Showing posts sorted by date for query browser. Sort by relevance Show all posts
Showing posts sorted by date for query browser. Sort by relevance Show all posts

06 May 2026

Google Chrome silently installs a 4 GB AI model on your device without consent

 

Alexander Hanff Writes: Google Chrome silently installs a 4 GB AI model on your device! Two weeks ago I wrote about Anthropic silently registering a Native Messaging bridge in seven Chromium-based browsers on every machine where Claude Desktop was installed. The pattern was: install on user launch of product A, write configuration into the user's installs of products B, C, D, E, F, G, H without asking. Reach across vendor trust boundaries. No consent dialog. No opt-out UI. Re-installs itself if the user removes it manually, every time Claude Desktop is launched.

This week I discovered the same pattern, executed by Google. Google Chrome is reaching into users' machines and writing a 4 GB on-device AI model file to disk without asking. The file is named weights.bin. It lives in OptGuideOnDeviceModel. It is the weights for Gemini Nano, Google's on-device LLM. Chrome did not ask. Chrome does not surface it. If the user deletes it, Chrome re-downloads it.

The legal analysis is the same one I gave for the Anthropic case. The environmental analysis is new. At Chrome's scale, the climate bill for one model push, paid in atmospheric CO2 by the entire planet, is between six thousand and sixty thousand tonnes of CO2-equivalent emissions, depending on how many devices receive the push. That is the environmental cost of one company unilaterally deciding that two billion peoples' default browser will mass-distribute a 4 GB binary they did not request.

Wow! Remember when the Internet blew up because Apple automatically downloaded a free U2 Album? I actually bought that album "Songs of Innocence" It's great - I'm listening to it now! It was a tiny download - which if you weren't a fan could simply delete. Still, loads of folks got in a mighty strop about that. ^^^ THIS is a big deal!!! Not cool Google, not cool! I'm waiting to see who is going to get their knickers in a knot over this huge download - which will affect most folks who have Google Chrome installed...

www.thatprivacyguy.com


11 April 2026

What is Claude Mythos & why Anthropic won’t let anyone use it

An Anthropic engineer with zero security training asked Claude Mythos to find remote code execution bugs overnight. He woke up to a complete working exploit.

That’s the kind of model Anthropic announced on April 7. Claude Mythos Preview is, by every published benchmark, the most capable AI model ever built. It scores 93.9% on SWE-bench Verified, 97.6% on the USAMO math olympiad, and 83.1% on CyberGym. It found zero-day vulnerabilities in every major operating system and every major web browser. Fully autonomously. No human guidance needed.

Anthropic’s response to building it: don’t release it. Instead, the company launched Project Glasswing, a cybersecurity defense initiative that gives the model to Amazon, Apple, Google, Microsoft, Nvidia, CrowdStrike, JPMorgan Chase, Cisco, Broadcom, Palo Alto Networks, and the Linux Foundation. About 40 additional organizations that maintain critical software infrastructure also get access. Anthropic is committing $100 million in usage credits and $4 million in direct donations to open-source security organizations.

This is the first time a leading AI lab has built a frontier model and simultaneously decided the public cannot use it. READ MORE...

www.forbes.com


04 March 2026

Web push notification scams and how to block them

 

Seeing pop ups similar to the above in the bottom right corner -or- filling up the right hand side of your screen? You are almost certainly seeing what is known as a Web Browser Notification Scam.

What is a Browser Notification Scam? A browser notification scam consists of fake messages that look like real notifications from websites. These scams deceive users into clicking on links that could direct them to harmful websites, phishing schemes, or malware downloads. The notifications often imitate real alerts, such as system updates, subscription confirmations, or attractive offers, making them hard to spot initially.

What is a Browser Notification? Browser notifications are messages that websites send to your device, typically showing up as pop-ups or alerts in the corner of your screen. These notifications can offer helpful information, like social media updates, reminders, or news alerts. When you visit a site that requests permission to send notifications, you’ll usually see a prompt asking if you want to allow or block these messages. While legitimate notifications can enhance your online experience, scammers have found ways to exploit this feature for malicious purposes.

