21 Sep, 2026

BragJack attacks hijack AI browser agents through malicious extensions

Security researcher Gal Weizman of Forever Security has disclosed a new attack technique that can hijack the AI assistants built into popular browsers using a single malicious browser extension. Dubbed BragJack, the proof-of-concept was demonstrated against five Chromium-based browsers or browser assistants: Google Chrome’s Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic’s Claude […]

5 mins read

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. The figures came from a joint advisory by Japanese, US, Australian, and German authorities that collectively traced the […]

3 mins read

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload […]

5 mins read

Viral AI actress’ hotline face-scans every caller, watches their mood

Last night, in a clip viewed more than eight million times, AI actress Tilly Norwood glitched mid-interview and unexpectedly began speaking Chinese on the Piers Morgan Uncensored show. Norwood has been the subject of much controversy and mainstream commentary for starring in an upcoming AI-generated film, Misaligned. Her creators run a “Talking Tilly” service that lets anyone video-call […]

5 mins read

Gyazo server flaw exploited to steal 23.6 million user records

The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. Gyazo is a cloud-based screenshot and screen-recording tool operated by Helpfeel that automatically uploads user screen captures to the cloud and gives them a shareable link to share on chats, […]

3 mins read

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. LastPass and Delphos Labs uncovered the campaign, which they report impersonates the password manager brand and at least 39 other companies. Alongside the Rapuncel infostealer, the repositories deliver a Microsoft-signed kernel driver that […]

3 mins read

Microsoft Teams will let admins block custom file extensions

Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with malware and security threats to meet their company’s security requirements. This will come as an update to Weaponizable File Protection, a built-in Teams messaging safety feature that scans conversations and blocks chat or channel messages with dangerous, high-risk file attachments. As detailed in […]

2 mins read

Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts

Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. In a Windows release health dashboard update on Thursday, Microsoft said the issue was fixed in the Microsoft Defender Antivirus update (version 4.18.26080.4) released on September 17. The company acknowledged the bug in late […]

2 mins read

New Check Point flaw lets hackers execute code with root privileges

Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. Tracked as CVE-2026-91843, this flaw stems from a stack-based buffer overflow weakness in the login process for Security Management Server instances, which manage Security Gateways (firewalls) and monitor network security events. […]

2 mins read

Microsoft fixes broken copy and paste for Excel 2016 users

Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. This follows a wave of customer reports on the Microsoft Q&A forums and Reddit that KB5002914 breaks copy-and-paste, autofill, and formula dragging in Excel. “Although users try to paste content, the source remains […]

3 mins read