Security researchers at Socket have uncovered a large impersonation and browser traffic redirection campaign in the Chrome Web Store.
According to a news post on the official website, the campaign uploaded 737 VPN extensions to the Chrome Web Store and managed to lure more than 75,000 users to installing them on their devices.
The extensions impersonated 66 legitimate privacy and VPN brands—such as NordVPN, Proton VPN, and Surfshark—to deceive users into downloading them.
Core Threat Behaviors
Traffic Interception: Once activated, the extensions route the victim’s entire browser session through a SOCKS5 proxy controlled by a single threat actor. This places the attacker in a position to read and monitor all browser traffic.
Subscription Fraud: The extensions funnel users toward a paid subscription tier that promises premium server locations (such as Japan, Canada, and Australia). However, Socket found that none of these premium servers actually exist.
Deceptive Tactics & Evasion
DNS-over-HTTPS Evasion: The extensions use Cloudflare and Google’s DNS-over-HTTPS to silently resolve proxy IPs, preventing the victim’s machine from emitting plaintext DNS queries that security software might flag.
Store Review Gaming: The developers submitted false justifications to Chrome Web Store reviewers and used post-approval code substitution to sneak in the malicious proxy behaviors.
Hidden Domains: An internal developer manual accidentally left inside one of the extensions revealed explicit instructions to staff to never hardcode the actual domains into the extension, ensuring they stay hidden from automated scanners.
The campaign specifically targets Russian-speaking users who are trying to bypass internet censorship to access blocked services like YouTube, Instagram, and ChatGPT. By impersonating trusted anti-censorship tools, the attackers successfully tricked thousands of users into handing over full visibility of their web browsing activity to a threat actor based in Russia.
Microsoft is once again using a tried strategy of its “getting customers to upgrade” playbook. This time it is removing features from the classic app Windows Media Player in order to make the modern Windows Media Player look better on first glance.
The change was observed in the latest experimental builds of the Windows operating system. According to the report by Windows detective Xeno on X, Windows Media Player Legacy lost the ability to display subtitles, captions and lyrics.
Windows Media Player Legacy has been nerfed slightly in build 29648. It is no longer possible to enable "Lyrics, captions, and subtitles". Attempting to do so will tell you to go use the modern Media Player. The menu has also been nerfed pic.twitter.com/OToXhpJBRK
Windows Media Player Legacy has been nerfed slightly in build 29648. It is no longer possible to enable “Lyrics, captions, and subtitles”. Attempting to do so will tell you to go use the modern Media Player. The menu has also been nerfed
There are better media players out there in most cases, including the free VLC Media Player. It is unclear whether Microsoft will go ahead with the feature deprecation in the legacy Windows Media Player, but it is certainly not too far fetched that it will roll the change out in stable versions of Windows 11 in the future.
Microsoft pushing customers to migrate to certain products
Microsoft has a long history of employing aggressive tactics to move users from legacy applications to newer versions. Instead of simply letting the old app exist unsupported, they frequently implement forced redirects, server cutoffs, or feature stripping to make the “classic” app unusable.
Here are some examples:
Mail & Calendar / Classic Outlook > “New Outlook”
Microsoft is currently replacing the native Windows Mail & Calendar app and the classic Win32 Outlook desktop app with a web-wrapper called “New Outlook”.
How they degraded the classic experience: Microsoft added a persistent “Try the new Outlook” toggle to the classic apps. If a user clicks it, the classic app disappears. For users of the built-in Windows 10/11 Mail app, Microsoft eventually hard-coded the app to forcibly redirect to New Outlook upon launch. If users found workarounds to open the classic Mail app, Microsoft began disabling its ability to send and receive emails, rendering it entirely useless to force the transition
Classic Teams > New Teams
Microsoft rebuilt Teams from the ground up to improve performance, moving from an Electron framework to WebView2/React.
How they degraded the classic experience: Instead of letting the older version slowly phase out, Microsoft announced an “End of Availability” date. After July 2024 (and mid-2025 for certain enterprise environments), the classic Teams app completely stopped connecting to servers. If a user tried to launch it, they were met with a hard-blocking screen stating the app was no longer available, forcing an immediate download of the new version or a redirect to the web browser.
