BragJack attacks hijack AI browser agents through malicious extensions
Security researcher Gal Weizman of Forever Security has disclosed a new attack technique that can hijack the AI assistants built into popular browsers using a single malicious browser extension. Dubbed BragJack, the proof-of-concept was demonstrated against five Chromium-based browsers or browser assistants: Google Chrome’s Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic’s Claude […]
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. The figures came from a joint advisory by Japanese, US, Australian, and German authorities that collectively traced the […]
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload […]
Viral AI actress’ hotline face-scans every caller, watches their mood
Last night, in a clip viewed more than eight million times, AI actress Tilly Norwood glitched mid-interview and unexpectedly began speaking Chinese on the Piers Morgan Uncensored show. Norwood has been the subject of much controversy and mainstream commentary for starring in an upcoming AI-generated film, Misaligned. Her creators run a “Talking Tilly” service that lets anyone video-call […]
Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6Â million user records. Gyazo is a cloud-based screenshot and screen-recording tool operated by Helpfeel that automatically uploads user screen captures to the cloud and gives them a shareable link to share on chats, […]
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. LastPass and Delphos Labs uncovered the campaign, which they report impersonates the password manager brand and at least 39 other companies. Alongside the Rapuncel infostealer, the repositories deliver a Microsoft-signed kernel driver that […]
Microsoft Teams will let admins block custom file extensions
Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with malware and security threats to meet their company’s security requirements. This will come as an update to Weaponizable File Protection, a built-in Teams messaging safety feature that scans conversations and blocks chat or channel messages with dangerous, high-risk file attachments. As detailed in […]
Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. In a Windows release health dashboard update on Thursday, Microsoft said the issue was fixed in the Microsoft Defender Antivirus update (version 4.18.26080.4) released on September 17. The company acknowledged the bug in late […]
New Check Point flaw lets hackers execute code with root privileges
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. Tracked as CVE-2026-91843, this flaw stems from a stack-based buffer overflow weakness in the login process for Security Management Server instances, which manage Security Gateways (firewalls) and monitor network security events. […]
Microsoft fixes broken copy and paste for Excel 2016 users
Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. This follows a wave of customer reports on the Microsoft Q&A forums and Reddit that KB5002914 breaks copy-and-paste, autofill, and formula dragging in Excel. “Although users try to paste content, the source remains […]