#BrowserVPNSecurity
OAuth Phishing Attacks Bypass Passwords by Turning User Consent Into a Security Threat #Accountsecurity #AIPhishingAttacks #BrowserVPNSecurity
OAuth Phishing Attacks Bypass Passwords by Turning User Consent Into a Security Threat
 Cybercriminals are targeting something more difficult to protect with traditional password advice: the user consent. New phishing techniques called OAuth consent phishing allow the intruders to gain persistent access to the targeted accounts without stealing their passwords, according to a recent FBI warning. The bureau’s Internet Crime Complaint Center described the technique in a September 1 public service announcement, noting that it has been observed since late 2025 and is targeting prominent individuals and their families and personal contacts.  The FBI describes OAuth consent phishing as accessing accounts without requiring the user’s password. OAuth is the framework that allows the services to use the familiar “Sign in with” or “Continue with” authentication options. It allows the legitimate third-party applications to request access to the resources like emails, calendars, files, and cloud storage without requiring the users to share their passwords.  The attackers are taking advantage of the legitimate procedure to get account access. The attack typically starts with sending a message that appears to be sent from a trusted contact or service. The victim clicks on the link and enters their credentials on a real login page of a trusted site. The user is then directed to an app authorization screen asking to allow specific permissions such as reading emails or accessing files.  If the victim approves the request, the intruder receives an OAuth authorization token with the permissions granted. This changes the response needed to compromise. Unlike with traditional credential phishing, changing the password will not eliminate the malicious OAuth token. The FBI recommends that the victims revoke the unauthorized authorization through their application security settings. Changing the credentials or using a new MFA code will not remove the granted access. The campaigns can also scale.  In recent months, security researchers have documented 10 to 15 new operations of this type every 24 hours in recent months, with several million attacks recorded during a single four-week period earlier this year. Phishing kits such as Kali365 and EvilTokens have further lowered the technical barrier for attackers. Security tools can help address some of the attack steps, without preventing the user from voluntarily approved malicious permission request.  The network can block known phishing domains, malicious redirectors, and scam infrastructure before the victim reaches them. Dark web monitoring can also alert users if their email addresses appear on cybercrime forums after an account compromise. The change highlights a shortcoming in traditional account-security advice: protecting passwords and MFA remains important, but users must scrutinize the applications and permissions they authorize.
dlvr.it
September 24, 2026 at 3:33 PM
Google’s Incognito Mode Does Not Make Users Invisible. Here’s What It Actually Protects #Browser #BrowserVPNSecurity #Chrome
Google’s Incognito Mode Does Not Make Users Invisible. Here’s What It Actually Protects
  Google’s Chrome Incognito mode can keep browsing history off a device, but it was never designed to make users anonymous online. A class-action lawsuit over the feature exposed how far that distinction could be misunderstood, with Google agreeing to delete or remediate billions of private-browsing records and change how it explains Incognito to users. The lawsuit, Brown v. Google, was filed in 2020 and alleged that Google continued collecting information about users while they browsed through Chrome’s Incognito mode and other browsers’ private-browsing modes. The plaintiffs initially sought billions of dollars in damages, with their claims eventually putting at least $5 billion at stake. However, Google did not ultimately agree to pay $5 billion. Under the settlement, there was no class-wide monetary payout. Instead, Google agreed to data deletion and remediation measures, changes to its privacy disclosures, and additional restrictions on data collection. Plaintiffs’ lawyers valued the settlement’s non-monetary relief at more than $5 billion, with estimates reaching $7.8 billion. The case nevertheless exposed a fundamental problem with private browsing: preventing a browser from retaining a user's history is not the same thing as preventing websites, network operators or online services from observing that user's activity. Google employees raised concerns about Incognito The legal dispute became particularly notable after internal Google communications surfaced during litigation. In one email, Google Chief Marketing Officer Lorraine Twohill told CEO Sundar Pichai that the company should make Incognito "truly private." She also warned that Google could not market the feature too strongly because it was "not truly private," requiring what she described as "fuzzy, hedging language." Other internal communications were even more critical of the feature. According to material cited in the litigation, Google employees described Incognito as "misleading" and "effectively a lie," while another employee argued that Google should stop using the Incognito name and its spy-themed icon because users could misunderstand the protection it provided. Another recommendation suggested replacing the messaging with a warning that users were not protected from Google. These discussions mattered because the lawsuit was not simply about whether Incognito stored browsing history locally. It questioned whether users were being given a sufficiently accurate understanding of what happened to their data after it left the browser. Google disputed the allegations and maintained that the limitations of Incognito had been communicated to users. A Google spokesperson said the company believed the lawsuit was without merit and argued that Incognito was intended to provide a private browsing experience, rather than prevent websites and services from collecting information. What Incognito actually does Chrome's Incognito mode does provide a real privacy function, but that function is primarily local. When a user opens an Incognito window, Chrome starts a separate browsing session. Once all Incognito windows are closed, Chrome does not retain the browsing history, cookies and site data, or information entered into forms from that session in the normal browser profile. Third-party cookies are also blocked by default in current versions of Chrome, although users can temporarily allow them for particular sites. This makes Incognito useful in situations where the concern is another person accessing the same device. Someone using a shared computer, for example, can browse for a gift without leaving the visited pages in Chrome's ordinary history. It can also provide a separate browsing session when a user does not want existing cookies and account sessions to carry over. But there is an important limitation. Incognito does not erase everything created during a session. Downloads remain on the device, and