Skype Classic (v7) > Skype 8
When Microsoft redesigned Skype from a native peer-to-peer desktop app into a cloud-based application, the new version was widely criticized for missing features, a confusing mobile-first UI, and heavy resource usage.
How they degraded the classic experience: Because users refused to upgrade, Microsoft simply pulled the plug on the backend servers for Skype v7. Even if you had the classic program installed and it worked perfectly the day before, it abruptly refused to log in, displaying a mandatory upgrade prompt.
Internet Explorer 11 > Microsoft Edge
Microsoft wanted to kill off Internet Explorer in favor of their Chromium-based Edge browser.
How they degraded the classic experience: Before they officially removed IE11 from Windows, Microsoft installed a Browser Helper Object (BHO). If a user tried to navigate to a “modern” website (like YouTube, Twitter, or Instagram) using IE11, the browser would intentionally refuse to load the page. Instead, it would forcibly close the tab and automatically launch Microsoft Edge to open the URL. Eventually, Microsoft pushed a Windows Update that made clicking the iexplore.exe shortcut simply launch Edge.
Other examples:
Classic Control Panel migration to Settings app (ongoing since 2015). Removing legacy apples, redirecting to Settings, sometimes with inferior options.
Windows Live Messenger (MSN) to Skype. Microsoft shut down the Messenger protocol servers to force the migration. Messenger displayed a notification that a new version was available, which lead to the downloading of Skype and the removal of the classic app.
When Microsoft released Windows 11, it became clear quickly that the company’s attempt to fix the often convoluted Explorer context menu backfired. Microsoft’s answer was to introduce a two-tier context menu. The new one, displayed when users right-clicked and the second one, which users could access by holding down Shift or selecting the option to display it after the initial right-click.
The first contained common actions, like copying or format, the second all the entries from third-party apps that had not switched to the new system yet.
Microsoft revealed plans to launch another redesign of the context menu days ago on the official Windows blog. There, the company admitted that the current solution had performance and reliability issues.
The redesign addresses these and gives users more control over what they see and what they don’t require.
For that purpose, Microsoft is introducing new customization options in the Settings app for the context menu. You can enable or disable some of the options displayed there, including which apps are allowed to display entries on the main level and not in a submenu.
The shared screenshot shows the options that are in testing right now. You can display or hide
Send to
Print
Create shortcut
Copy as path
Rotate image
The apps that appear directly.
Additional options let users disable the icon-powered actions at the top (cut, copy, paste, rename, share, delete) in favor of inline options, keep cloud options separate, display properties at the bottom of the menu or display the legacy context menu right away.
Some actions can’t be configured at the time, including setting an image as the wallpaper, adding a file to the favorites, or AI actions.
It remains to be seen whether this new attempt at improving the File Explorer context menu is a successful one, or whether it is going to fail as badly as the initial redesign when Windows 11 launched.
Microsoft confirmed that the latest update for its Windows 11 operating system may cause “certain games to become unresponsive”. The update released on August 11, 2026 — KB KB5121003 — for Windows 11 version 25H2 and 24H2 may cause several issues when playing games, writes Microsoft in the bug report.
According to the description, players may experience the following issues among others:
the game application becomes unresponsive
the game application closes without notice
the error “EXCEPTION_ACCESS_VIOLATION” is displayed
the device restarting without warning
Affected games include ARC Raiders, Marvel Tokon: Fighting Souls and The Finals. Other gamers may be affected as well, but Microsoft says the issue has been reported for a “limited number of games” only.
Microsoft has not published a workaround at the time, which leaves gamers with just two options:
Roll-back the update to pre-August 11th-levels.
Skip problematic games until the issue is fixed.
While the first option allows affected gamers to play the games once again without the reported problems, uninstalling the August update removes security patches and leaves the system open for potential attacks that exploit them.
The issue is currently under investigation. Microsoft says that it will update the bug listing once it has found a solution for the issue.
Back in May 2026, some users of Google’s Chrome web browser discovered a jump in used storage space on their devices. The culprit at the time was an AI model that the browser downloaded automatically to user devices for on-device artificial intelligence processing.
The main idea here is to allow some AI tasks to run locally only, meaning that no interaction with a Google server is needed to make use of the functionality. The whole download felt forced to some users, who had no say in the matter whatsoever.
