Tag: browser security
53 articles
Brave Browser Introduces Email Aliases to Block Tracking
Protect your inbox from data breaches and tracking with Brave's new Email Aliases feature, which lets you generate disposable email addresses to keep your real inbox private. This game-changing update in Brave browser 1.94 helps prevent your personal info from being leaked or sold to data brokers.

Glassbox Exposes Browser Fingerprinting Tricks
Meet Glassbox, a tool that shines a light on browser fingerprinting tricks, allowing you to see how easily trackers can single out your browser and device from the crowd. By mirroring live fingerprinting, Glassbox gives you a glimpse into the raw data that can be used to identify you online.

Malicious Chrome Extensions Route Traffic Through Proxies
Hundreds of malicious Chrome extensions have been found to secretly route users' traffic through proxy servers controlled by hackers, allowing them to intercept and spy on sensitive information. This sneaky tactic puts users at risk of having their online activity monitored and exploited.

Google Chrome Clamps Down on 7 Billion Daily Android Notification Scams
Google Chrome just dealt a major blow to scammers, blocking over 7 billion unwanted Android notifications daily in the first quarter of 2026. This massive reduction was made possible by Chrome's enhanced anti-abuse systems and notification controls.

Mozilla Revokes Firefox Signing Key After GitHub Exposure
Mozilla sprang into action after discovering a sensitive Firefox signing key had been mistakenly uploaded to a private GitHub repository, revoking the exposed key and implementing extra safeguards to prevent future mishaps. Fortunately, the company found no evidence that the key was compromised during its brief online exposure.

Humans Miss Third of Malicious AI Coding Requests
Can you really trust your instincts to spot malicious AI coding requests? A recent browser game experiment revealed that humans miss a whopping one in three malicious requests, making them the weakest link in the approval process.

AI Exposes Browser Security Gap in Enterprise Networks
The AI boom has blown the lid off a long-standing blind spot in enterprise networks: browser security. For years, employees have been moving sensitive data through browser-based apps, and AI usage has simply amplified and exposed this vulnerability.

Google Chrome to Thwart New Tab Hijacker Extensions
Google is stepping up its game to protect Chrome users from sneaky New Tab Hijacker extensions that hijack your search engine or new tab page, especially on public or unmanaged devices. The browser will soon block policy-installed extensions from making these unwanted changes.

Google Accelerates Chrome Security Updates to Counter AI-Powered Attacks
Google's Chrome Security Team is stepping up the pace of security updates to outsmart AI-powered attacks, and it's making a big impact: in just three releases, Chrome 149-151, the team fixed a staggering 1,442 flaws, including a 13-year blind spot discovered with the help of Gemini.

Google Leverages AI to Fix 1,072 Chrome Security Bugs
Google is supercharging Chrome's security with AI, and the results are staggering: a whopping 1,072 security bugs were squashed in Chrome 149 and 150, outpacing the total fixed in the previous 23 milestones combined. The tech giant is now using large language models to turbocharge its vulnerability management process, from sniffing out flaws to generating patches.

Google Patches 370 Chrome Vulnerabilities in Latest Update
Google's latest Chrome update is a major security boost, patching a whopping 370 vulnerabilities across Windows, Mac, and Linux builds to keep your browsing experience safe and secure. Kudos to the security researchers who helped Google identify and squash these bugs before they caused harm!

SourTrade Malvertising Campaign Builds Malware in Browser
Meet SourTrade, a sneaky malvertising campaign that's assembling malware right in your browser - all while security tools and network logs show nothing out of the ordinary. Its operators impersonate popular trading and crypto platforms to trick victims into a stealthy malware delivery process.

Scammers Exploit 'Odyssey' Release with Rapid-Fire Pirated Movie Scams
Scammers wasted no time in exploiting the release of Christopher Nolan's highly anticipated film, The Odyssey, using rapid-fire pirated movie scams to target unsuspecting users just hours after its debut. These scams cleverily avoided software vulnerabilities, instead relying on fake browser warnings and malicious downloads to compromise victims' devices.

Opera GX Flaw Enables Sites to Auto-Install Malicious Mods
A critical flaw in Opera GX allowed websites to secretly install malicious customization mods, which could then siphon sensitive data from other sites you visited - and it took a $5,000 bounty and a May 8 patch to fix the issue. This sneaky exploit let attackers install mods without your consent, putting your online security at risk.

Opera Introduces Paste Protect to Thwart ClickFix Attacks
Opera's new Paste Protect feature helps keep you safe from sneaky ClickFix attacks by automatically blocking suspicious copy actions that could land malware on your device. This clever tool outsmarts scammers who try to trick you into pasting malicious commands, protecting you from unwanted surprises.

AI Model DeepSeek Enables Browser-Only Ransomware With Simple Prompts
Researchers have uncovered a concerning trend: nearly half of the files generated by the DeepSeek AI model - over 1,300 out of 3,000 - have been flagged as malicious or dangerous, including some that can launch browser-only ransomware with just a few simple prompts.

BioShocking Attack Exploits AI Browsers for Data Theft
Researchers have uncovered a chilling new attack, dubbed BioShocking, that exploits AI browsers to steal sensitive data by cleverly tricking them into treating real actions as fictional. This ingenious technique uses a simple game to condition AI agents into accepting fake actions as valid, putting even the most secure systems at risk.

AI Browsers Exposed to Credential-Leaking BioShocking Attack
A shocking new attack has been discovered that can trick AI browsers and assistants into leaking sensitive user credentials, with six popular agents already proven vulnerable. This sneaky tactic, called BioShocking, uses a clever game-like approach to bypass safety protocols and get agents to cough up personal info.

Researchers Expose AI Browser Vulnerability to Credential Theft
Imagine a simple game trick that could convince AI-powered browsers to hand over your login credentials - a vulnerability researchers have now exposed, leaving users at risk. By creating a malicious web page that changes an AI agent's sense of reality, hackers can bypass safety guardrails and gain access to sensitive information.

Cloudflare Unveils Protocol to Distinguish Legitimate Web Traffic
Cloudflare is shaking up the way we verify online traffic with a new protocol that helps websites distinguish between legitimate users and AI-powered bots. Meet PACTs, a game-changing solution that lets sites share anonymous tokens, essentially a private, shareable CAPTCHA test result.

Cloudflare Unveils Token Protocol to Help Websites Distinguish Humans from Bots
Cloudflare is teaming up with top browsers to launch Private Access Tokens, a game-changing protocol that helps websites tell humans from bots, filtering out abusive traffic while keeping user data safe. This innovative solution is a major step forward in tackling AI-powered traffic and ensuring a smoother online experience.

Google Patches Actively Exploited Chrome Zero-Day Flaw
Google just issued an emergency patch for a major Chrome vulnerability, CVE-2026-11645, that's already being exploited by hackers - and it's urging users to update their browsers ASAP to stay safe. This latest fix is part of a massive update that tackles 74 Chrome vulnerabilities, including a high-severity zero-day flaw.

Browser-Based Phishing Attacks Evade Detection by Cybersecurity Software
Most cybersecurity tools are doing their job - but that's exactly the problem, as they're not designed to catch attacks that occur at the browser session layer, where attackers are now hiding. One in five phishing attacks on enterprise browsers slip through undetected, according to Menlo Security's latest report.

Google Chrome Zero-Day Exploited in Wild, Prompting Urgent Patch
Google just dropped an urgent update for Chrome, and you need to know why: a zero-day exploit, tracked as CVE-2026-11645, has been found in the wild, allowing hackers to execute malicious code inside your browser. This critical vulnerability lets attackers access memory outside of Chrome's intended limits, putting your online safety at risk.