09/05/2026
When was the last time you looked at the browser extensions installed on your computer?
I'm guessing the answer is... never 🤷
Once an extension is installed and working, it disappears into the background. You stop thinking about it.
That's why this latest announcement from Microsoft caught my attention 👀
It has removed 119 malicious extensions from the Edge Add-ons store after discovering they had been downloaded around 2.6 million times.
These were tools people install every day, including ad blockers, PDF tools, VPNs, translators and video downloaders.
On the surface, they appeared perfectly legitimate.
The malicious behavior didn't start right away.
In many cases, the extensions waited days before doing anything harmful, so they were much harder to detect.
From there, some were able to steal information stored in the browser, redirect people to malicious websites, or download additional software onto the device.
Cyberattacks are changing 😬
Years ago, we thought about security in terms of downloading the wrong file or opening the wrong email attachment.
Today, attackers are much happier to hide inside software that people already trust.
A browser extension feels harmless because it's designed to make life easier.
It might block adverts, help you edit PDFs or translate web pages, so it doesn't raise suspicion.
Now, most browser extensions are perfectly safe and genuinely useful. But they're worth treating like any other softw