bookmarks saved during the session remain available after Incognito is closed. Signing into a website can also allow that service to associate activity with the account being used. The key distinction is therefore simple: Incognito primarily limits what Chrome stores locally. It does not turn the internet connection into a private tunnel. Your ISP and network administrator can still see activity Opening an Incognito window does not prevent an internet service provider from observing network activity. Google's own documentation states that organizations managing a network, including schools, employers and internet service providers, may be able to observe activity while a user is browsing in Incognito. Incognito also does not hide activity or location from the websites being visited. This is an important distinction from encryption. Chrome's HTTPS protections can encrypt traffic between a browser and an HTTPS-enabled website, helping prevent someone monitoring the connection from reading the contents of that traffic. Chrome also warns users when they are about to load sites without HTTPS, while Secure DNS can encrypt DNS lookups in supported configurations. But HTTPS does not make the user anonymous. The network still has visibility into connection metadata, while the destination website receives the request and can process information available to it. In other words, Incognito and HTTPS solve different problems. Incognito reduces local traces. HTTPS protects communications in transit. Neither one, by itself, is an anonymity system. Websites can still identify and track users The privacy boundary becomes even clearer once a user reaches a website. Google's current Chrome documentation explicitly states that Incognito does not change how websites collect data or how the services those websites use collect information. Sites can continue gathering information even when a user is not signed in. Websites can also use first-party technologies and other mechanisms to understand activity within a session. Third-party cookies are only one part of the tracking ecosystem. Google itself notes that websites can use different mechanisms to personalize content and advertising and learn about activity across sites. This is also where the distinction between an IP address and browser history matters. Incognito can prevent a local Chrome profile from retaining the list of pages a user visited. It does not automatically conceal the network address from the websites receiving the connections. And if a person voluntarily signs into a service while using Incognito, the service has an obvious account-level identifier with which to associate the activity. Google's own documentation warns that signing into a Google service or another website during an Incognito session can allow that site to remember the activity. The lawsuit forced changes to Incognito The settlement went further than simply changing a warning message. According to the court filing, Google agreed to delete or remediate billions of records reflecting class members' private browsing activities. The company also agreed to continue blocking third-party cookies in Incognito for five years. The filing provides an unusually detailed picture of why the cookie change mattered. Google had historically collected its own third-party cookies when users visited non-Google websites. After the lawsuit was filed, Google implemented third-party-cookie blocking for Incognito users. Under the settlement, that protection had to remain in place for five years. The plaintiffs' filing said blocking data associated with Google's third-party cookies in Incognito could reduce Google's global annual revenue by nearly $500 million. Google also agreed to remove four identified private-browsing detection signals. According to the plaintiffs' filing, those signals could reveal that a user had chosen private browsing and were then used to label the resulting data as private. The settlement required Google to delete those signals and agree not to use such detection mechanisms to identify or track private browsing. The class covered an estimated 136 million users, according to court-related filings. Google eventually changed the warning The dispute also changed the language presented to Chrome users. Chrome's current Incognito documentation now makes the limitation explicit. It says that Incognito does not change how data is collected by websites users visit and the services those websites use, including Google. Google also says that websites, network administrators and ISPs may still be able to observe activity during an Incognito session. That clarification is arguably more important than the Incognito icon itself. The familiar private-browsing interface can create an intuitive association between the words "Incognito" and anonymity. Technically, however, the feature is much narrower. Chromium describes Incognito as a window-level mode in which pages are not persisted to browsing history and a temporary cookie store is used for the session. That is a local privacy mechanism, not an invisibility cloak. So, is Incognito worth using? Yes, if the objective is local privacy. If you share a computer with other people, do not want a particular browsing session stored in your ordinary history, or want a temporary browser session separated from your normal cookies, Incognito remains useful. It is also useful for testing how a website behaves without the cookies and account state associated with a normal session. But users should not treat the Incognito icon as a guarantee that their online activity is hidden. It does not prevent an ISP or network administrator from observing activity. It does not stop websites from collecting information. It does not automatically hide an IP address. It does not prevent a user from being identified after signing into an account. And it does not protect files downloaded to the device after the session ends. Users seeking stronger privacy need to think in layers rather than relying on a single browser setting. A privacy-focused browser can reduce tracking at the browser level. Tracker and content blockers can limit third-party collection. A properly configured VPN can conceal the user's IP address from the websites they visit and hide destination traffic from the ISP, although the VPN provider itself becomes part of the trust model. Keeping the browser, operating system and extensions updated remains essential because privacy controls cannot compensate for an unpatched security vulnerability. Chrome itself should also not be treated as static. Google continues to modify its privacy and security architecture. Third-party-cookie protections in Incognito are already part of the browser's privacy model, while Google has also explored additional protections for IP addresses in Incognito. The larger lesson from the Incognito lawsuit is therefore not that private browsing is useless. It is that privacy has layers, and the word "private" can mean very different things depending on where the data is stored, who controls the network and which services receive the user's requests. Incognito can hide your browsing history from someone checking the same device. It cannot make you disappear from the internet.