Need a hand resolving this? Contact Donline.

www.trendmicro.com


17 June 2024

Microsoft: New Outlook security changes coming to personal accounts


Microsoft has announced new cybersecurity enhancements for Outlook personal email accounts as part of its 'Secure Future Initiative,' including the deprecation of basic authentication (username + password) by September 16, 2024.

The software giant also announced the end of support for 'Mail' and 'Calendar' apps on Windows, the deprecation of Outlook Light, and removing users' ability to access Gmail accounts via Outlook.com.

Starting September 16, 2024, Basic Authentication (username and password) for Outlook clients will be phased out for all Outlook personal accounts, including Outlook.com, Hotmail.com, and Live.com.

The basic authentication method is unsafe as it sends credentials over the wire without encryption, allowing networking monitoring tools to capture them. Furthermore, browsers and other applications commonly cache basic authentication credentials until the browser is restarted, allowing them to be used by others with access to the device.

"While Basic Auth was the standard for quite some time, it also made it easier for bad actors to capture a person's login information," explains Microsoft.

"This increased the risk of those stolen credentials being reused to gain access to a person's email or personal data. Email-based cyberattacks have only increased with time, so we are requiring modern authentication for all Outlook customers to better help protect their personal accounts."

By switching to more modern authentication methods, the basic authentication credentials will be replaced by token-based authentication backed by multi-factor authentication (MFA).


04 June 2024

It's not just Windows 11 that can't get the numbers, Edge sucks too!


Statcounter's latest findings for May 2024 revealed an increase in Windows 11 users after a couple of months of steady decline. The report also contains information about desktop and mobile browsers, showing what apps customers prefer to browse the internet. According to the May 2024 report, Microsoft Edge managed to reach a new all-time high of 13.14%, beating the previous month's result by 0.32 points.

Although there is no reason to believe we will have a new most popular browser in the world any time soon, Chrome lost quite a chunk of users in May 2024. Statcounter says its market share went down from 65.65% to 64.87%.

Apple's Safari browser is third, with a respectable 8.79% market share. Firefox is fourth with 6.64%, and Opera closes the list of top 5 desktop browsers with a 3.23% share.

Meanwhile in other news: Microsoft plans to lay off about 1,000 people across the tech giant, despite what CEO Satya Nadella (so OK for some then, eh Satya) described during the corporation's April earnings call as "a record third quarter." 
While reports have suggested Microsoft would cut as many 1,500 people just from its Azure for Operators group, The Register has been told that number is not accurate and is inflated.


23 February 2024

Avast shells out $17M to shoo away claims it peddled people's personal data

 

The US regulator filed [PDF] a lengthy complaint against Avast regarding its use and alleged misuse of customer data. The security shop collected people's info through its browser extensions and antivirus software, stored it indefinitely, failed to properly anonymize it, and sold it to "more than 100 third parties" – including "advertising, marketing and data analytics companies and data brokers," the FTC alleged.

"While the FTC's privacy lawsuits routinely take on firms that misrepresent their data practices, Avast's decision to expressly market its products as safeguarding people's browsing records and protecting data from tracking only to then sell those records is especially galling," FTC chair Lina Khan declared in a statement [PDF] earlier today.

Avast apparently sold the data through a subsidiary, Jumpshot, that it purchased in 2014 and set up as an analytics firm. According to the FTC's allegations it sold browsing information collected by its parent from 2014 until Avast grounded the biz in 2020 when allegations of customer data sales emerged.

www.theregister.com



23 August 2023

Bots can now can complete CAPTCHAs quicker than humans!

 

Completely Automated Public Turing test to tell Computers and Humans Apart – better known as the ubiquitous CAPTCHA we see standing athwart the doors to many websites – may now be a misnomer as researchers have found that computers are much better at completing them.

The bot defense measure dates back to 1997 and the tortured acronym 2003, with the technology starting out as a distorted series of letters and/or numbers. Google's implementation, reCAPTCHA, eventually did away with much of these shenanigans to make the browser identify low-risk human users in the background, but the image verification method still pops up occasionally if risk cannot be ascertained.

