QR Codes, Browser Extensions, and the difference between DR and BCP
This week: Why QR Codes should be called RQ Codes, why you need to think about browser extensions, and why you can't insure your way out of doing the real work.
3 - QR Codes should be called RQ codes
“The North Korean [gang] has been targeting government entities, academic institutions, and think tanks with spear-phishing emails containing malicious QR codes”
Source: SecurityWeek
What?
The FBI has warned that a North Korean cyber gang is sending highly targeted phishing emails containing malicious QR codes to high-value targets. These codes push users onto their mobile phones, which are not always protected by corporate security tools and thus increase the likelihood of the attack succeeding.
So What?
QR codes are images that enable us to go directly to a web page without having to type (or even see) the URL of the website.
But.. If we can’t see the URL of the website, how can we be sure the website is trustworthy?
As I’ve always said (even back in October 2024 and February 2023):
QR codes should really be called RQ codes: Really Questionable.
2 - Browser Extensions are Doorways for Attackers
“Malicious Google Chrome extensions have stolen large language models (LLM) conversations and browser data from hundreds of thousands of users.”
Source: Dark Reading
What?
Attackers recently cloned a legitimate Chrome browser extension to steal the ChatGPT and DeepSeek conversations, and other browsing data, from over 900,000 users. The extensions quietly sent sensitive prompts, corporate URLs, and other data to attacker servers, revealing how easily browsers and their add-ons can be attacked.
So what?
If you allow staff to install browser extensions or add-ons on their devices without prior approval, you’re increasing the likelihood that something malicious will get installed on one of your devices.
A browser extension could also be a doorway that an attacker uses to walk into your organisation.
1 - Business Continuity is not Disaster Recovery
“Business continuity is business operations. Disaster recovery is [just] the technical restoration – the nerd side”
Source: Insurance Business Magazine
What?
This recent interview with an insurer’s CISO reveals some very interesting insights, including:
The difference between DR and BC - DR (Disaster Recovery) is just about the technical restoration of data and systems. BC (Business Continuity) is about the broader ability of the business to continue (or recover) its operations.
An attacker’s path into your organisation may be through a supplier: The attackers have realised that “you can attack a large, very well-secured company via a third party who does not necessarily meet those same standards.”
Your insurance won’t save you if you haven’t done the work - While you may think you have significant insurance coverage, “if you fail to meet the basic controls that the cyber insurers are asking you to attest to… your coverage is not going to hold”
So what?
All of this reinforces why regulatory ‘pains’ like NIS2 and DORA (and regulators like the Central Bank of Ireland) are pushing organisations to take a broader view on what ‘appropriate security’ looks like.
You also can’t just deal with the risks through risk transfer.
You have to look at risk reduction.
In other words:
You can’t insure your way out of doing the real work.


