05/09/2026
When was the last time you looked at the browser extensions installed on your computer?
I'm guessing the answer is... never š¤·
Once an extension is installed and working, it disappears into the background. You stop thinking about it.
That's why this latest announcement from Microsoft caught my attention š
It has removed 119 malicious extensions from the Edge Add-ons store after discovering they had been downloaded around 2.6 million times.
These were tools people install every day, including ad blockers, PDF tools, VPNs, translators and video downloaders.
On the surface, they appeared perfectly legitimate.
The malicious behaviour didn't start straight away.
In many cases, the extensions waited days before doing anything harmful, so they were much harder to detect.
From there, some were able to steal information stored in the browser, redirect people to malicious websites, or download additional software onto the device.
Cyber attacks are changing š¬
Years ago, we thought about security in terms of downloading the wrong file or opening the wrong email attachment.
Today, attackers are much happier to hide inside software that people already trust.
A browser extension feels harmless because it's designed to make life easier.
It might block adverts, help you edit PDFs or translate web pages, so it doesn't raise suspicion.
Now, most browser extensions are perfectly safe and genuinely useful. But they're worth treating like any other software you install.
If you no longer use one, remove it.
If you don't recognise one, find out what it does.
And if an extension asks for permissions that seem excessive, ask why it needs that level of access.
One of the biggest lessons in cyber security is that convenience and trust are closely linked.
The more useful something appears to be, the less likely we are to question it.
That's what attackers are counting on š±
š How many browser extensions do you think are installed on your computer right now... and could you name them all?