loader image
Fake ChatGPT Extensions Spied on 1M Chrome Users

Malicious actors have exploited fake ChatGPT extensions and counterfeit DeepSeek tools to spy on more than one million Google Chrome users, according to cybersecurity researchers. These extensions, disguised as legitimate AI-related tools, secretly collected user data once installed, compromising privacy under the guise of enhancing browser functionality. The deceptive add-ons appeared on the Chrome Web […]

NodeCordRAT Uses Discord to Steal Chrome Data

A malicious tool dubbed NodeCordRAT uses Discord as a command-and-control platform to exfiltrate sensitive browser data. According to cybersecurity researchers, the remote access trojan targets victims through compromised NPM packages, primarily aiming to extract information from Google Chrome, such as login credentials, browsing activity and authentication tokens. Distributed through seemingly legitimate JavaScript libraries, the malware […]

ChatGPT Health Prompts Privacy Alarm

OpenAI’s new health-focused feature has sparked a wave of concern among privacy advocates. The company encouraged users to link personal medical records and wellness app data through the latest ChatGPT health prompts, saying this would deliver more personalized support. In a recent blog post, OpenAI assured users that it added enhanced data privacy protections to […]

Logitech Gear Stops on Mac After Certificate Lapse

A growing number of Mac users report that their Logitech gear stops functioning properly due to an expired software certificate. Keyboards and mice suddenly lose compatibility, and users notice missing customizations and input interruptions. The issue affects devices connected via both USB receivers and Bluetooth. Logitech’s Options and Options+ software, which typically manages customization features, […]

CISA Flags HPE OneView Flaw as Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) flags a high-severity HPE OneView vulnerability as being actively exploited in the wild, raising concerns for organizations using the infrastructure management platform. The agency added the flaw to its Known Exploited Vulnerabilities catalog, a list that prioritizes weaknesses currently targeted by malicious actors. HPE OneView, used to […]

OpenAI Rolls Out GPT-5.2 Codex-Max

OpenAI rolls out GPT-5.2 “Codex-Max” to a select group of users as part of a testing phase, aiming to advance its capabilities in AI-assisted coding. The new model, described as potentially the company’s most robust coding tool to date, builds upon previous Codex versions while introducing performance enhancements that target software development tasks. The rollout […]

Chronomaly Zero-Day Lets Hackers Gain Root

A newly disclosed chronomaly zero-day lets hackers gain root access on Linux systems running certain vulnerable kernel versions, according to cybersecurity researcher farazsth98. The exploit leverages multiple security flaws that allow attackers to escalate privileges and take full control of a targeted system. Researchers linked the vulnerability to three tracked issues: CVE-2025-54322, CVE-2025-48543, and CVE-2025-38352. […]

Forcepoint Flaw Lets Attackers Escape Sandbox

A newly disclosed forcepoint flaw vulnerability in the Forcepoint One DLP Client allows attackers to escape a restricted Python environment and run arbitrary code. Identified as CVE-2025-14026, the high-severity bug undermines protections intended to sandbox user activity, raising concerns about broader data security risks. The flaw enables malicious actors to bypass constraints configured by the […]

Google-Featured Fake Extension Steals 900K Chats

A malicious campaign involving a Google-featured fake extension has compromised more than 900,000 Chrome users, according to researchers at OX Security. Two rogue browser add-ons, disguised as AI chat assistants, secretly collected conversations from ChatGPT and DeepSeek, as well as users’ full browsing histories. The fake extensions cloned the interface of AITOPIA, a legitimate AI […]

Veeam Patches Critical RCE Flaws

Veeam patches critical RCE flaws in its latest Backup & Replication software release, aiming to neutralize a group of high-severity vulnerabilities recently uncovered in the platform. The company issued emergency security updates to prevent potential exploitation of these weaknesses, urging all users to apply the fixes immediately. The vulnerabilities posed risks that could allow remote […]

D-Link Legacy Routers Hit by Critical RCE

A critical remote code execution flaw is actively hitting a number of D-Link legacy routers, exposing users to serious cyber threats. Attackers are exploiting a vulnerability identified as CVE-2026-0625, which carries a CVSS score of 9.3. The flaw stems from improper input sanitization on the routers’ ‘dnscfg.cgi’ endpoint, allowing unauthenticated remote actors to inject system-level […]

Booking Scam Deploys DCRat in European Hotels

A new phishing campaign targeting European hospitality businesses uses fraudulent reservation emails posing as Booking.com communications. This booking scam deploys DCRat through a multi-stage infection chain that starts with spoofed travel cancellations and leads to full system compromise, researchers at Securonix revealed. Dubbed PHALT#BLYX, the campaign tricks hotel staff with urgent emails showing fake charges […]