Google has issued an emergency update to address a high-severity zero-day vulnerability, CVE-2025-13223, in its Chrome browser. This flaw, linked to the V8 JavaScript engine, allows attackers to execute arbitrary code…
Google has issued an emergency update to address a zero-day vulnerability in Chrome that is actively being exploited. This patch affects approximately 2 billion Chrome users, highlighting the ongoing challenges faced by…
In March 2026, cybersecurity researchers discovered CrystalX RAT, a new malware-as-a-service (MaaS) being promoted in private Telegram channels. This malware offers a wide range of capabilities, including remote access,…
A memory leak vulnerability named Squidbleed, tracked as CVE-2026-47729, has been discovered in the Squid web proxy software, affecting versions since 1997. This flaw allows attackers to read beyond memory buffer…
Bitdefender researchers have uncovered a malicious extension for the Windsurf IDE that deploys a multi-stage NodeJS stealer via the Solana blockchain. Disguised as a legitimate R language support tool for Visual Studio…
Security researchers at Rebora Security have identified critical vulnerabilities in popular Chrome extensions SiderAI and MaxAI, affecting millions of users. The vulnerabilities, named 'Spyder' and 'MaXSS', allow…
A malicious browser extension named 'Google Notes' targets cryptocurrency users by swapping wallet addresses during transactions. This clipper malware is delivered through unsigned installers on Chromium-based browsers,…
Bybit's Security Operations Center (SOC) reported a sophisticated malware campaign targeting macOS users searching for 'Claude Code,' an AI development tool from Anthropic. The campaign, first identified in March 2026,…
Alexander Hanff, a safety expert, revealed that the Claude Desktop application from Anthropic installs Native Messaging bridge files across multiple Chromium-based browsers without user consent. This unauthorized…
Check Point Research has identified a new form of ransomware generated by the AI model DeepSeek, which operates entirely within web browsers by exploiting the File System Access API. This attack method requires no…