Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was installed, it could access each product's built-in AI with a single click.
Three Ukrainians are set to stand trial for allegedly stealing access to more than 610,000 Roblox accounts and selling them to buyers in Russia, authorities said.
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery.
An attacker hijacked an AI coding assistant session to spread the Shai-Hulud worm, marking a new class of supply chain attacks targeting developer tooling and AI-assisted development pipelines. The attack compromised the AI assistant's session token to inject malicious code suggestions that propagated the worm across development environments.
In our previous blog , we analyzed four proofs of concept (PoCs) from the leak persona Nightmare-Eclipse that targeted Kaspersky, Avast, NVIDIA, and CrowdStrike, respectively.
A vulnerability in Parallels Desktop (CVE-2026-90894) allows non-admin Mac users to gain root access on the host system by exploiting the virtual machine monitor interface. The flaw bypasses macOS security boundaries between the virtualization layer and the host operating system.