Floating servers depicting HR platform breaches and Black Basta cyber threats.

Daily Cybersecurity News - January 18, 2026

Chrome Extensions Target Hr Platforms

Executive Summary

Malicious Chrome extensions, posing as productivity and security tools, targeted enterprise HR and ERP platforms to steal authentication credentials. The extensions blocked access to security management pages, hindering incident response.

Key TTPs

  • Initial Access: Masquerading as legitimate productivity and workflow tools on the Chrome Web Store.
  • Execution: Stealing authentication tokens and session hijacking via cookie exfiltration and injection.
  • Defense Evasion: Blocking access to security and incident response pages within targeted platforms.

Campaign Analysis

The extensions exfiltrated cookies every 60 seconds to attacker-controlled servers, maintaining persistent access. The attackers could take over authenticated sessions without needing usernames, passwords, or multi-factor authentication.

Targeting & Infrastructure

  • Target Profile: Enterprise HR and ERP platforms such as Workday, NetSuite, and SAP SuccessFactors.
  • Infrastructure: Use of multiple developer accounts to publish extensions with identical code and infrastructure patterns.

Relevant Terms

  • Session Hijacking: Exploiting a valid computer session to gain unauthorized access to information or services.
  • DOM (Document Object Model): A programming interface for HTML and XML documents that represents the page structure, allowing programs to modify the content.

Black Basta Leader Added to Most Wanted List

Executive Summary

Ukrainian and German authorities identified Oleg Evgenievich Nefedov, the alleged leader of the Black Basta ransomware group. Nefedov has been added to the EU's Most Wanted and INTERPOL's Red Notice lists.

The Scheme

  • TTP 1: Technical hacking of protected systems.
  • TTP 2: Hash cracking to extract passwords.
  • TTP 3: Deploying ransomware and extorting money for decryption.

The Players

  • Threat Actor: Russia-linked RaaS Black Basta.
  • Facilitators Arrested: Two Ukrainian nationals (Hash Crackers).
  • Fugitive at Large: Oleg Evgenievich Nefedov (Leader).

The Consequence

  • Outcome: Authorities conducted searches and seized digital storage devices and cryptocurrency assets.

Strategic Takeaway

The addition of Black Basta's leader to the most wanted list highlights the ongoing international effort to combat ransomware.

Relevant Terms

  • Ransomware-as-a-Service (RaaS): A business model where ransomware developers lease their ransomware tools to affiliates who conduct attacks.
  • Hash Cracking: The process of recovering passwords from a cryptographic hash using specialized software.