Security
Malicious Chrome Extensions Steal Workday, NetSuite Logins
* Five malicious Chrome extensions on the Chrome Web Store targeted enterprise HR and ERP platforms. * Attack methods included __session cookie exfiltration, blocking security admin pages, and bidirectional cookie injection for session hijack. * The campaign hit Workday, NetSuite and SAP SuccessFactors; the extensions had >2,300 installs and were reported