Skip to main content

Posts

Showing posts with the label phishing attacks

Google to Block Logins From Embedded Browser Frameworks to Protect From Phishing & MitM Attacks

Google announced a new security update to block users sign-in using Embedded browser frameworks in order to improve the protection against Phishing and MitM attacks. Jonathan Skelker, Product Manager and Account Security at Google said, “Form of phishing, known as “ man in the middle ” (MITM), is hard to detect when an embedded browser framework (e.g.,  Chromium Embedded Framework  – CEF) or another automation platform is being used for authentication. “ Cybercriminals abusing this technology to perform Man-in-the-Middle attacks and steal the user’s credentials by intercepting the web traffic when Embedded browsers frameworks help users for the automated login process. Embedded Browser Frameworks Lets Hackers Intercept the Traffic If any users enter the Google account credentials on the phishing page that using Embedded browser frameworks will automate the login process by interacting with the original Google server. Meanwhile,  MITM  attacker intercepts the commun