Normal view
Entra Agent ID from a Security Perspective
-
/r/netsec - Information Security News & Discussion
- X.com silently injects session-bound tracking tokens into your clipboard on every copy โ security tools correctly flag this as malicious injection
X.com silently injects session-bound tracking tokens into your clipboard on every copy โ security tools correctly flag this as malicious injection
Did some digging into why pasting from X.com triggers "malicious injection" warnings in security tools (CrowdStrike, Defender, SentinelOne). Turns out it's not a false positive.
Every time you copy text or a link from X.com, their JavaScript intercepts the `copy` event and rewrites your clipboard before it lands. Three injection vectors:
**URL tracking** โ clean tweet links get `?s=12&t=<base64-token>` appended. The token is session-bound and uniquely identifies you.
**HTML clipboard payload** โ X writes `text/html` alongside `text/plain`. The HTML contains hidden `<span>` elements with base64-encoded tracking data. This is what trips the XSS detection rules.
**Cross-context deanonymization** โ paste a tweet link into email, a forum, or Slack, and X can correlate the copier's identity with the paste destination. Shadow social graph construction without consent.
The `t=` parameter is the smoking gun. It's a base64-encoded binary blob that persists across your session. Security scanners see "base64 blob injected into clipboard" and flag it โ same behavior as information-stealing malware, because technically it's the same mechanism.
No opt-out. No disclosure. The bug bounty program was dissolved.
Full technical writeup with detection regex and DevTools monitoring code:
[link] [comments]
Signal says UK plan to scan devices for nude images 'endangers us all'
-
/r/netsec - Information Security News & Discussion
- WinGet - Code Execution, Persistence and Detection Strategies
WinGet - Code Execution, Persistence and Detection Strategies
-
The Register - Security
- Chrome's zero-day Whac-A-Mole continues with fifth exploited bug of the year
Chrome's zero-day Whac-A-Mole continues with fifth exploited bug of the year
Cisco SASE with Meraki: Get in the Fast Lane to SASE
-
McAfee Blogs
- New Research: Rising Costs Are Driving Consumers to Ignore Scam Instincts for Better Deals
New Research: Rising Costs Are Driving Consumers to Ignore Scam Instincts for Better Deals
Most peopleย donโtย get scammed because they ignore warning signs.ย
They get scammed because they find a reason to explain those warning signs away.ย
The website looks a little off, but the deal is incredible. The text message is unexpected, butย theyโreย already waiting for a package. The seller is unfamiliar, but the discount is too good to pass up.ย
Thatโsย what makes major shopping events such fertile ground for scammers.ย ย
New McAfee research suggests that economic pressure may be making that problem worse,ย asย 40% ofย consumers sayย they would trust a lower priced deal without verifying it.ย That means as costs are climbing, shoppers are less likely to second guess aย too-good-to-be-true dealย that could be aย scam.ย
โAnyoneย who has ever fallen for a scam thought they would recognize one first,โ McAfeeโs Head of Threat Research Abhishek Karnik reminds shoppers.ย
โThat confidence is part of what scammers count on,โ he says. โTools likeย McAfeeย exist precisely for those moments, flagging suspicious links, messages, and offers in real time, before a split-second decision becomes a costly one.โย
New McAfee Research Reveals the Cost of Deal Huntingย
While mostย shoppers believe they can spot aย scam, McAfeeโs new research suggests many are engaging inย behaviorsย that increase their risk.ย
Rising Prices Are Driving Riskier Shopping Decisionsย
Economic pressure is changing how people shop online.ย
McAfee found:ย
- 82% prioritize finding the cheapest deal when shopping onlineย
- 55% spend more time hunting for dealsย
- 40% would trust a lower-priced deal without verifying it firstย
- 29% would skip researching a seller if the deal seemed especially goodย
- 27% are more likely to consider unfamiliar sellers because of lower pricesย
- 23% feel pressure to act quickly before deals disappearย
The sameย behaviorsย that help shoppers find bargains can also make them more vulnerable to fraud.ย
โWhat the data reflects is that economic pressure has effectively done some of the scammerโs work for them,โ says Karnik. โWhen consumers are already primed to move quickly and prioritize price over authenticity, it takes far less effort to push them toward a bad click or a fraudulent purchase.โย
Shopping Scams Are Already Costing Americans Real Moneyย
Theย financial impactย is significant:ย
- 37% say they have lost money due to online shoppingย scamsย or fraudย
- 45% of victims lost more than $100ย
- 25% lost between $100 and $499ย
- 20% lost $500 or moreย
- 36% were unable to recover any of their moneyย
AI Is Making Shopping Scams Harder to Spotย
Consumers are increasingly aware that artificial intelligence is changing theย scamย landscape.ย
According to McAfee research:ย
- 70% agree AI-generated content is making shoppingย scamsย harder toย identifyย
- Nearly three-quartersย haveย encounteredย shopping content they believed was suspicious or AI-generatedย
โTheย signsย people have historically relied on, poor grammar, low-quality images, obviously off branding, are no longer reliable,โย advisesย Karnik. โAI has lowered the production cost of a convincing fake to nearly zero.โย
Itโsย not just a fake landing page fraudsters are creating.ย ย
โAI is being used to make fake review sections, impersonation messages that look exactly like it came from a major retailer,ย realistic logos, believable URLS,โ Karnik says. โWhen youโre shoppingย online, you need to adjust your expectations to match that newย AIย reality.โย