dlvr.it
August 18, 2026 at 7:31 PM
US Treasury Sanctions VPN Provider Linked to Ransomware Operations #BrowserVPNSecurity #CriticalInfrastructure #CyberAttacks
US Treasury Sanctions VPN Provider Linked to Ransomware Operations
 The United States Department of the Treasury has taken unprecedented steps by sanctioning a virtual private network (VPN) service provider and its administrator for the first time ever. The VPN was used by ransomware groups to disguise their digital footprints and launch attacks on businesses in the United States. The Treasury’s Office of Foreign Assets Control (OFAC) sanctioned First VPN Service (1VPNS) and its Ukrainian administrator, Dmytro Rashevskyi.  In addition, the OFAC sanctioned Belarusian national Yegeniy Vladimirovich Silayev for allegedly selling cryptors – software used to camouflage ransomware and other malicious computer programs. According to the Treasury, ransomware groups that use the services of 1VPNS have already generated billions of dollars in losses for businesses and critical infrastructure in the United States. The victims of such attacks include hospitals, local governments, banks, and other organizations.  The Treasury alleges that First VPN Service has been operating since 2014 and has been marketing itself on hacker forums as a privacy-focused provider that does not store any information on its users and does not respond to any legal requests. In addition, investigators allege that Rashevskyi used the nicknames Maksim Sorin and Roman Chabanenko to sign up for hosting services from other companies that had declined to provide services to First VPN Service due to illegal activities.  Furthermore, the Treasury alleges that First VPN Service has been used to mask the Internet Protocol (IP) address of users who utilize the service to conceal their tracks on the web. In addition, the accused used the VPN to hide the origin of ransomware distribution, attack infrastructure, and exfiltrate data during cyber-espionage and ransomware operations.  Silayev, who is not affiliated with First VPN Service, has been accused of selling encryption and obfuscation tools that enable malicious software to elude detection by cybersecurity software, thus increasing the software’s success rate. The sanctions imposed on the individuals and entities involved prevent them from accessing any property or funds in the United States or controlled by Americans.  In addition, Americans are generally prohibited from dealing with them, and entities owned at least 50% by the sanctioned individuals or entities are also banned. According to the Treasury, the sanctions will disrupt ransomware cybercriminals’ ability to operate and deter organizations from supporting ransomware groups by continuing to offer their services.  The action taken by the OFAC comes after an international law enforcement operation that dismantled First VPN Service in May 2026. During the operation, European authorities and the FBI searched 33 servers, one surface web domain, and one Tor domain, as well as a Ukrainian residence.  In addition, investigators identified individuals who purchased the service from the company. The recent sanctions imposed by the Treasury on First VPN Service and its administrator follow the Treasury’s sanctions against the infrastructure of the 911 S5 botnet, which disrupted hundreds of thousands of computers using free VPN applications that doubled as anonymous proxy servers for cybercriminals in 2024.
