Chrome “WebView” Vulnerability Allows Hackers to Bypass Security Restrictions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released an urgent security update for the Chrome browser to address a high-severity vulnerability in the WebView tag component that could allow attackers to bypass critical security restrictions. Google rolled out Chrome version 143.0.7499.192/.193 for Windows and Mac, …

Malicious Chrome Extension Steal ChatGPT and DeepSeek Conversations from 900K Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two rogue Chrome extensions have compromised over 900,000 users by secretly exfiltrating ChatGPT and DeepSeek conversations, along with full browsing histories, to attacker servers. Discovered by OX Security researchers, the malware impersonates the legitimate AITOPIA AI sidebar tool, with one …

Sedgwick confirms Data Breach Following TridentLocker Ransomware Gang Claim

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sedgwick has confirmed a cybersecurity incident at its government-focused subsidiary after the TridentLocker ransomware gang claimed responsibility for stealing 3.4 gigabytes of data. The breach highlights ongoing risks to federal contractors handling sensitive U.S. agency data.​ Claims administration giant Sedgwick …

Judge Demands OpenAI to Release 20 Million Anonymized ChatGPT Chats in AI Copyright Dispute

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A federal judge in New York has ordered OpenAI to provide 20 million anonymized user logs from ChatGPT to the plaintiffs in a major copyright lawsuit involving AI. The judge made this decision despite OpenAI’s privacy concerns, upholding an earlier …

Critical AdonisJS Vulnerability Allow Remote Attacker to Write Files On Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical path traversal vulnerability in AdonisJS has been discovered that could allow remote attackers to write arbitrary files to server filesystems, potentially leading to complete system compromise. The vulnerability, tracked as CVE-2026-21440, affects the bodyparser module of the popular TypeScript-first …

Critical Dolby Codec Vulnerability Exposes Android Devices to Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has issued its January 2026 Android Security Bulletin, urging users to update to the 2026-01-05 patch level or later to mitigate a critical vulnerability in Dolby components. The standout issue, CVE-2025-54957, targets the Dolby Digital Plus (DD+) codec and …

NordVPN Denies Data Breach Following Threat Actor Claim on Dark Web

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NordVPN has firmly rejected claims of a data breach after a threat actor surfaced alleged stolen data on a dark web breach forum, purporting to expose the VPN provider’s Salesforce development server. The incident, first spotted on January 4, underscores …

New Tool to Remove Copilot, Recall and Other AI Tools From Windows 11

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s aggressive push to integrate artificial intelligence features into Windows 11 has prompted developers to create the RemoveWindowsAI project. An open-source tool designed to remove or disable unwanted AI components from the operating system. RemoveWindowsAI is a community-driven utility available …

Christmas Phishing Surge Chains Docusign Spoofing with Identity Theft Questionnaires

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The holiday season has brought with it a surge in sophisticated phishing attacks that combine two dangerous tactics: credential harvesting through spoofed Docusign notifications and identity theft through fake loan application forms. These coordinated campaigns exploit the seasonal chaos of …

CloudEyE MaaS Downloader and Cryptor Infects 100,000+ Users Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous malware campaign has emerged across Central and Eastern Europe, causing widespread concern among cybersecurity professionals and organizations. CloudEyE, a Malware-as-a-Service downloader and cryptor, has rapidly gained traction among threat actors seeking to distribute other harmful malware payloads. In …