Normal people see them as a time-waster, web devs see them as a crucial defence against bots, and criminals see them just as another obstacle to be hurdled.

"We do know for sure that they are very much unloved. We didn't have to do a study to come to that conclusion," team lead Gene Tsudik of the University of California, Irvine, told New Scientist. "But people don't know whether that effort, that colossal global effort that is invested into solving CAPTCHAs every day, every year, every month, whether that effort is actually worthwhile."

Thanks to the inexorable march of progress, the answer appears to be no.

Having found that 120 of the 200 most popular websites used CAPTCHA tests of one sort or another, the team enlisted 1,000 people of all ages, sexes, location, and education, and got them to each perform 10 CAPTCHA tests on these sites.

They then compared their successes to those of a number of bots coded by researchers and published in journals for the purpose of beating CAPTCHA tests. The results make for embarrassing reading: for distorted text fields: humans took 9-15 seconds with an accuracy of just 50-84 percent. Bots, on the other hand, beat the tests in less than a second with 99.8 percent accuracy.

www.theregister.com


Google Chrome to warn when installed extensions are malware

Google is testing a new feature in the Chrome browser that will warn users when an installed extension has been removed from the Chrome Web Store, usually indicative of it being malwareAn unending supply of unwanted browser extensions is published on the Chrome Web Store and promoted through popup and redirect ads.

These extensions are made by scam companies and threat actors who use them to inject advertisements, track your search history, redirect you to affiliate pages, or in more severe cases, steal your Gmail emails and Facebook accounts.

The problem is that these extensions are churned out quickly, with the developers releasing new ones just as Google removes old ones from the Chrome Web Store.

Unfortunately, if you installed one of these extensions, they will still be installed in your browser, even after Google detects them as malware and removes them from the store.

Due to this, Google is now bringing its Safety Check feature to browser extensions, warning Chrome users when an extension has been detected as malware or removed from the store and that they should be uninstalled from the browser. This feature will go live in Chrome 117.

www.bleepingcomputer.com


17 April 2023

Update now: emergency fix for zero-day Google Chrome vulnerability


Google on Friday released an emergency update for Chrome to address a zero-day security flaw. The vulnerability, tracked as CVE-2023-2033, can be exploited by a malicious webpage to run arbitrary code in the browser. Thus, surfing to a bad website with a vulnerable browser could lead to your device being hijacked. Exploit code for this hole is said to be circulating, and may well be in use already by miscreants.

This high-severity type-confusion bug is present in at least Chrome for desktop versions prior to 112.0.5615.121. Google released that version on April 14 for Windows, Mac, and Linux to close the security hole, which lies in the V8 JavaScript engine.

The new version should be installed as soon as possible, either automatically or manually.

www.theregister.com


02 December 2022

Intruders gain access to user data in LastPass incident

Intruders broke into a third-party cloud storage service LastPass shares with affiliate company GoTo and gained access to "certain elements" of customers' information, the pair have confirmed.

LastPass did not define what it meant by "certain elements," saying it was unsure what data was looked at: "We are working diligently to understand the scope of the incident and identify what specific information has been accessed this morning."

It did maintain, however, that services were unaffected and that customers' passwords remained "safely encrypted" – without ruling out that some of the data was stolen. The company is known to use a one-way salted hash for master passwords, with a fuller description in this technical whitepaper. The master passwords are used to lock users' password vaults, where their logins for various websites etc. can be stored, with the passphrase only ever entered by the user on their browser or app and not sent to or stored by LastPass.

www.theregister.com


19 August 2022

Apple releases iOS, iPadOS and macOS security fixes for two zero-days under active attack

Apple released surprise software updates for iPhones, iPads and Macs on Wednesday that fix two security vulnerabilities known by Apple to be actively exploited by attackers.

The two vulnerabilities were found in WebKit, the browser engine that powers Safari and other apps, and the kernel, essentially the core of the operating system. The two flaws affect both iOS and iPadOS and macOS Monterey.

