this post was submitted on 17 Dec 2025
7 points (88.9% liked)

blueteamsec

570 readers
20 users here now

For [Blue|Purple] Teams in Cyber Defence - covering discovery, detection, response, threat intelligence, malware, offensive tradecraft and tooling, deception, reverse engineering etc.

founded 2 years ago
MODERATORS
top 1 comments
sorted by: hot top controversial new old

To copy what I said when this was posted in another community:

The png didn't do shit. Users where compromised by a malicious extension.

Steganagrophy (hiding data in a png) is a non issue and cannot do anything independently. It is also impossible to really stop.

Which is probably why the cybersecurity news cycle likes to pretend that steganagrophy is a risk on it's own, so that they can sell you products to stop this "theat".

I hate the clickbait title is what I'm trying to say. But the writeup is pretty interesting.

Although the real solution to this problem is probably only letting users install known safe extensions from an allowlist, instead of "pay us for consulting!".