Visualização normal
-
Graham Cluley
-
Smashing Security podcast #484: How websites are tracking you with silence
When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking tricks on the web. Meanwhile, the intelligence agencies of the "Five Eyes" (not Five Guys) have got together and published advice on how companies should communicate after
-
Security | TechRepublic
-
Chrome to Block Policy-Abusing Extensions on Personal Devices
Google is developing Chrome protections that could block policy-installed extensions from hijacking New Tab pages and search settings on personal devices. The post Chrome to Block Policy-Abusing Extensions on Personal Devices appeared first on TechRepublic.
Chrome to Block Policy-Abusing Extensions on Personal Devices
Google is developing Chrome protections that could block policy-installed extensions from hijacking New Tab pages and search settings on personal devices.
The post Chrome to Block Policy-Abusing Extensions on Personal Devices appeared first on TechRepublic.
-
Security | TechRepublic
-
Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities
Google is testing twice-weekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browser’s patch gap. The post Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities appeared first on TechRepublic.
Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities
Google is testing twice-weekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browser’s patch gap.
The post Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities appeared first on TechRepublic.
-
Security | TechRepublic
-
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now. The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic.
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now.
The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic.
-
Arstechnica

-
Chrome may get faster updates with no restart required
With Chrome, Google pioneered the rapid release model for browser security. Now, Google says updates may need to change in the face of AI security analysis. According to the company, the number of bug fixes in Chrome releases has skyrocketed in recent months because AI is detecting so many flaws. We could be looking at more frequent updates soon, but Google is also working on ways to get those updates rolled out without bothering you as much. Google has released two major Chrome milestone builds
Chrome may get faster updates with no restart required
With Chrome, Google pioneered the rapid release model for browser security. Now, Google says updates may need to change in the face of AI security analysis. According to the company, the number of bug fixes in Chrome releases has skyrocketed in recent months because AI is detecting so many flaws. We could be looking at more frequent updates soon, but Google is also working on ways to get those updates rolled out without bothering you as much.
Google has released two major Chrome milestone builds recently—Chrome 149 in early June and Chrome 150 just a few weeks later. These two updates had a total of 1,072 bug fixes, which is more than the previous 23 releases combined. Such is the impact of giant cybersecurity AI models that can probe software for vulnerabilities at light speed. Some of these vulnerabilities were serious, too, with one bug hiding in the Chrome codebase for 13 years. If it had been exploited, an attacker could have bypassed the Chrome sandbox to make the browser access local files.
With the vastly higher rate of vulnerability identification, Google is worried bad actors will also be able to identify software flaws faster. Its goal is to ensure your Chrome install is always up to date or as close to it as possible. The first step toward that is the two-week update cycle the company announced earlier in 2026, but it's now piloting a system that would update Chrome twice per week. This would get patches out the door faster, ensuring that browsers are ready for the threat of AI-fueled attacks.


-
Security | TechRepublic
-
DuckDuckGo Now Blocks Most Video Ads on Windows, Mac, iPhone
DuckDuckGo’s web browser, often referred to as the DuckDuckGo Privacy Browser, can now block video ads, including in-video ads on YouTube. The post DuckDuckGo Now Blocks Most Video Ads on Windows, Mac, iPhone appeared first on TechRepublic.
DuckDuckGo Now Blocks Most Video Ads on Windows, Mac, iPhone
DuckDuckGo’s web browser, often referred to as the DuckDuckGo Privacy Browser, can now block video ads, including in-video ads on YouTube.
The post DuckDuckGo Now Blocks Most Video Ads on Windows, Mac, iPhone appeared first on TechRepublic.
-
Security | TechRepublic
-
New Chrome Update Fixes 382 Security Bugs Across Desktop, Mobile
Google released a Chrome update addressing 382 security bugs, including sandbox-escape risks. Users and IT teams should update quickly. The post New Chrome Update Fixes 382 Security Bugs Across Desktop, Mobile appeared first on TechRepublic.
New Chrome Update Fixes 382 Security Bugs Across Desktop, Mobile
Google released a Chrome update addressing 382 security bugs, including sandbox-escape risks. Users and IT teams should update quickly.
The post New Chrome Update Fixes 382 Security Bugs Across Desktop, Mobile appeared first on TechRepublic.
-
Security | TechRepublic
-
New BioShocking Attack Tricks AI Browsers Into Leaking Credentials
LayerX found that BioShocking could trick AI browsers into leaking credentials by disguising malicious prompts as game rules. The post New BioShocking Attack Tricks AI Browsers Into Leaking Credentials appeared first on TechRepublic.
New BioShocking Attack Tricks AI Browsers Into Leaking Credentials
LayerX found that BioShocking could trick AI browsers into leaking credentials by disguising malicious prompts as game rules.
The post New BioShocking Attack Tricks AI Browsers Into Leaking Credentials appeared first on TechRepublic.
-
Security | TechRepublic
-
Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features
Microsoft found a fake Perplexity AI Chrome extension that rerouted searches through attacker servers. Here’s what users should check now. The post Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features appeared first on TechRepublic.
Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features
Microsoft found a fake Perplexity AI Chrome extension that rerouted searches through attacker servers. Here’s what users should check now.
The post Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features appeared first on TechRepublic.
-
Security | TechRepublic
-
Update Chrome Now: Google Fixes 18 Security Flaws, Including Critical Bugs
Google’s Chrome 149 security update fixes 18 bugs, including four critical flaws affecting WebGL, Autofill, and Blink components. The post Update Chrome Now: Google Fixes 18 Security Flaws, Including Critical Bugs appeared first on TechRepublic.
Update Chrome Now: Google Fixes 18 Security Flaws, Including Critical Bugs
Google’s Chrome 149 security update fixes 18 bugs, including four critical flaws affecting WebGL, Autofill, and Blink components.
The post Update Chrome Now: Google Fixes 18 Security Flaws, Including Critical Bugs appeared first on TechRepublic.
-
Arstechnica