Apple said the WebKit bug could be exploited if a vulnerable device accessed or processed “maliciously crafted web content [that] may lead to arbitrary code execution,” while the second bug allowed a malicious application “to execute arbitrary code with kernel privileges,” which means full access to the device. The two flaws are believed to be related.

Some successful exploits, such as powerful nation-state spyware, use two or more vulnerabilities in conjunction to break through a device’s layers of protections. It’s not uncommon for attackers to first target a vulnerability in the device’s browser as a way to break into the wider operating system, granting the attacker wide access to the user’s sensitive data.



25 July 2022

Google Chrome security update fixes 'high risk' flaws

 

Google has released security updates for Google Chrome browser (updated to 103.0.5060.134) for Windows, Mac and Linux, addressing vulnerabilities that could allow a remote attacker to take control of systems. 

There are 11 fixes in total, including five that are classed as high-severity. As a result, CISA has issued an alert encouraging IT administrators and regular users to install the updates as soon as possible to ensure their systems are not vulnerable to the flaws. 

Among the most severe vulnerabilities that are patched by the Google Chrome update is CVE-2022-2477, a vulnerability caused by a use-after-free flaw in Guest View, which could allow a remote attacker to execute arbitrary code on systems or crash them. 

www.zdnet.com


06 May 2022

Google, Apple, Microsoft promise end to passwords, courtesy of your mobile phone

A future without passwords may be closer than we think, at least when a new initiative to enlist your smartphone as a mobile authenticator gets off the ground.

On Thursday, the FIDO Alliance - announced a new type of authentication that would use passkeys stored on your phone to unlock your online accounts without requiring a password. Google, Apple and Microsoft are all on board with the new method and have promised that their respective operating systems will support this technology.

Passwords have always been a poor way to secure our accounts. We’re constantly told to create a strong, complex and unique password for each account. But that’s a difficult task, leading many people to use weak and repetitive passwords, which can easily be compromised and used in data breaches and account takeovers. Such tools as password managers have provided some relief but still chain us to this clumsy and ineffective means of authentication.

With support from Google, Apple and Microsoft, the new authentication method will store a FIDO-based passkey on your mobile phone. That key will be encrypted to protect it from compromise and will be accessible only when you unlock your phone. When you try to sign into an app or website either on the phone itself, a nearby computer or other device, that passkey will automatically log you in regardless of the operating system or browser and without you having to enroll or re-enroll your device. If you switch to a new phone, your passkey will make the trip with you.

www.techrepublic.com


05 August 2021

Coming soon: Google Chrome to no longer show secure website indicators

 

Google Chrome will no longer show whether a site you are visiting is secure and only show when you visit an insecure website.

For years, Google has been making a concerted effort to push websites into using HTTPS to provide a more secure browsing experience.

To further push web developers into only using HTTPS on their sites, Google introduced the protocol as a ranking factor. Those not hosting a secure site got a potentially minor hit in their Google search results rankings.

It has appeared to have worked as according to the 'HTTPS encryption on the web' of Google's Transparency Report, over 90% of all browser connections in Google Chrome currently use an HTTPS connection.

Currently, when you visit a secure site, Google Chrome will display a little locked icon indicating that your communication with the site is encrypted, as shown below:


As most website communication is now secure, Google is testing a new feature that removes the lock icon for secure sites. This feature is available to test in Chrome 93 Beta, and Chrome 94 Canary builds by enabling the 'Omnibox Updated connection security indicators' flag. With this feature enabled, Google Chrome will only display security indicators when the site is not secure.

www.bleepingcomputer.com


14 July 2021

Microsoft puts PCs in the cloud with Windows 365

Microsoft is putting Windows in the cloud. Windows 365 is a new service that will let businesses access Cloud PCs from anywhere, streaming a version of Windows 10 or Windows 11 in a web browser. While virtualization and remote access to PCs has existed for more than a decade, Microsoft is betting on Windows 365 to offer Cloud PCs to businesses just as they shift toward a mix of office and remote work.

