Attackers Abuse ChatGPT Share Links to Host Fake Outage Pages That Deliver Malware

Attackers Abuse ChatGPT Share Links to Host Fake Outage Pages That Deliver Malware

Threat actors are exploiting ChatGPT’s content-sharing feature to set up fake OpenAI outage pages. These pages instruct users to download malware disguised as the ChatGPT desktop app. The campaign, called “LLMShare” and uncovered by Push Security, uses Google ads to lead users to a malicious shared ChatGPT page hosted on the legitimate chatgpt.com domain. Since…

Read More
Researcher Claims Trump Mobile Website Leaked Data on More Than 27,000 Customers Through Unprotected API

Researcher Claims Trump Mobile Website Leaked Data on More Than 27,000 Customers Through Unprotected API

A self-taught tech enthusiast who goes by the name “Louis” claims he found a vulnerability in the Trump Mobile website that let him extract customer data using simple HTTP POST requests. He says the flaw exposed information for more than 27,000 customers who had placed orders. The issue appears to have been fixed, although Trump…

Read More
OpenAI just released its answer to Claude Mythos

OpenAI just released its answer to Claude Mythos

OpenAI is launching Daybreak, an AI initiative focused on detecting and patching vulnerabilities before attackers find them. Daybreak uses the Codex Security AI agent that launched in March to create a threat model based on an organization’s code and focus on possible attack paths, validate likely vulnerabilities, and then automate the detection of the higher…

Read More
Hackers Abuse Google Ads and Claude.ai Shared Chats to Distribute macOS Malware

Hackers Abuse Google Ads and Claude.ai Shared Chats to Distribute macOS Malware

Attackers are currently running a malvertising campaign that uses Google Ads and legitimate shared chats on Claude.ai to spread macOS infostealer malware. The campaign was identified by Berk Albayrak, a security engineer at Trendyol Group, with BleepingComputer independently confirming a second active version using different infrastructure. Users searching for “Claude mac download” might see sponsored…

Read More
Chrome for Android Adds Approximate Location Sharing Option for Websites

Chrome for Android Adds Approximate Location Sharing Option for Websites

Google is introducing a new approximate location sharing option in Chrome for Android, replacing the previous all-or-nothing location permission model. Users can now share a neighborhood-level location with websites instead of their exact coordinates. The update was announced on the Google blog and is currently being rolled out on mobile devices first. According to Google,…

Read More
Canvas is down as ShinyHunters threatens to leak schools’ data

Canvas is down as ShinyHunters threatens to leak schools’ data

The Instructure-owned learning management platform, Canvas, is down after recently confirming a massive data breach that impacted student names, email addresses, ID numbers, and messages. Students attempting to access the system on Thursday saw a message from the hacking group ShinyHunters, which claimed responsibility for the attack: ShinyHunters has breached Instructure (again). Instead of contacting…

Read More
Google Chrome Is Silently Downloading a 4GB Gemini Nano AI Model to User Devices Without Consent

Google Chrome Is Silently Downloading a 4GB Gemini Nano AI Model to User Devices Without Consent

Google Chrome has been quietly downloading around 4GB of Gemini Nano AI model weights to user devices without their consent, and it automatically re-downloads the files if they are deleted. This behavior has been confirmed on Windows 11, Apple Silicon, and Ubuntu systems, with user reports indicating it has been happening for about a year….

Read More
Zoom Integrates World ID Deep Face to Verify That Meeting Participants Are Human in Real Time

Zoom Integrates World ID Deep Face to Verify That Meeting Participants Are Human in Real Time

Zoom has announced a partnership with Tools for Humanity to bring World ID Deep Face into Zoom Meetings. The goal is to enable real-time verification that participants are human rather than AI-generated. The integration is mainly targeted at enterprises and regulated industries such as financial services, healthcare, and executive communications. During the process, no personal…

Read More