat ™
  • TechSpot
  • Tesla
  • The Verge
  • TNW
  • Trusted Reviews
  • UFO
  • VentureBeat
  • Visual Capitalist
  • Wired
  • ZDNet

Site Links

  • About Techcratic
  • Affiliate Disclaimer
  • Affiliate Link Policy
  • Contact Techcratic
  • Dealors Discount Store
  • Privacy and Security Disclaimer
  • Privacy Policy
  • RSS Feed
  • Site Map
  • Support Techcratic
  • Techcratic
  • Tech Deals
  • TOS
  • 𝕏
Click For A Secret Deal

Techcratic – Your All In One Tech Hub © 2020 – 2025
All Rights Reserved
∞

No Result
View All Result
  • 30 Second Tech ™
  • AI
  • App Zone ™
  • Apple
  • Ars Technica
  • CNET
  • Crypto News
  • Cybersecurity
  • Endgadget
  • Gaming
  • I Like Cats ™
  • I Like Dogs ™
  • MacRumors
  • Macworld
  • Tech Deals
  • Techcratic ™
  • Techs Got To Eat ™
  • Tesla
  • UFO
  • Wired