:

737 FAKE VPN EXTENSIONS HIJACK CHROME TRAFFIC

INDUSTRY DESK1 MIN READ
WED, AUG 12, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Over 737 malicious browser extensions impersonating legitimate VPN and proxy services have been discovered on the Chrome Web Store, routing user traffic through a single operator's SOCKS5 proxies.

The fraudulent extensions mimicked well-known VPN providers, deceiving users into installing them. Once installed, the extensions redirected all user traffic through proxies controlled by a single third party, creating a significant privacy and security risk. Users believed they were downloading trusted services but instead granted access to their browsing activity to an unknown operator. The extensions remained available on the Chrome Web Store for an extended period before discovery. This incident highlights ongoing vulnerabilities in app store review processes. Extensions continue to slip through security checks despite platform safeguards. Users relying on these fake tools had their traffic monitored and potentially logged by the proxy operator. Google has removed the extensions following the discovery. Security researchers recommend users verify VPN and proxy extensions through official websites and check reviewer counts and ratings before installation. This incident underscores the importance of downloading security tools only from official sources.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A compromised AI package exposed credentials from 2,500 users in a large-scale supply-chain attack. Attackers scraped and exfiltrated terabytes of sensitive data.

JUST NOWAI Desk

A new Android malware combo pairs NFC relay malware called WindRelay with the SpyNote remote administration tool to steal credit card data and conduct fraud in real time.

JUST NOWSecurity Desk

Unknown actors are conducting widespread vulnerability scans while impersonating AI assistants like ClaudeBot, according to reports circulating in security communities.

1H AGOAI Desk

A critical vulnerability in Adobe Commerce and Magento platforms is being actively exploited to compromise customer accounts. The flaw, tracked as CVE-2026-71362, poses immediate risk to e-commerce operations worldwide.

1H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.