Security News

Cybersecurity news aggregator

🌐
MEDIUM Attacks Web Discovery

AI chatbot-spoofing Chrome extensions facilitate data theft

  • What: Malicious Chrome extensions disguised as AI chatbots are being used to steal sensitive data.
  • Impact: Over 260,000 users have downloaded the extensions, which exfiltrate emails, API keys, and other sensitive information.
Read Full Article →

AI/ML , Data Security AI chatbot-spoofing Chrome extensions facilitate data theft February 13, 2026 By SC Staff (Adobe Stock) Malicious actors have created 32 malicious Google Chrome extensions masquerading as ChatGPT, Google Gemini, and other AI chatbots to exfiltrate emails, API keys, and other sensitive information as part of the AiFrame campaign, The Register reports. Identical codebases and permissions have been observed across all the extensions, which have been downloaded at least 260,000 times, an analysis from LayerX Security showed. One of the extensions, AI Assistant, was discovered to have an iframe overlay enabling remote content loading and covert feature updates without requiring a Chrome Web Store update. Aside from transmitting extracted site metadata, text content, titles, and excerpts to the remote iframe, AI Assistant, which is still available on the Chrome Web Store, also enabled transcription. "The campaign exploits the conversational nature of AI interactions, which has conditioned users to share detailed information. By injecting iframes that mimic trusted AI interfaces, they've created a nearly invisible man-in-the-middle attack that intercepts everything from API keys to personal data before it ever reaches the legitimate service," said LayerX Security researcher Natalie Zargarov. Get essential knowledge and practical strategies to use AI to better your security program. Learn More SC Staff AI/ML Google Gemini weaponized in state-sponsored attacks SC Staff February 13, 2026 The Hacker News reports that multiple state-sponsored threat operations have been exploiting Google Gemini to facilitate accelerated cyber intrusions. Security Operations Check Point acquires 3 startups for $150 million to bolster cybersecurity SC Staff February 13, 2026 Check Point Software Technologies Ltd. has acquired three venture-backed startups, Cyclops Security, Cyata Security, and Rotate Inc., for approximately $150 million to enhance its cybersecurity capabilities. Government security Trust and data integrity: Cornerstones of AI for the public sector SC Staff February 13, 2026 As government agencies accelerate AI adoption, trust and data integrity have become mission-critical. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Related Terms Byte Cipher Ciphertext Data Encryption Standard (DES) Data Loss Prevention (DLP) Diffie-Hellman Digital Envelope Digital Signature Digital Signature Algorithm (DSA) Digital Signature Standard (DSS) You can skip this ad in 5 seconds

Share this article