Claude AI Extension Flaw Enables Cross-Plugin Hijacking

A security flaw in the Claude AI Chrome extension could put users at risk, as it allows other browser extensions to issue commands to Claude without verification. This vulnerability creates a backdoor for hackers to hijack the AI model, warns LayerX senior researcher Aviad Gispan.

https://osintsights.com/claude-ai-extension-flaw-enables-cross-plugin-hijacking?utm_source=mastodon&utm_medium=social

#ClaudeAiExtensionFlaw #CrosspluginHijacking #BrowserSecurity #Vulnerability #Llm

Claude AI Extension Flaw Enables Cross-Plugin Hijacking

Discover the Claude AI Extension flaw that enables cross-plugin hijacking and learn how to protect yourself from this vulnerability now.

OSINTSights
πŸ“šπŸš€ Oh, how dare a webpage reveal that your browser's been gossiping all along! 🀭 Thanks, Rise Up Labs, for informing usβ€”without askingβ€”about the sky we missed while we were busy staring at this digital snoop-fest, Vol. IV. Bravo, Matt, for teaching us that our devices are blabbermouths, one millisecond at a time. πŸ˜‚πŸ‘
https://sinceyouarrived.world/taken #digitalprivacy #browsersecurity #techhumor #dataawareness #RiseUpLabs #HackerNews #ngated
taken.

A web page that tells you what your browser gave away the moment you arrived. No login, no form, no permission. Most pages do this. None of them tell you.

Since You Arrived

Microsoft Edge Exposes Saved Passwords in Plaintext

Microsoft Edge's password management has a concerning vulnerability: it loads all saved passwords into browser memory in plaintext at startup, making it easier for hackers to steal credentials on compromised systems. This is in stark contrast to other Chromium-based browsers like Google Chrome and Brave, which only decrypt…

https://osintsights.com/microsoft-edge-exposes-saved-passwords-in-plaintext?utm_source=mastodon&utm_medium=social

#BrowserSecurity #CredentialTheft #PlaintextPasswords #MicrosoftEdge #ChromiumbasedBrowsers

Microsoft Edge Exposes Saved Passwords in Plaintext

Learn how Microsoft Edge exposes saved passwords in plaintext and take action now to secure your browser and protect your credentials effectively today.

OSINTSights

Microsoft Edge Exposes Saved Passwords in Cleartext

Storing passwords in plain text poses a significant risk, especially in shared environments, as a security researcher recently discovered that Microsoft Edge saves decrypted credentials in its memory, making them vulnerable to exposure. This flaw allows saved passwords to be accessible even when they're not in use.

https://osintsights.com/microsoft-edge-exposes-saved-passwords-in-cleartext?utm_source=mastodon&utm_medium=social

#BrowserSecurity #MicrosoftEdge #PasswordExposure #CleartextStorage #EmergingThreats

Microsoft Edge Exposes Saved Passwords in Cleartext

Discover how Microsoft Edge exposes saved passwords in cleartext and learn what you can do to protect yourself, secure your browser now.

OSINTSights
Chrome’s Silent Gemini Nano Download Has a Consent Problem

Google can make a product argument for on-device AI in Chrome. The privacy, consent, and trust problems are still far more serious.

CybersecKyle

Google Chrome adds approximate location sharing on Android, giving users more control over privacy

https://fed.brid.gy/r/https://nerds.xyz/2026/05/chrome-approximate-location-sharing/

Firefox Exposed: AI Model Uncovers 271 Zero-Day Vulnerabilities

Meet the AI model that just supercharged Firefox security, uncovering a whopping 271 zero-day vulnerabilities that have now been squashed in the latest update to Firefox 150. This game-changing collaboration between Firefox and Anthropic's cutting-edge tools has made the browser safer than ever.

https://osintsights.com/firefox-exposed-ai-model-uncovers-271-zero-day-vulnerabilities?utm_source=mastodon&utm_medium=social

#ZeroDay #Firefox #AiModel #VulnerabilityManagement #BrowserSecurity

Firefox Exposed: AI Model Uncovers 271 Zero-Day Vulnerabilities

Discover how Firefox fixed 271 zero-day vulnerabilities with AI, learn more about their security efforts and upgrade to the latest version now for enhanced protection.

OSINTSights
Chrome 147 & Firefox 150.0.1 ship critical security updates: use-after-free & memory corruption bugs could allow code execution or info leaks. Patch to latest browser versions ASAP. πŸ›‘οΈ https://radar.offseq.com/threat/chrome-147-firefox-150-security-updates-rolling-ou-587da3ca #OffSeq #BrowserSecurity #Vulnerability

πŸ›‘οΈ Now Announcing: A New Cybersecurity Session at BSides Luxembourg

𝗖𝗒𝗠𝗣π—₯π—˜π—›π—˜π—‘π—¦π—œπ—©π—˜ 𝗙π—₯π—”π— π—˜π—ͺ𝗒π—₯π—ž 𝗙𝗒π—₯ π—”π—‘π—”π—Ÿπ—¬π—­π—œπ—‘π—š 𝗔𝗑𝗗 π——π—˜π—§π—˜π—–π—§π—œπ—‘π—š π— π—”π—Ÿπ—œπ—–π—œπ—’π—¨π—¦ 𝗕π—₯𝗒π—ͺπ—¦π—˜π—₯ π—˜π—«π—§π—˜π—‘π—¦π—œπ—’π—‘π—¦ – Van Nguyen

Take a closer look at one of the web’s most overlooked threats in this 30-minute lightning talk session feature within the Actionable CTI and Detection Engineering Village. This session dives into the growing risk of malicious browser extensions and how they silently impact millions of users through tracking, redirects, ad injection, data theft, and other unwanted actions.

Built on a curated dataset of 460 malicious extensions removed from the Chrome Web Store, this talk presents a practical detection framework combining static and dynamic analysis techniques, including CodeQL and Python-based workflows. A valuable session for analysts, threat hunters, and defenders looking to better understand browser-based threats.

Van Nguyen is a Security Analyst with a strong background in Software Engineering, Machine Learning, and IT Security, currently focusing on modern threat analysis and detection methodologies.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
πŸ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #ThreatIntelligence #DetectionEngineering #BrowserSecurity #CyberSecurity #Infosec

Mozilla Firefox uses AI to hunt bugs and suddenly zero days do not feel so untouchable

https://fed.brid.gy/r/https://nerds.xyz/2026/04/firefox-ai-bug-hunting/