Cybersecurity firm KOI has disclosed a serious privacy breach involving the Urban VPN Proxy browser extension, which has recorded nearly 8 million cumulative installations across major browsers. The investigation found that the extension abuses script-based manipulation of browser APIs to secretly extract sensitive user data, with a particular emphasis on conversations conducted on widely used AI platforms. When engaging with AI services such as ChatGPT, users frequently share confidential and personal information, including names, physical addresses, political opinions, religious beliefs, gender identity, and other private attributes. KOI’s analysis reveals that the affected extensions do not selectively monitor content. Instead, they systematically capture entire AI conversations, collecting both user-entered prompts and the complete AI-generated responses. Although Urban VPN advertises features designed to protect users—such as scanning AI responses for malicious links or phishing attempts—these safeguards appear misleading. In reality, the extensions harvest full chat transcripts and forward them to third-party data analytics and marketing entities, rather than restricting data use to security purposes. The collected information allows advertisers to construct detailed behavioral profiles, accurately infer user interests, and deliver highly targeted advertisements aimed at increasing engagement and conversions. This practice effectively erodes user privacy. The harvested data reportedly includes all AI conversation content, conversation IDs, timestamps, session metadata, and details about the AI platform and model in use. Notably, the surveillance mechanisms operate independently of the VPN tunnel, ad blocking, or AI protection features. Disabling these options does not prevent data collection. Security researchers warn that uninstalling the extensions entirely is the only effective mitigation. The impacted AI platforms include ChatGPT, Claude, Gemini, DeepSeek, Grok, Copilot, Meta AI, and Perplexity. The implicated extensions—Urban VPN Proxy, 1ClickVPN Proxy, and Urban Browser Guard—have begun to be removed from browser stores, with some automatically disabled through Chrome’s cloud-based security enforcement.
APT28 (also known as Fancy Bear), a Russia-linked advanced persistent threat group, has launched a targeted cyber espionage campaign leveraging a newly identified malware framework...
A large-scale data theft campaign has impacted more than a dozen companies following a breach at a SaaS integration provider, leading to the compromise of authentication tokens. Th...
hropic has introduced Claude Mythos Preview, an advanced general-purpose language model that demonstrates a striking ability to independently locate and exploit previously unknown ...