Security news

Latest security news

23 of 1,256 storiesChromeClear all

Today · Wed, 16 Sept 2026

  1. One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

    Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was installed, it could access each product's built-in AI with a single click. On Comet, Edge,

    The Hacker NewsMicrosoft, Chrome

Yesterday · Tue, 15 Sept 2026

  1. KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

    Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

    The Hacker NewsGoogle, Chrome
  2. China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

    A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The

    The Hacker NewsGoogle, Microsoft, Windows

Mon, 14 Sept 2026

  1. Twitch extension with 30K installs exposes users’ OAuth tokens

    A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service.

    BleepingComputerChrome, Firefox
  2. Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

    A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store - Chrome -

    The Hacker NewsGoogle, Chrome, Firefox

Sat, 12 Sept 2026

  1. BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

    Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments.

    SecurityWeekWindows, Chrome

Thu, 10 Sept 2026

  1. BlueMoon exploit kit turns Chrome and Windows flaws into attacks

    Four different espionage groups used the same exploit kit to target recently fixed flaws, showing why “patch later” is a dangerous gamble.

    Malwarebytes LabsWindows, Chrome
  2. New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

    Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.

    BleepingComputerGoogle, Microsoft, Windows
  3. Update Chrome now to protect against an actively exploited vulnerability

    Chrome issues another monster update, fixing an actively exploited V8 vulnerability and 229 other flaws.

    Malwarebytes LabsChrome

About this news

1,256
Stories
41
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets