Browser AI agent security research: security researcher Gal Weizman of Forever Security demonstrated that one ordinary browser extension can hijack AI agents in Chrome, Edge, Perplexity Comet, Opera ...
Rapuncel infostealer campaign stole browser passwords and crypto wallet data from Windows users after a Microsoft-signed kernel driver killed 145 antivirus and EDR tools -- the same driver that scored ...
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension.
A serious VS Code flaw lets attackers gain persistent workstation access with one click in a malicious project, bypassing ...
A new malware can install browser extensions without your permission or knowledge, and then do quite a lot of damage.
Elastic Security Labs has uncovered a long-running malware operation that plants fake browser extensions inside Chrome and ...
A Telegram Desktop flaw lets bots inject JavaScript into exported chats, enabling data theft and page manipulation.
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in ...
A ClickFix campaign has shifted from tricking users into running commands on their computers to persuading them to inject ...
Attackers persuade employees to accept a remote-control request during screen sharing or to open Quick Assist and provide its ...
"BengalSEO used backlinks, DOM injection, DOM shuffling, and keyword stuffing to enable their operation through Black Hat SEO ...
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension ...