260,000 Chrome Users Exposed by Fake AI Extensions Targeting Gmail

260,000 Chrome Users Exposed by Fake AI Extensions Targeting Gmail

We have seen our fair share of malicious Chrome extensions in the past 17 or so years since Google released the initial version of its browser. From fake VPN extensions and outright malicious extensions to sophisticated session replay malware. This time, more than 260,000 Chrome users unknowingly installed a browser extension labeled as a helpful AI assistant. According to researchers…

Read More
Windows 11 Notepad Bug Let Markdown Links Run Files Without Warning

Windows 11 Notepad Bug Let Markdown Links Run Files Without Warning

Microsoft has patched a high-severity security vulnerability in Windows 11 Notepad that allowed specially crafted Markdown links to launch local or remote programs – without triggering standard Windows security warnings. The flaw tracked as CVE-2026-20841 was fixed as part of the February 2026 Patch Tuesday updates, which we release monthly. While exploitation required a user to open…

Read More
Betterment’s financial app sends customers a $10,000 crypto scam message

Betterment’s financial app sends customers a $10,000 crypto scam message

Betterment, a financial app, sent a sketchy-looking notification on Friday asking users to send $10,000 to Bitcoin and Ethereum crypto wallets and promising to “triple your crypto,” according to a thread on Reddit. The Betterment account says in an X thread that this was an “unauthorized message” that was sent via a “third-party system.” Here’s…

Read More
China’s New Cybersecurity Law Demands Faster Incident Reporting From Companies

China’s New Cybersecurity Law Demands Faster Incident Reporting From Companies

China has enacted a major revision of its Cybersecurity Law, effective January 1, 2026. The amendments mark the most significant shift since the law’s original introduction in 2017 and materially change how companies must handle cyber incidents, regulatory reporting, and compliance exposure. The updated framework places speed and accountability at the center of enforcement. Incident…

Read More
Discord customer service data breached; Government-ID images, and user details stolen

Discord customer service data breached; Government-ID images, and user details stolen

Discord has revealed that one of its customer service providers has suffered a data breach. The attackers gained access to Government-ID images, and user details. Discord doesn’t actually mention when the breach took place, it only says it “recently discovered an incident”. The fact that Government ID images were stolen is important, the U.K.’s Online…

Read More