meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

Targeting your browser bookmarks? [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

Technology, Tech News, Daily News, News

4.81.1K Ratings

🗓️ 1 October 2022

⏱️ 18 minutes

🧾️ Download transcript

Summary

David Prefer from SANS sits down with Dave to discuss how a new covert channel exfiltrates data via a browser's built-in bookmark sync. David goes on to describe how this research will "describe how the ability to synchronize bookmarks across devices introduces a novel vector for data exfiltration and other misuses." In the research, he shares how he tested his said hypothesis and goes on to describe how the interesting find was tested on multiple browsers including Chrome, Edge, Brave and Opera. In his research, he found that bookmarks are able to keep data and synchronize it, making it easier to infiltrate and extract data from. David shares the rest of his findings, as well as what organizations and browser developers can do to work on this new threat. The research can be found here: Bookmark Bruggling: Novel Data Exfiltration with Brugglemark Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the CyberWire Network, powered by N2K.

0:07.0

Today's episode is sponsored by SRM, your first call for cybersecurity and

0:18.1

investigations. Threats today are evolving faster than ever before and since 2005 SRM has pioneered

0:25.3

tailored security solutions for global corporations and their executives.

0:29.5

Whether it's defending against cyber attacks with their award-winning team of ethical hackers and incident response specialists,

0:36.4

or navigating the murky waters of compliance and ESG challenges,

0:40.9

SRMs, Insight and Straight straightforward advice will help you navigate complex risks

0:46.4

and emerge more resilient.

0:48.4

Their secret, a culture that nurtures the sharpest minds, giving them access to the newest technologies and the freedom

0:55.3

to solve problems in new ways, enabling them to craft simple effective solutions for your

1:01.4

unique cyber challenges.

1:03.7

Search your first call to discover how SRM can help your business. Hello everyone and welcome to the CyberWire's research Saturday.

1:27.0

I'm Dave Bitner and this is our weekly conversation with researchers and analysts tracking

1:31.9

down the threats and vulnerabilities solving some of the hard problems of protecting ourselves in a rapidly evolving cyberspace.

1:39.0

Thanks for joining us. You know, I actually had this idea sort of coming to me a few years back actually, where I was contemplating how there are some extremely

1:55.4

common applications that most organizations are likely to be using and then

2:00.6

sort of wondering myself you know how many of those have an inherent need to communicate with or access resources outside of the corporate network?

2:09.6

And so that kind of drew my attention to browsers and what and what functions might exist that may not have been given much attention in that regard.

2:17.0

That's David Prefer. He's a student at the SENS Technology Institute.

2:22.0

The research we're discussing today is titled Bookmark

2:24.8

Bruggling. Novel Data Exfiltration with Bragglemark. Well, I think it's fair to say that browsers,

2:33.0

some people.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.