[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fG3YffVfy6Wpr_7_H9k911hYD9Rkv_nPk9Zamh2dQSKc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"51b90c5d-7977-432c-abd4-515f749748c9","browser-side-channel-attack-exploits-drive-activity-for-cross-tab-spying","951081a3-099f-4e0b-a72e-d061db485910","Browser Side-Channel Attack Exploits Drive Activity for Cross-Tab Spying","The FROST technique demonstrates how attackers can exploit browser APIs and hardware side channels to breach user privacy without requiring any permissions or downloads. By measuring subtle timing differences in solid-state drive operations through JavaScript and the Origin Private File System API, malicious websites can infer what other websites and applications users have open. This attack highlights the growing sophistication of browser-based surveillance techniques that can bypass traditional security controls. Organizations must recognize that even seemingly harmless website visits can now potentially compromise user privacy and sensitive information about their digital activities.","**Immediate actions:**\n- Disable or restrict the Origin Private File System API in organizational browsers through group policies\n- Implement browser isolation solutions for high-risk web browsing activities\n- Configure content security policies to limit JavaScript execution capabilities\n\n**Long-term improvements:**\n- Deploy endpoint detection tools that monitor for unusual browser-based data collection patterns\n- Establish policies requiring use of hardened browser configurations for sensitive work\n- Implement network-level monitoring to detect suspicious cross-domain communication patterns\n\n**User education measures:**\n- Train users to avoid opening sensitive applications while browsing untrusted websites\n- Educate staff about the risks of browser-based side-channel attacks and privacy implications\n- Promote use of separate browser profiles or virtual machines for different types of activities",[12,13,14,15,16],"CIS Control 7","CIS Control 11","NIST PR.DS-5","NIST PR.AC-3","GDPR Article 32","published","2026-06-01T10:05:34.183849+00:00","2026-06-01T10:05:33.908+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fwebsites-can-now-spy-on-you-through-your-hard-drive\u002F","websites-can-now-spy-on-you-through-your-hard-drive-96f78d","Websites Can Now Spy on You Through Your Hard Drive",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":32,"name":33,"slug":34,"description":35,"color":36},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]