❌

Normal view

30+ Chrome extensions disguised as AI chatbots steal users' API keys, emails, other sensitive data

12 February 2026 at 23:59

Are you a good bot or a bad bot?

More than 30 malicious Chrome extensions installed by at least 260,000 users purport to be helpful AI assistants, but they steal users' API keys, email messages, and other personal data. Even worse: many of these are still available on the Chrome Web Store as of this writing.…

Posting AI-generated caricatures on social media is risky, infosec killjoys warn

11 February 2026 at 19:56

The more you share online, the more you open yourself to social engineering

If you've seen the viral AI work pic trend where people are asking ChatGPT to "create a caricature of me and my job based on everything you know about me" and sharing it to social, you might think it's harmless. You'd be wrong.…

Critical React Native Metro dev server bug under attack as researchers scream into the void

3 February 2026 at 20:01

Too slow react-ion time

Baddies are exploiting a critical bug in React Native's Metro development server to deliver malware to both Windows and Linux machines, and yet the in-the-wild attacks still haven't received the "broad public acknowledgement" that they should, according to security researchers.…

Notepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoor

3 February 2026 at 00:23

The group targets telecoms, critical infrastructure - all the usual high-value orgs

Security researchers have attributed the Notepad++ update hijacking to a Chinese government-linked espionage crew called Lotus Blossom (aka Lotus Panda, Billbug), which abused weaknesses in the update infrastructure to gain a foothold in high-value targets by delivering a newly identified backdoor dubbed Chrysalis.…

StopICE hacked to send alarming text messages, admins accuse border patrol agent of sabotage

2 February 2026 at 20:16

The ICE-tracking service says it doesn't store usernames or addresses

ICE-reporting service StopICE has blamed a US Customs and Border Protection (CBP) agent for attacking its app and website and sending users text messages warning them that their information had been "sent to the authorities."…

Thousands more Oregon residents learn their health data was stolen in TriZetto breach

30 January 2026 at 19:32

Parent company Cognizant hit with multiple lawsuits

Thousands more Oregonians will soon receive data breach letters in the continued fallout from the TriZetto data breach, in which someone hacked the insurance verification provider and gained access to its healthcare provider customers across multiple US states.…

❌