Summaries
Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.
Showing 1-3 of 3 results
| Date | Provider | Score | Summary |
|---|---|---|---|
| 12 Aug 2026, 10:09 PM | The Hacker News | 6.0 | 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
737 free Chrome VPN and proxy extensions across 40+ developer accounts were found routing users' entire browser sessions through a single SOCKS5 proxy on port 1082, giving the operator adversary-in-the-middle visibility into destinations, source IPs, TLS SNI values, and plaintext HTTP bodies. 274 of these impersonated 66 real VPN brands including NordVPN, Proton VPN, and ExpressVPN; 221 have been removed but 516 remain active on the Chrome Web Store with 75,486 total installs. Why: If you or your team uses a free Chrome VPN extension, check it against the list of 737 identified extensions — 516 are still live and can intercept all non-loopback browser traffic including API calls and credentials sent over plain HTTP. Builders who use browser-based VPNs for testing geo-restricted APIs or bypassing regional blocks should switch to system-level VPNs or verified provider apps instead of store extensions. |
| 12 Aug 2026, 9:00 PM | The Register | 4.5 | Akira ransomware scum blocked victim's security tools – and broke their own encryptor
An Akira ransomware affiliate breached a victim via a SonicWall SSL VPN account that lacked MFA, then rebooted the machine into Safe Mode to kill security tools—but Safe Mode also broke the encryptor due to memory constraints. Huntress analyst James Northey warns this was a lucky break, not a reliable defense, since attackers could retool the encryptor to work in Safe Mode. Data and credentials were already exfiltrated before the encryption failed. Why: If you run a SonicWall SSL VPN or any VPN endpoint without MFA, you are the exact target profile described here—credential-spray attacks succeeded in seven minutes against an unprotected account. Enforce MFA on all VPN accounts now, and assume that even if encryption fails, attackers will still steal Active Directory data and file-share credentials before they leave. |
| 12 Aug 2026, 2:15 PM | The Hacker News | 3.0 | Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Cisco has confirmed active exploitation of CVE-2026-20349 (CVSS 8.6), a high-severity denial-of-service vulnerability in Secure Firewall ASA and FTD Software. An unauthenticated remote attacker can send a crafted HTTP request to the Remote Access SSL VPN service on affected devices, causing them to reload. The flaw stems from insufficient error checking when processing HTTP requests and affects devices with IKEv2 Remote Access VPN, SSL-VPN, or Zero Trust Network Access enabled across ASA versions 9.16 through 9.24 and FTD versions 7.0 through 7.6. Why: If your organization runs Cisco ASA or FTD firewalls with SSL VPN, IKEv2 Remote Access VPN, or Zero Trust Network Access enabled, you should patch to the fixed versions listed in the advisory immediately—this is being actively exploited. If you don't manage Cisco firewall appliances directly, this has no actionable impact on your work. |