ioc.exchange is one of the many independent Mastodon servers you can use to participate in the fediverse.
INDICATORS OF COMPROMISE (IOC) InfoSec Community within the Fediverse. Newbies, experts, gurus - Everyone is Welcome! Instance is supposed to be fast and secure.

Administered by:

Server stats:

1.6K
active users

#chrome

59 posts52 participants9 posts today

Using #Linux on my desktop for 21 years, I can't figure out why #Google #Chrome doesn't see my external camera (anymore), only the internal one.

Both are USB devices and all other applications I've tried see both.

Error messages? Traces? Helpful documentation that describes what Chrome actually tries, rather than bland superficial crap for folks who'd be confused by details?

No no no, the UI must be clean. Can't have too much detail.

Such as the details that might actually help.

Argh.

#browser market share 2024/25:

This is serious! #chrome is taking over the internet like #microsoft did the same about 30 years ago with the Internet Explorer.

Thanks to the world wide success of the #apple #iphone and #ipad the #safari browser comes second. The rest is dust. Including #mozilla #firefox.

With #google Chrome winning the browser race they can dictate web techlologies. Keep in mind, that Google is an advertising company in the first place ...

gs.statcounter.com/browser-mar

StatCounter Global StatsBrowser Market Share Worldwide | Statcounter Global StatsThis graph shows the market share of browsers worldwide based on over 5 billion monthly page views.

Jacob Voytko's "War Story" is a fantastic tale on debugging. It's interesting how chrome-only bugs are the toll for browser monoculture. The dream of “it just works” ends the moment it doesn’t, and then it’s your problem. This is what happens when the rendering engine is the platform, one day Math.abs() just... isn’t.

Debugging like this is inherently social. Lone wolfing it won’t cut it. A coworker goes from “I’m busy” to “I’ll clear my schedule” in one breakpoint. Classic.

And man, layered optimization is a trap. V8’s dual-tier pipeline let a broken opcode ship silently. Math.abs() turned into identity in the hot path. Nobody noticed because it mostly worked. Just not always. You gotta love a bug that’s already fixed and still eats two days of your life.

Final fix? One-line Chrome version check and a war-crime-length comment. Sometimes engineering is just knowing where to duct tape.

clientserver.dev/p/war-story-t

Client/Server · War story: the hardest bug I ever debuggedBy Jacob Voytko

New Evasive Campaign Delivers LegionLoader via Fake CAPTCHA & CloudFlare Turnstile

A new malicious campaign has been discovered targeting users searching for PDF documents online. The attack uses fake CAPTCHAs and CloudFlare Turnstile to deliver LegionLoader malware, which then installs a malicious browser extension. The infection chain involves a drive-by download, execution of a VMware-signed application that sideloads a malicious DLL, and use of process hollowing to inject the LegionLoader payload. The browser extension, disguised as 'Save to Google Drive', is installed on Chrome, Edge, Brave and Opera browsers to steal sensitive user data and monitor Bitcoin activities. The campaign has affected over 140 customers, primarily in North America, Asia and Southern Europe, with technology and financial services sectors being the most targeted.

Pulse ID: 67f0e1fafb3df4665f729a46
Pulse Link: otx.alienvault.com/pulse/67f0e
Pulse Author: AlienVault
Created: 2025-04-05 07:55:38

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.
#Asia#BitCoin#Brave

#Firefox has always been behind #Chrome in terms of extension security. And this is probably the first time I'm seeing it leaping ahead.

Scenario: I want the LanguageTool extension to be only activated when I need it, since it's sending my writing to another server & could be spyware.

In Firefox, it now works “only when clicked”, and compared with Chrome, you don't need a page reload. So I could be writing this text here, remember that I need to spellcheck, and just activate it via click.

Silent Credit Card Thief Uncovered

A sophisticated credit card skimming campaign dubbed 'RolandSkimmer' has been discovered, targeting users in Bulgaria. The attack utilizes malicious browser extensions across Chrome, Edge, and Firefox, initiated through a deceptive LNK file. The malware employs obfuscated scripts to establish persistent access, harvesting and exfiltrating sensitive financial data. The attack workflow involves system reconnaissance, downloading additional malicious files, and injecting scripts into web pages. The threat actor uses unique identifiers to track victims and employs sophisticated techniques to evade detection. The campaign demonstrates the evolving nature of web-based credit card skimming threats, highlighting the need for enhanced security measures against LNK-based attacks and unverified browser extensions.

Pulse ID: 67efc6e92fbd533808f09435
Pulse Link: otx.alienvault.com/pulse/67efc
Pulse Author: AlienVault
Created: 2025-04-04 11:47:53

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

#Google #Chrome "feature" now broken.

I made many #GoogleChrome search engine "bookmarks" for sites I use often. As a keyboardist, I'd create engines with good shortcuts, but the URLs wouldn't use `%s` for the search string. E.g., my work uses #Canvas LMS, so I had a `cnvs` engine with URL `org.instructure.com/login/saml`. I'd type `cnvs` in the box, press enter, & away it'd go.

Now engine URLs without `%s` are invalid! I add `%s` to make them work, but now I must type a search string, too! 😛👹👺