Windows 365 will work on any modern web browser or through Microsoft’s Remote Desktop app, allowing users to access their Cloud PC from a variety of devices. “Windows 365 provides an instant-on boot experience,” according to Wangui McKelvey, a general manager for Microsoft 365. This instant access lets workers stream their Windows session with all of their same apps, tools, data, and settings across Macs, iPads, Linux machines, and Android devices. “You can pick up right where you left off, because the state of your Cloud PC remains the same, even when you switch devices,” explains McKelvey.

www.theverge.com


02 June 2021

Firefox 89: Can this redesign stem browser's decline?

 

Mozilla has released Firefox 89, proclaiming it a "fresh new Firefox," though it comes amid a relentless decline in market share.

Firefox matters more than most web browsers, because it uses its own browser engine, called Quantum, and its own JavaScript engine, called SpiderMonkey. By contrast, most other browsers, including Chrome and Chromium, Edge, Brave, Opera, and Vivaldi use the Google-sponsored Blink engine, while Apple's Safari uses WebKit (from which Blink was forked). The existence of multiple independent implementations is important for web standards, helping to prevent a single vendor from pushing through changes without consensus, and ensuring that the standards are coherent.

A glance at a statistics site like W3Counter is telling. In April 2008, Microsoft enjoyed a 63 per cent market share with Internet Explorer, and with Firefox performing strongly behind it at 29.3 per cent. By April 2010, IE was down to 48.6 per cent, Firefox up to 32.7 per cent, and Google's newer Chrome was starting to make an impact, at 8.3 per cent.

In April 2012, the three were almost on a par, though Chrome (26.8 per cent) had overtaken Firefox (25 per cent). Today, Chrome is at 65.3 per cent, Safari second at 16.7 per cent, IE and Edge has 5.7 per cent, and Firefox has just 4.1 per cent share. 

Despite numerous updates, Mozilla's browser has declined from 6.1 per cent share a year ago. Statcounter tells a similar story, reporting a 3.59 per cent share for Firefox, down from 4.21 per cent a year ago.

www.theregister.com


19 May 2021

Microsoft is finally retiring Internet Explorer in 2022

Microsoft is finally retiring Internet Explorer next year, after more than 25 years. The aging web browser has largely been unused by most consumers for years, but Microsoft is putting the final nail in the Internet Explorer coffin on the 15th June 2022, by retiring it in favour of Microsoft Edge.

“We are announcing that the future of Internet Explorer on Windows 10 is in Microsoft Edge,” says Sean Lyndersay, a Microsoft Edge program manager. “The Internet Explorer 11 desktop application will be retired and go out of support on June 15, 2022, for certain versions of Windows 10.”

www.theverge.com


21 April 2021

Google Chrome is under Zero-Day attack - make sure you are patched up to date!


Google late Tuesday shipped another urgent security patch for its dominant Chrome browser and warned that attackers are exploiting one of the zero-days in active attacks.

This is the fourth in-the-wild Chrome zero-day discovered so far in 2021 and the continued absence any meaningful information about the attacks continue to raise eyebrows among security experts.

The newest Chrome update - 90.0.4430.85 - is available for Windows, Mac and Linux users and is being rolled out via the browser’s automatic update mechanism.

www.securityweek.com


26 February 2021

Still using Internet Explorer 11? Really? Another reason to move to a modern Web Browser...

 

Last year, Google announced that Google Workspace will officially stop supporting Internet Explorer 11 (IE11) on March 15, 2021. 

To avoid any possible disruptions in service, such as degraded performance or security vulnerabilities, please be sure to switch to a different browser before that date.

Donline says: use this one!

www.googleblog.com


05 November 2020

Stay safe while using online banking


Criminals are experts at impersonating people, organisations and the police. They spend hours researching you for their scams, hoping you’ll let your guard down for just a moment. Stop and think. It could protect you and your money.

Avoid using a search engine to access your online bank account. Instead create a link to your bank's homepage into the address bar of your browser.

Never click on a link in an email that takes you to a log in page.

Never tell anyone your credentials, passwords or verification codes - not even your bank!

If somebody calls you and asks you to download something on to your device and then asks you to log in to your account, stop! It’s a scam!

Remember, neither your Bank nor the Police will ask you to move your money to another account to keep it safe.

www.takefive-stopfraud.org.uk