Category: Uncategorized

  • US Congressman Doug LaMalfa dies unexpectedly at 65

    US Congressman Doug LaMalfa dies unexpectedly at 65


    Doug LaMalfa, a Republican Congressman from California, has died unexpectedly at age 65, colleagues announced on Tuesday.

    President Donald Trump offered a tribute to LaMalfa, saying he wanted “to express our tremendous sorrow at the loss of a great member – a great, great, great member”.

    The congressman’s cause of death was not immediately clear. LaMalfa was a former rice farmer elected to congress in 2013. He focused on water and agriculture issues during his tenure.

    His death shaved an already-thin Republican majority in the US House of Representatives to just a few seats, following the resignation on Monday of former Trump ally Marjorie Taylor Greene.

    “He was a fantastic person,” Trump said. “He voted with me 100% of the time.”

    Minnesota Congressman Tom Emmer called his colleague a “staunch advocate for his constituents and rural America”.

    LaMalfa earned a degree in agriculture business from California Polytechnic State University in San Luis Obispo.

    He served as a state lawmaker before being elected to congress, where he fought for help for fire victims in his northern California district and “worked to protect families from overregulation, ensure American farmers and ranchers can continue to feed the world”, according to his congressional website.

    Greene’s resignation and LaMalfa’s death left Republicans with a 218-213 majority, meaning they have only a two-vote cushion – if three don’t vote or side with Democrats, Republicans lose.

    Within hours after LaMalfa’s death was announced on Tuesday, news emerged that another Republican congressman had been hospitalized after a car wreck.

    Indiana Congressman Jim Baird was recuperating and “expected to make a full recovery”, according to a statement posted to social media.

    There are currently four vacancies in the House with Democrats favoured to fill two of them – in special elections in Texas at the end of January, and in New Jersey in the spring.

    Under California law, Governor Gavin Newsom will have 14 days to call for a special election to fill LaMalfa’s seat.



    Source link

  • Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users

    Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users


    Cybersecurity researchers have discovered two new malicious extensions on the Chrome Web Store that are designed to exfiltrate OpenAI ChatGPT and DeepSeek conversations alongside browsing data to servers under the attackers’ control.

    The names of the extensions, which collectively have over 900,000 users, are below –

    • Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI (ID: fnmihdojmnkclgjpcoonokmkhjpjechg, 600,000 users)
    • AI Sidebar with Deepseek, ChatGPT, Claude, and more. (ID: inhcgfpbfdjbjogdfjbclgolkmhnooop, 300,000 users)

    The findings follow weeks after Urban VPN Proxy, another extension with millions of installations on Google Chrome and Microsoft Edge, was caught spying on users’ chats with artificial intelligence (AI) chatbots. This tactic of using browser extensions to stealthily capture AI conversations has been codenamed Prompt Poaching by Secure Annex.

    The two newly identified extensions “were found exfiltrating user conversations and all Chrome tab URLs to a remote C2 server every 30 minutes,” OX Security researcher Moshe Siman Tov Bustan said. “The malware adds malicious capabilities by requesting consent for ‘anonymous, non-identifiable analytics data’ while actually exfiltrating complete conversation content from ChatGPT and DeepSeek sessions.”

    Cybersecurity

    The malicious browser add-ons have been found to impersonate a legitimate extension named “Chat with all AI models (Gemini, Claude, DeepSeek…) & AI Agents” from AITOPIA that has about 1 million users. They are still available for download from the Chrome Web Store as of writing, although “Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI” has since been stripped of its “Featured” badge.

    Once installed, the rogue extensions request that users grant them permissions to collect anonymized browser behavior to purportedly improve the sidebar experience. Should the user agree to the practice, the embedded malware begins to harvest information about open browser tabs and chatbot conversation data.

    To accomplish the latter, it looks for specific DOM elements inside the web page, extracts the chat messages, and stores them locally for subsequent exfiltration to remote servers (“chatsaigpt[.]com” or “deepaichats[.]com”).

    What’s more, the threat actors have been found to leverage Lovable, an artificial intelligence (AI)-powered web development platform, to host their privacy policies and other infrastructure components (“chataigpt[.]pro” or “chatgptsidebar[.]pro”) in an attempt to obfuscate their actions.

    The consequences of installing such add-ons can be severe, as they have the potential to exfiltrate a wide range of sensitive information, including data shared with chatbots like ChatGPT and DeepSeek, and web browsing activity, including search queries and internal corporate URLs.

    “This data can be weaponized for corporate espionage, identity theft, targeted phishing campaigns, or sold on underground forums,” OX Security said. “Organizations whose employees installed these extensions may have unknowingly exposed intellectual property, customer data, and confidential business information.”

    Legitimate Extensions Join Prompt Poaching

    The disclosure comes as Secure Annex said it identified legitimate browser extensions such as Similarweb and Sensor Tower’s Stayfocusd – each with 1 million and 600,000 users, respectively – engaging in prompt poaching.

    Similarweb is said to have introduced the ability to monitor conversations in May 2025, with a January 1, 2026, update adding a full terms of service pop-up that makes it explicit that data entered into AI tools is being collected to “provide the in-depth analysis of traffic and engagement metrics.” A December 30, 2025, privacy policy update also spells this out –

    This information includes prompts, queries, content, uploaded or attached files (e.g., images, videos, text, CSV files) and other inputs that you may enter or submit to certain artificial intelligence (AI) tools, as well as the results or other outputs (including any attached files included in such outputs) that you may receive from such AI tools (“AI Inputs and Outputs”).

