Daily Recap, Google Chrome rolled out session cookie theft protection for all users and shipped Chrome 148 with patches addressing 151 vulnerabilities to strengthen browser defenses. The day also covered ongoing breach litigation and threats using AI tools, plus malware and exploit activity across BTMOB, FortiClient EMS, Gogs, and Kimsuky.
#GoogleChrome #Chrome148 #151Vulnerabilities #CookieGuard #23andMe #CharterCommunications #Carnival #GreyVibe #Ukraine #ChatGPT #Gemini #BTMOB #FortiClientEMS #Gogs #Kimsuky #HTTPSpy #HelloDoor #VSCodeTunnels #Zapier #FIFA #Polymarket
#GoogleChrome #Chrome148 #151Vulnerabilities #CookieGuard #23andMe #CharterCommunications #Carnival #GreyVibe #Ukraine #ChatGPT #Gemini #BTMOB #FortiClientEMS #Gogs #Kimsuky #HTTPSpy #HelloDoor #VSCodeTunnels #Zapier #FIFA #Polymarket
Chrome Security
- Google Chrome rolled out session cookie theft protection for all users and shipped Chrome 148 with patches for 151 vulnerabilities to harden browser security. – Chrome Cookie Guard, Chrome 148 Patch
Data Breaches
- California sued 23andMe over its handling of the 2023 breach, while Charter Communications disclosed a leak affecting 4.9 million accounts and Carnival said a breach exposed data on 6 million people. – 23andMe Lawsuit, Charter Breach, Carnival Breach
- A man was sentenced to prison for selling personal data on 7 million elderly Americans, underscoring ongoing abuse of stolen consumer records. – Data Seller
AI-Driven Threats
- GreyVibe, a Russia-linked group, is using AI tools including ChatGPT and Gemini to intensify attacks against Ukraine. – GreyVibe Attack, GreyVibe AI, GreyVibe AI Use
- Geordie raised $30 million to build an AI security and governance platform as interest grows in managing frontier-AI risk. – Geordie Funding
- A House panel is preparing a hearing on the cybersecurity impact of AI, signaling rising policy focus on emerging threats. – AI Hearing
Malware & Exploits
- BTMOB malware-as-a-service is generating custom phishing payloads for Android attacks, expanding mobile credential theft. – BTMOB Malware
- Attackers are exploiting a FortiClient EMS flaw to deliver infostealer malware, while a critical Gogs RCE bug and a new zero-day in Gogs can let authenticated or remote attackers execute arbitrary code. – FortiClient Exploit, Gogs RCE, Gogs Zero-Day
- Kimsuky expanded its toolkit with HTTPSpy, HelloDoor, and VS Code tunnels to improve persistence and stealth. – Kimsuky Tools
- Zapier patched a bug chain that researchers said could have enabled widespread account takeover. – Zapier Fix
Fraud & Abuse
- The FBI warned about fake FIFA websites being used in World Cup fraud schemes targeting unsuspecting users. – FIFA Fraud
- A Google security engineer was charged over alleged Polymarket insider trading tied to confidential search trends, with reports citing about $1.2M in gains. – Polymarket Charge, Google Insider
Security Operations
- Coverage also highlighted how SIEM can help MSPs reduce alert noise and respond to threats faster. – SIEM for MSPs