China-linked threat actor DarkSpectre has moved to compromise 2.2 million Google Chrome, Mozilla Firefox, and Microsoft Edge users' online meeting-related information via 18 nefarious extensions as part of the new Zoom Stealer campaign, which follows its GhostPoster and ShadyPanda attacks, according to BleepingComputer.
Security Boulevard reports that more than 900,000 Google Chrome users have had their conversations with AI chatbots ChatGPT and DeepSeek stolen via malicious extensions impersonating an add-on by AITOPIA, which places a sidebar for chatting with large language models.
Associated Radiologists of the Finger Lakes, P.C., a New York-based radiology services provider, had the data of its current and former patients exposed following a cybersecurity incident in late October, according to WETM-TV.
StateScoop reports that New York Gov. Kathy Hochul has approved new state legislation that would prohibit state and municipal governments from buying certain technologies from companies mandated to provide intelligence to foreign adversaries in a bid to bolster its cybersecurity posture.
France's data protection authority, the CNIL, has imposed a €1.7 million GDPR fine on software company Nexpublica for severe cybersecurity failures that led to a significant data breach, according to The Cyber Express.
A small, globally dispersed team of digital security experts at Access Now's Digital Security Helpline serves as a critical frontline defense for journalists and human rights activists targeted by government spyware, according to TechCrunch.