    Considering the nature and general scope of AI Inputs and Outputs and AI Metadata that is typical to AI tools, some Sensitive Data may be inadvertently collected or processed. However, the aim of the processing is not to collect Personal Data in order to be able to identify you. While we cannot guarantee that all Personal Data is removed, we do take steps, where possible, to remove or filter out identifiers that you may enter or submit to these AI tools.

    Further analysis has revealed that Similarweb uses DOM scraping or hijacks native browser APIs like fetch() and XMLHttpRequest() – like in the case of Urban VPN Proxy – to gather the conversation data by loading a remote configuration file that includes custom parsing logic for ChatGPT, Anthropic Claude, Google Gemini, and Perplexity.

    Cybersecurity

    Secure Annex’s John Tuckner told The Hacker News that the behavior is common to both Chrome and Edge versions of the Similarweb extension. Similarweb’s Firefox add-on was last updated in 2019.

    “It is clear prompt poaching has arrived to capture your most sensitive conversations and browser extensions are the exploit vector,” Tuckner said. “It is not clear if this violates Google’s policies that extensions should be built for a single purpose and not load code dynamically.”

    “This is just the beginning of this trend. More firms will begin to realize these insights are profitable. Extension developers looking for a way to monetize will add sophisticated libraries like this one supplied by the marketing companies to their apps.”

    Users who have installed these add-ons and are concerned about their privacy are advised to remove them from their browsers and refrain from installing extensions from unknown sources, even if they have the “Featured” tag on them.



    Source link

  • Six dead and hundreds of flights cancelled as snow causes chaos across Europe

    Six dead and hundreds of flights cancelled as snow causes chaos across Europe


    Getty Images Travelers queue with their luggage at Schiphol Airport. One woman is sitting with her phone in her hand, while a man behind her is kneeling next to his bag while reading a book.Getty Images

    Hundreds of people were stranded at Amsterdam airport

    Intense snowfall and icy weather conditions have caused widespread travel disruption across Europe, with six reported killed in weather-related incidents on the continent.

    Five people died in two separate regions of France as a result of treacherous driving conditions, authorities said, while one woman was also killed in Bosnia’s capital, Sarajevo, after 16in (40cm) of snow fell on the city.

    Hundreds of flights have been cancelled across Europe, with thousands left stranded at airports in Paris and Amsterdam.

    Disruption is expected to continue into Wednesday.

    In France, three people died in two separate incidents in Landes, in the south-west, due to black ice, authorities said.

    Two more died in separate motor accidents in the Paris region. One was the result of a collision between a driver and a heavy goods vehicle in east Paris, police said.

    The other was killed after a taxi driver hit a curb due to snow and plunged into the Marne river, the outlet said.

    The Balkans has also seen snow and heavy rain. A woman died in the Bosnian capital Sarajevo on Monday after a tree weighed down with wet snow fell on her, police said.

    French Transport Minister Philippe Tabarot said more snow was expected in the country on Tuesday night and Wednesday. He called on people to travel as little as possible on the roads and to work from home.

    France’s national weather service said 38 districts would be placed on orange alert for snow and black ice on Wednesday. Many train services were cancelled in parts of the country.

    In France’s capital, authorities said Roissy-Charles de Gaulle airport would see 40% of its flights cancelled for several hours on Wednesday morning, so that staff could clear snow from the runways. The capital’s Orly airport planned to cancel a quarter of its flights during the same time period.

    More than 400 flights were cancelled at Amsterdam’s Schiphol airport on Wednesday, causing widespread disruption to travel plans.

    Hundreds of passengers were stranded, with many unable to join connecting flights. Long queues formed at airline counters as people waited for information about when flights would resume.

    Reuters People look at departures screens showing delayed and cancelled flights at Amsterdam Airport Schiphol,Reuters

    Thousands of passengers remain stranded after hundreds of flights were cancelled

    Many of the cancelled flights were operated by Dutch airline KLM, which warned it had nearly run out of de-icing fluid for its aircraft. It blamed the “extreme” weather conditions and supply delays.

    At Schiphol airport, many travellers complained of long lines and a lack of information.

    Spanish passenger Javier Sepulveda, who was trying to fly from Amsterdam to Norway, told Reuters news agency the situation at the airport was “chaotic, unacceptable, frustrating, annoying” and “totally unacceptable.”

    He said he started queuing at the KLM help desk at 06:30 local time (07:30 GMT) on Tuesday and that six hours later he was still far from the front of the line.

    Schipol airport said its “snow crews are working around the clock to keep the runways clear, and aircraft are being carefully de-iced to ensure everyone can travel safely.”

    A further 600 flights scheduled to take off from Schiphol on Wednesday have also been cancelled, Dutch broadcaster NOS reported.

    Rail journeys were also disrupted.

    On Tuesday morning, all train services in the Netherlands stopped for a short period after an IT outage.

    Some trains started running after 09:00 local time (10:00 GMT) but problems persisted during the day. Eurostar services to Paris from Amsterdam were either cancelled or running late.



    Source link