What Are the Most Common Shopping Scams During Major Sales Events?ย
Scammers follow consumer attention.ย
Whenever millions of people are searching for deals at the same time, scammers create fake websites, impersonate retailers and delivery companies, and use urgency to pressure shoppers into acting before they think.ย
Here are some of the most common shoppingย scamsย consumersย encounterย during major sales events,ย as well as the red flags consumers can watch for:ย
| Scam Typeย | How It Worksย | Red Flagsย |
| Fake shopping websitesย | Fraudulent websites mimic real retailers and disappear after collecting paymentsย | Prices far below competitors, little company information, newly created websitesย |
| Fake social media adsย | Ads promote products that never arrive or are counterfeitย | Too-good-to-be-true discounts, limited reviews, unfamiliar brandsย |
| Delivery notificationย scamsย | Fake package alerts claim there is an issue with your shipmentย | Unexpected texts, suspicious links, requests for paymentย |
| Retailer impersonationย scamsย | Messages claim there is a problem with your account or orderย | Urgent language, login requests, unfamiliar sender addressesย |
| QR codeย scamsย | QR codes redirect shoppers to fraudulent websitesย | Codes placed on flyers, posters, packages, or public locationsย |
| Brushingย scamsย | Unsolicited packages arrive at your homeย | Items you never ordered, requests to scan codes or leave reviewsย |
| Fake recallย scamsย | Messages claim a recent purchase has been recalledย | Requests for payment, account credentials, or personal informationย |
ย According to McAfee research, consumers most commonly reportย encounteringย fake shipping notifications, deliveryย scams, retailer impersonationย scams, account alerts, and suspicious discount offers during major shopping periods.ย
How McAfee Can Helpย
Withย McAfee+ Premium, multiple layers work together before any damage is done: ย
- Scam Detectorย flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engageย
- Secure VPNย keeps your data private, especially on public Wi-Fiย ย
- Web Protectionย helps block risky sites, even if you do accidentallyย clickย ย helpsย block risky sites, even if you do accidentally clickย ย ย
- Password Managerย doesnโt just help you make unique, strong passwords, it keeps them stored and organized for you
- Device Securityย helps detect malicious apps or downloadsย ย ย
- Identity Monitoringย alerts you if your personal info shows up where it should not, so you can act fastย ย ย
- Personal Data Cleanupย helps remove your information from sites selling it.ย
- Online Account Cleanupย assistsย in taking down your old, forgotten accounts across the webย
- Social Privacy Managerย helps youย monitorย and changeย privacy settings across your social platforms in just a few clicksย
Together, these protections are designed to address the broader range of online risks people face every day.ย
Plus, click here to get McAfeeโs limited-time deals on real-time protection this Amazon Prime Day, from June 23 to June 26.
About our consumer researchย
McAfee surveyed 1,000 U.S. adults in May 2026 as part of a broader study of 5,000 respondents across the U.S., UK, France, Germany, and Japan, focused on online shopping intentions,ย scamย awareness, and purchaseย behaviors.ย
The post New Research: Rising Costs Are Driving Consumers to Ignore Scam Instincts for Better Deals appeared first on McAfee Blog.
France probes compromise of gov messaging platform after account hijack
-
/r/netsec - Information Security News & Discussion
- I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue
I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue
I scanned Chrome extension manifests for chrome_settings_overrides and found 23 extensions silently routing 758,000 users' searches through hidden monetization networks.
The pattern: install a free extension (satellite imagery, maps, news reader), your default search gets quietly replaced and every query goes through the operator's middleware before reaching a search network, generating affiliate revenue you never consented to.
Key findings:
- 8 distinct brokers behind these extensions. If one extension gets pulled, another goes up under a different name.
- Several extensions have zero functionality beyond the search override
- One extension affirmatively claims "We don't track your searches" while its own privacy policy says otherwise
- One uses runtime declarativeNetRequest injection so the real behavior is invisible to static analysis
The `hspart` parameter in the final search redirect URL is the clustering key. One value maps an entire broker network regardless of extension name, domain, or publisher identity.
Full report: https://malext.io/reports/SearchJack/
[link] [comments]
Qilin NHS breach tally grows as Essex trust confirms stolen records
-
/r/netsec - Information Security News & Discussion
- I just completed Search Skills room on TryHackMe! Learn to efficiently search the Internet and use specialised services and technical docs for information
AI Agents May Always Fall for Prompt Injections
-
The Register - Security
- Norks blast 250+ fake job offers to developers over 6 weeks to try and snarf creds and crypto
Norks blast 250+ fake job offers to developers over 6 weeks to try and snarf creds and crypto
Meta Deletes Face-Recognition System From Its Smart Glasses App After WIRED Report
-
The Register - Security
- Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix
Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix
Ransomware sends Illinois high school on an early summer vacation
-
The Register - Security
- GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections
GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections
NSO Group back in Meta's crosshairs after alleged WhatsApp targeting
All the Ways Europe Is Ditching American Technology