dlvr.it
July 27, 2026 at 3:20 PM
ExpressVPN Expands Privacy Tools with Launch of Hybrid Browser Extension #BrowserVPNSecurity #ExpressVPN #HybridVPNExtension
ExpressVPN Expands Privacy Tools with Launch of Hybrid Browser Extension
  Increasingly, immersive technologies are moving from being novel to being part of everyday digital infrastructure, which raises questions regarding privacy within virtual environments. Activities previously conducted on conventional screens now occur within headsets that process vast streams of personal data, such as browsing behavior, location signals, and device interactions, as well as process vast streams of personal data. It has been announced that ExpressVPN has partnered with Meta in recognition of this emerging privacy frontier, which will allow its security tools to be integrated directly into Meta Quest. An application will be introduced by Meta through the Meta App Store, which will enable headset users to activate full-device VPN protection within the virtual reality environment.  Additionally, ExpressVPN has released a hybrid browser extension that combines VPN and proxy functionality into an effective privacy tool, signaling an ongoing effort to adapt traditional internet security models to the increasingly complex environment of immersive computing. An integral part of the newly introduced extension is Smart Routing, which enables users to control how browser traffic interacts with the VPN network with granularity.  By using the system, specific websites can be automatically linked to predefined VPN endpoints or routing preferences rather than requiring users to switch server locations multiple times when navigating between services hosted in various regions. In addition to streamlining the management of geographically sensitive connections, this approach also maintains a consistent level of privacy protection. Additionally, additional safeguards have been implemented in order to increase protections at the browser-level. WebRTC leaks are a well-known method by which IP addresses can be uncovered despite the use of VPNs, and the extension incorporates mechanisms to block them. HTML5 geolocation data transmission is also restricted by controls in the extension. These measures are designed to prevent websites from inferring a user's physical location through browser-based signals by limiting the ability of websites to do so.  In light of the fact that most digital activity now takes place within web environments, browser-centric protection has been focused as a way to address this reality. In order to facilitate streaming media, electronic commerce transactions, and collaborative work platforms, browser interfaces are increasingly replacing standalone software applications.  It appears as though the company is positioning the hybrid extension as a flexible bridge between lightweight web privacy and comprehensive network protection by concentrating security controls at this layer while still providing a primary VPN application that can fully encrypt devices at the device level. At the same time, the company is expanding its privacy infrastructure beyond traditional computing devices to include immersive technology, which is rapidly gaining in popularity. In addition to the Meta Quest platform support, we are introducing a dedicated VPN application which can be downloaded directly from the Meta App Store, enabling encrypted connectivity across the headset's system environment. Additionally, the hybrid extension is expected to be available on the platform in a browser-specific version, providing an additional level of security for virtual reality activities.  It has historically been difficult to deploy conventional VPNs in VR ecosystems, requiring complex network workarounds or external device configuration. Native integration therefore indicates a significant change in how privacy tools are adapting to these environments. It is important to note that this development is part of a broader change that is occurring within the VPN industry as internet usage gradually expands into a variety of connected hardware categories.  Increasingly, browsing occurs within headsets and other immersive devices, rather than just laptops or smartphones. The use of flexible routing and layered protection to safeguard user data across emerging digital interfaces may become more prominent as a result of the emergence of this technology.  In addition to providing an encrypted connection directly to the Meta Quest headset through a dedicated application distributed through the Meta App Store as part of the company's collaboration with Meta, the company is introducing hybrid browser technology as well. As a result of this development, virtual reality headsets are increasingly regarded as more than entertainment devices; they are becoming full-featured computing platforms that facilitate various digital activities, including communication, content consumption, and collaboration.  ExpressVPN utilizes a native VPN application that is deployed within the device environment to ensure that network traffic generated by the entire headset is routed through encrypted channels rather than limiting protection only to individual applications or browsing sessions. This type of system-wide coverage is especially useful for applications that consume large amounts of bandwidth, such as VR streaming and multiplayer gaming, where unprotected traffic can be subjected to network throttling.  In addition, the company stated that its newly introduced hybrid extension will shortly be extended to the headset's native browsing environment in the near future. VR browser users will be able to secure web traffic via a streamlined protection mode once it is implemented, which will not require the user to remain active through a background VPN.  In addition to providing additional privacy for browser-based activity, this lighter configuration also ensures that system resources are preserved during performance-sensitive applications, such as those that affect the immersive experience directly due to computational overhead and frame stability.  As part of the extension architecture, the provider's proprietary Lightway Protocol has been updated to incorporate post-quantum cryptographic protections, as well as support for the extension architecture. By strengthening the protocol, we hope to address emerging concerns that future developments in quantum computing may undermine conventional encryption algorithms, positioning it as a forward-looking safeguard against decryption capabilities of the future. It is currently available for popular browsers including Google Chrome and Mozilla Firefox, however it is expected that integration with Meta Quest in the near future will be available as soon as possible. Combined, the developments demonstrate how privacy infrastructure is gradually evolving in order to accommodate new digital interfaces, extending encrypted connectivity beyond traditional desktop and mobile ecosystems into immersive computing environments.  The combination of these developments illustrates how privacy architectures are gradually being revised to accommodate the changing boundaries of the internet as digital interaction is increasingly centered on browsers, applications, and immersive devices. Security strategies that once focused on a single device or network layer are becoming more adaptable to meet changing requirements.  Organizations and individual users should examine how data flows through emerging platforms and ensure that encryption and routing controls evolve simultaneously. With the internet continuing to extend beyond conventional computing interfaces, solutions that integrate flexible browser-level safeguards with device-wide encryption may represent a practical solution for maintaining consistent privacy standards.
dlvr.it
March 8, 2026 at 1:18 PM