-
Browser extensions turn nearly 1 million browsers into website-scraping bots
Extensions installed on almost 1 million devices have been overriding key security protections to turn browsers into engines that scrape websites on behalf of a paid service, a researcher said. The 245 extensions, available for Chrome, Firefox, and Edge, have racked up nearly 909,000 downloads, John Tuckner of SecurityAnnex reported. The extensions serve a wide range of purposes, including managing bookmarks and clipboards, boosting speaker volumes, and generating random numbers. The common thre
Browser extensions turn nearly 1 million browsers into website-scraping bots
Extensions installed on almost 1 million devices have been overriding key security protections to turn browsers into engines that scrape websites on behalf of a paid service, a researcher said.
The 245 extensions, available for Chrome, Firefox, and Edge, have racked up nearly 909,000 downloads, John Tuckner of SecurityAnnex reported. The extensions serve a wide range of purposes, including managing bookmarks and clipboards, boosting speaker volumes, and generating random numbers. The common thread among all of them: They incorporate MellowTel-js, an open source JavaScript library that allows developers to monetize their extensions.
Intentional weakening of browsing protections
Tuckner and critics say the monetization works by using the browser extensions to scrape websites on behalf of paying customers, which include AI startups, according to MellowTel founder Arsian Ali. Tuckner reached this conclusion after uncovering close ties between MellowTel and Olostep, a company that bills itself as "the world's most reliable and cost-effective Web scraping API." Olostep says its service “avoids all bot detection and can parallelize up to 100K requests in minutes.” Paying customers submit the locations of browsers they want to access specific webpages. Olostep then uses its installed base of extension users to fulfill the request.


-
Arstechnica

-
Time to check if you ran any of these 33 malicious Chrome extensions
As many of us celebrated the year-end holidays, a small group of researchers worked overtime tracking a startling discovery: At least 33 browser extensions hosted in Google’s Chrome Web Store, some for as long as 18 months, were surreptitiously siphoning sensitive data from roughly 2.6 million devices. The compromises came to light with the discovery by data loss prevention service Cyberhaven that a Chrome extension used by 400,000 of its customers had been updated with code that stole their sen
Time to check if you ran any of these 33 malicious Chrome extensions
As many of us celebrated the year-end holidays, a small group of researchers worked overtime tracking a startling discovery: At least 33 browser extensions hosted in Google’s Chrome Web Store, some for as long as 18 months, were surreptitiously siphoning sensitive data from roughly 2.6 million devices.
The compromises came to light with the discovery by data loss prevention service Cyberhaven that a Chrome extension used by 400,000 of its customers had been updated with code that stole their sensitive data.
’Twas the night before Christmas
The malicious extension, available as version 24.10.4, was available for 31 hours, from December 25 at 1:32 AM UTC to Dec 26 at 2:50 AM UTC. Chrome browsers actively running Cyberhaven during that window would automatically download and install the malicious code. Cyberhaven responded by issuing version 24.10.5, and 24.10.6 a few days later.


© Getty Images