A single unauthenticated connection gives attackers a full shell; credential theft observed in under three minutes on honeypot servers.
A new report dubbed "BrowserGate" warns that Microsoft's LinkedIn is using hidden JavaScript scripts on its website to scan visitors' browsers for installed extensions and collect device data.