By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: From Firefox Malware to Stolen Pornhub Data: This Week’s Security News Is Not Sexy
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > From Firefox Malware to Stolen Pornhub Data: This Week’s Security News Is Not Sexy
News

From Firefox Malware to Stolen Pornhub Data: This Week’s Security News Is Not Sexy

News Room
Last updated: 2025/12/21 at 7:11 AM
News Room Published 21 December 2025
Share
From Firefox Malware to Stolen Pornhub Data: This Week’s Security News Is Not Sexy
SHARE

I know a lot of developers who got their start building Chrome or Firefox add-ons that include useful features that the browser itself didn’t have. Unfortunately, over the years, I’ve also seen a number of those add-ons get sold to companies that turned them into spyware, adware, or, as we reported this week, straight-up malware that can steal your browsing history, conversations with chatbots, and more. I think now is a good time to take a moment to remove any add-ons you no longer need or are outdated, don’t you?

Stay tuned on the add-on front, because we have even more bad news a little later on. Before we get to that, though, if you’re a Pornhub premium subscriber, keep an eye on your inbox: hackers have stolen over 94GB of search histories, viewing activity, and other data from subscribers. Here’s a simple opsec tip for my fellow adults in the room: never use your real name, real email address, or any other identifying information when engaging with adult content online. Use disposable email addresses, never use a username that can be traced back to any real handles you use online, and even consider virtual credit card numbers. Adult content is a goldmine for scammers looking to extort money, data, or worse. 

Ironically, it’s tips like these that you’ll get when you read our annual roundup of the best security advice we’ve heard this year, all from experts, analysts, and some even from the crew here on the PCMag security team. 

Meanwhile, in the wake of all these threats, Google announced this week that it’s retiring its dark web monitoring tool, which helps users determine if their data has been exposed. Luckily, if you were relying on it, you have much better options to turn to that will actively monitor and report to you if any of your data turns up in a breach.


Thousands of Firefox Users Compromised: 17 Extensions Hide Malware in Icons

If you thought that only Chrome users were at risk of malware-infested browser extensions, think again. Researchers at Koi Security identified 17 Firefox extensions that also host malware, hidden within their PNG icons. This attack method is known as steganography, where a payload or message is concealed within an image to evade detection. Sometimes used as a method of encryption, in this case, the PNG is actually a loader for the malware, which is then fetched from a remote server and runs irregularly, making it difficult to detect. 

The actual malware is also quite nasty, performing a range of malicious actions, including hijacking affiliate links (which means the attacker receives a cut of your online purchases), tracking your browsing habits, stripping security headers from the sites you visit, and even bypassing captchas designed to block bots. I’m just skimming the surface here, and that’s the worst part. The malware actually does more, and is surprisingly sophisticated in evading detection.

Newsletter Icon

Get Our Best Stories!

Stay Safe With the Latest Security News and Updates


SecurityWatch Newsletter Image

Sign up for our SecurityWatch newsletter for our most important privacy and security stories delivered right to your inbox.

Sign up for our SecurityWatch newsletter for our most important privacy and security stories delivered right to your inbox.

By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy
Policy.

Thanks for signing up!

Your subscription has been confirmed. Keep an eye on your inbox!

Cybernews has the full list of offending extensions, most of which are actually still live in the Firefox add-ons marketplace. Among the extensions caught using the same tactics are a free VPN (called Free VPN Forever, which serves as another reminder that free VPNs often aren’t all they’re cracked up to be), a live translation add-on, a weather extension, and an MP3 downloader. Remember, just because an add-on is in the Firefox marketplace or the Chrome web store doesn’t mean it’s safe, or has even been reviewed recently for malicious code changes.


LastPass Hammered With $1.6M Fine for 2022 Breach Fiasco

In 2022, LastPass suffered a breach that resulted in a hacker obtaining encrypted copies of customer vaults, as well as personal information like names, email addresses, billing addresses, and IP addresses. Eventually, that breach was traced back to both the theft of some of the company’s source code earlier that year and a keylogger that had been planted on an employee’s home computer. Aside from the personal data that was lost, the only way anyone could make use of an encrypted vault was if they had the master password for it, but it wasn’t a good look for a security company, sadly. 

