Google Chrome extension The Great Suspender could spy on a user’s browsing habits, inject ads into websites, or download sensitive data. The extension’s owner sold it to a third party that silently released a version silently released. Google eventually set things right, but it took too long. Security teams must carefully reach out to the impacted employee individually and guide them toward making prudent decisions on their own, says Peter Bergen. Bergen: The risks associated with running suspicious extensions usually impact the employee, not the company, more.”]

