When Browsers Become the Attack Surface: Rethinking Security for Scattered Spider

Discussion in 'other security issues & news' started by stapp, Sep 1, 2025 at 12:34 PM.

  1. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    28,628
    Location:
    UK
    https://thehackernews.com/2025/09/when-browsers-become-attack-surface.html
     
  2. gary_seven

    gary_seven Registered Member

    Joined:
    Nov 2, 2021
    Posts:
    13
    Location:
    california
    Very interesting report. One tool they highlight is Seraphic's BrowserTotal. While I'm anxious & interested to try it (on my production machine/environment - ran it in sandbox already), I don't see many posts from folks who have tried it ---> which makes me hesitant. Anyone care to comment?
     
  3. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,627
    Location:
    U.S.A. (South)
    Iconic Coolwebsearch never died. It simply waited and then evolved spawning millions of newer tentacles.
     
  4. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,649
    Location:
    Flat Earth Matrix
    New? Browsers were always #1 target, a browser is always allowed, it is like an opened window in a castle, thus locking it down is basics. I have no extensions, everything disabled, site permission blocked, only TCP port 443 allowed.

    It is paid to see, so ... It reports 10 Failed, but logs are hidden, I have only managed to glance at some errors like that XSS was loaded, the browser did not recent SSL and that is it.
     

    Attached Files:

    Last edited: Sep 2, 2025 at 3:06 AM
  5. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,650
    Location:
    U.S.A.
    Not impressed with this test since its using badssl.com for its SSL tests;

    Eset_SSL.png
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.