Advertisement
Malicious Chrome VPN Extensions Route Traffic via SOCKS5 Proxies
Over 730 free Chrome VPN extensions are redirecting user browser traffic through SOCKS5 proxies, enabling man-in-the-middle attacks and data interception.
AI Browser Prompt Injection Flaws Defeat Vendor Guardrails
New security research reveals that AI-powered web browsers remain susceptible to persistent prompt injection flaws despite guardrails.
Google Chrome Blocks Malicious New Tab Hijacker Extensions on Unmanaged Devices
Google Chrome will soon block policy-installed extensions from hijacking the New Tab page or changing the default search engine on unmanaged Windows and macOS devices.
Google Chrome Updates Resolve 1,442 Security Flaws
Google Chrome recently addressed 1,442 security flaws across versions 149, 150, and 151. Learn why immediate updates are crucial for user security.
JavaScript Smuggling: In-Memory Malware Assembly Evades Defenses
Attackers use JavaScript Smuggling and Blob objects to assemble infostealer malware in-memory, bypassing security filters on fake crypto and trading sites.
Anthropic Claude Chrome Extension: Malicious AI Action Trigger
A flaw in Anthropic's Claude for Chrome extension enables malicious extensions to trigger AI actions, potentially abusing access to connected services like Gmail, Google…
Advertisement
SASE AI Blind Spot: Why Packet Inspection Fails Modern Workflows
Enterprise data leakage via generative AI tools and browser extensions exposes critical flaws in traditional SASE models that rely solely on packet inspection.
Chrome 150 Update: Patching 27 Vulnerabilities, Critical Use-After-Free Flaws
Google Chrome 150 update patches 27 vulnerabilities, including two critical use-after-free bugs.
DuckDuckGo Browser Enhances Privacy with YouTube Ad Blocking
DuckDuckGo's privacy-focused browser now blocks most YouTube video ads, bolstering user privacy against tracking and unwanted commercial interruptions.
Opera GX Mod Auto-Installation Vulnerability Analysis
A critical flaw in Opera GX allowed malicious sites to auto-install mods and exfiltrate sensitive data. Learn how to detect and mitigate this browser threat.
Malicious Perplexity Chrome Extension Intercepts User Data
A malicious Chrome extension impersonating Perplexity AI intercepted user search queries and address bar inputs, routing them via attacker infrastructure, posing a…
Microsoft Pulls 119 Malicious StegoAd Edge Extensions
Microsoft removes 119 Edge extensions linked to the StegoAd campaign, which used steganography in images and fonts to steal credentials and commit ad fraud.
"Adblock for YouTube" Extension: Dormant Script Injection Threat
A popular Chrome ad blocker, "Adblock for YouTube," with over 10 million installs, contains a dormant capability for arbitrary JavaScript injection.
Chrome 149 Update Patches 18 High-Severity UAF Vulnerabilities
Google releases Chrome 149 to address 18 severe vulnerabilities, including multiple use-after-free defects in Graphics, Dawn, and Mojo components.
Malicious Chrome Wallpaper Extensions Distribute Adware
Analysis of 152 malicious Chrome wallpaper extensions distributing adware and generating fake traffic. Over 105K installs across 38 publisher accounts.
Chrome 149 Update Patches 28 Vulnerabilities — Mitigation Guide
Google addresses 28 security flaws in Chrome 149, including critical use-after-free bugs. Learn about technical impacts and enterprise patching requirements.
Google Patches CVE-2026-11645: 5th Chrome Zero-Day Exploited in 2026
Google addresses CVE-2026-11645, a critical zero-day vulnerability in Chrome being actively exploited. Learn about patch guidance and detection strategies.
2026 Verizon DBIR Analysis: Securing the Browser Against Phishing
The 2026 Verizon DBIR identifies browser-layer security gaps as a primary threat vector, highlighting risks from phishing, shadow AI, and malicious extensions.
Brave Origin: Reducing Browser Attack Surface via Paid Minimalism
Brave Software launches Brave Origin, a subscription-based minimalist browser that removes AI, crypto, and VPN features to prioritize privacy and performance.
Chromium RCE Risk: Unfixed Flaw Allows Background JavaScript
Google accidentally exposed details of an unfixed Chromium flaw. This enables RCE via persistent background JavaScript execution, affecting many browsers.
Microsoft Edge: Hardening Against Cleartext Password Exposure
Microsoft Edge will no longer load cleartext passwords into memory at startup, mitigating a significant local credential access risk for users.
Bypassing Enterprise DLP via Browser-Based Data Exfiltration
Examine how modern SaaS workflows and generative AI prompts bypass traditional DLP, creating significant visibility gaps in enterprise security posture.
Microsoft Edge Cleartext Password Exposure Risks — Mitigation Guide
Critical analysis of Microsoft Edge credential storage risks. Learn how to prevent cleartext password extraction and secure browser-based identities.
Firefox 150 Patch: 271 Zero-Days Found via Claude Mythos — Update Now
Firefox 150 addresses 271 vulnerabilities discovered by Anthropic’s Claude Mythos AI model, highlighting a shift in automated vulnerability discovery.