Now, the UK’s Information Commissioner’s Office (ICO) has fined the company £1.2M (approximately $1.6M) as a result of the breach, according to The Register. The ICO stated that the breach ultimately impacted 1.6 million users in the UK alone and that the company fell short of the expectations that its customers had that it would keep their data safe and secure. Additionally, the ICO claimed that LastPass failed to implement the necessary security measures to protect its customers, and also suffered from organizational issues that should have been resolved. Our review of LastPass highlights several security issues, some of which remain unresolved, despite the company’s assertion that, following the 2022 breach, it has taken numerous steps to enhance security and regain customer trust. 

Recommended by Our Editors


Analysts Warn of Cybersecurity Risks in Humanoid Robots

Personally, I have no desire to have a humanoid robot in my home (it feels a little too close to owning a person, you know?) but that’s not stopping dozens of companies from unveiling their own, and as Dark Reading reports, having a humanoid robot in proximity to real, living, breathing humans comes with security risks that few of those companies, or the public, have considered. 

Beyond the usual fears of Terminator-style violence (although the Chinese company EngineAI does have a humanoid robot called the “T800”), security analysts are more concerned in the short term with humanoid robots joining the array of smart home devices that are always connected, always listening, and always collecting data. The last thing you might want to learn is that the $5000 robot you purchased to fold your laundry and do your dishes is actually part of a botnet, or has been recording and sending all of your household conversations back to its manufacturer. 

Dark Reading’s story also explains why robots are so hard to secure at this stage, too: They’re not like PCs, running specific software for specific systems; they’re networks of networks, systems with hundreds of embedded systems, and as of right now, no one makes security tools to keep them safe and secure. 

About Our Expert

Alan Henry

Alan Henry

Managing Editor, Security


Experience

I’ve been writing and editing stories for almost two decades that help people use technology and productivity techniques to work better, live better, and protect their privacy and personal data. As managing editor of PCMag’s security team, it’s my responsibility to ensure that our product advice is evidence-based, lab-tested, and serves our readers.

I’ve been a technology journalist for close to 20 years, and I got my start freelancing here at PCMag before beginning a career that would lead me to become editor-in-chief of Lifehacker, a senior editor at The New York Times, and director of special projects at WIRED. I’m back at PCMag to lead our security team and renew my commitment to service journalism. I’m the author of Seen, Heard, and Paid: The New Work Rules for the Marginalized, a career and productivity book to help people of marginalized groups succeed in the workplace.

Read Full Bio

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article The best games of 2025 ranked – which is your favourite? The best games of 2025 ranked – which is your favourite?
Next Article Forget board games – the best free games all the family can play this Christmas Forget board games – the best free games all the family can play this Christmas
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Extremists are using AI voice cloning to supercharge propaganda. Experts say it’s helping them grow
Extremists are using AI voice cloning to supercharge propaganda. Experts say it’s helping them grow
Software
Ring settings everyone needs to save parcels & spot burglars this Christmas
Ring settings everyone needs to save parcels & spot burglars this Christmas
News
Huion Kamvas Pro 24 (Gen 3) drawing tablet Review: Wacom is in trouble
Huion Kamvas Pro 24 (Gen 3) drawing tablet Review: Wacom is in trouble
News
Our favorite stuff of 2025
Our favorite stuff of 2025
News

You Might also Like

Ring settings everyone needs to save parcels & spot burglars this Christmas
News

Ring settings everyone needs to save parcels & spot burglars this Christmas

8 Min Read
Huion Kamvas Pro 24 (Gen 3) drawing tablet Review: Wacom is in trouble
News

Huion Kamvas Pro 24 (Gen 3) drawing tablet Review: Wacom is in trouble

1 Min Read
Our favorite stuff of 2025
News

Our favorite stuff of 2025

21 Min Read
Ace Combat 8 Will Incorporate Dogfighting Tips From Real Jet Pilots
News

Ace Combat 8 Will Incorporate Dogfighting Tips From Real Jet Pilots

11 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?