
Episode 169: Malicious Browser Extensions
About this episode
In this episode, we’re digging into malicious browser extensions...the quiet, often overlooked attack vector living inside nearly every organization. While we focus on patching servers, hardening Active Directory, and deploying EDR, attackers are increasingly abusing the browser as their initial foothold. We’ll break down how these extensions work, why they’re so dangerous, and what IT leaders can realistically do about it.
Check out these resources:
Annex - Enterprise Software Extension Security & Management
https://x.com/IceSolst
[email protected]
Blog: https://offsec.blog/
Youtube: https://www.youtube.com/@cyberthreatpov
Twitter: https://x.com/cyberthreatpov
Follow Spencer on social ⬇
Spencer's Links: https://spenceralessi.com
Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
Get every episode summarized
Each time The Cyber Threat Perspective publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The Cyber Threat Perspective

Episode 173: How to Find Insecure Active Directory Permissions with ADeleg
The Cyber Threat Perspective

Episode 172: The biggest security blind spots in Midsized companies
The Cyber Threat Perspective

Episode 171: The future of pentesting with AI
The Cyber Threat Perspective

Episode 170: The Evasive Adversary
The Cyber Threat Perspective