Now, Google and also Microsoft have increased the local storage requirements for AI significantly. Instead of 4 gigabytes of free disk space, Google requires a whooping 20 gigabytes as the bare minimum.
Google says that the model is only downloaded if Chrome runs on a device with supported hardware capabilities, but fails to specify what that means.
The best way to check whether your device is eligible is to load chrome://settings/system in the browser’s address bar and check the “On-device AI” setting there.
If it is turned on, the device has the requirements apparently and there is a good chance that a gigabyte-sized AI model has been downloaded to the system.
The model is downloaded to this folder: %LOCALAPPDATA%\Google\Chrome\User Data\OptGuideOnDeviceModel
The AI file is not downloaded in all cases, even with the On-device AI feature enabled. I checked on a test system that had the toggle set to on but no such file on the local hard drive.
You can turn off the functionality, which has three consequences according to Google:
Any AI model downloaded automatically to the local system is removed.
Chrome won’t download AI models.
Features that rely on the functionality won’t work.
The main features that are not available when you turn off local AI are:
Help with writing or rephrasing text
Warn you about scams
Summarize web pages
Organize your tabs
While local AI processing is without a doubt beneficial to privacy, companies like Google should consider giving their customers a clear choice before they start downloading gigabyte-sized files to their devices.
Mozilla released a new version of its open source Firefox web browser a moment ago. Firefox 154.0 is the latest stable version. Also released are Firefox 153.1 ESR, Firefox 140.14 ESR (reaching end of support in September) and Firefox 115.39.0 ESR (for old operating systems).
The new stable version comes with several new features and improvements to existing features. The usual bug fixes and security updates are also included.
As far as new features are concerned, there are several important ones. First, the open source browser’s local network access protection includes WebSocket connections now. Means, when a remote website asks for permission to use WebSocket, Firefox will display a permission prompt first. The user needs to allow this explicitly so that the website can open a WebSocket.
There is also a change to how Firefox handles sites and cookies for some sites. The release gives users more control, as it is now possible to exempt sites from the browser’s cookie and site data cleaner without exempting it from tracking protection and other cookie restrictions at the same time.
The local translations feature got two new options. It supports translations in iframes now and Firefox’s full-page translations feature now runs on all page loads, which Mozilla says improves the experience for offering translations.
Second, the browser’s backup feature for profiles is now also available on macOS, meaning that all three desktop operating systems are covered. IT is a built-in feature to create a backup of a Firefox profile to make restores easier. Should not bother long-time Firefox users who back up the profiles manually using external means, but may help users who never bothered or knew about this option in the first place.
Lastly, there is a change to hard reloading a website using Shift and clicking on the refresh button. This will now also clear and update favicons, the little icons you see in front of the site address on the main Firefox toolbar.
Firefox users who watch videos in the browser benefit from seeking improvements. Mozilla claims that this is much faster now. I don’t use Firefox for that, but if you do, feel free to share your experience in the comments below.
You may also notice that Firefox View is no longer visible by default. Mozilla is hiding it by default for new profiles and for profiles where it has not been used in a while. It is still accessible via List all tabs > View all tabs, and can also be added back using the customize menu on the new tab page.
As far as security fixes are concerned, there are quite a few. The aggregate rating is high and Mozilla makes no mentions of exploits in the wild. Still, good idea to update asap.
Microsoft published a new release preview build for its Windows 11 operating system on August 14, 2026. The changes in these builds will find their way into the previews for the September 2026 update for the operating system. Most users will receive them on September 8 or later, as rollouts to stable systems begin on that date.
The big new feature, or should I say old feature, of the release brings back some of the taskbar customizations that Microsoft removed when it released Windows 11 about five years ago.
Windows 11 users who install the update on their device will regain the option to snap the taskbar to any screen edge. Up until now, Windows 11 limited this to the bottom position on the screen. Third-party workarounds and hacks offered options to bypass this restriction, but sometimes at the expense of stability.
The second taskbar related change introduces the option to make the entire taskbar slimmer to free up a few pixels for other content on the screen.
To manage these, do the following once the feature becomes available:
The update includes several other changes that are noteworthy:
Start menu: pick between a large and small Start menu under Settings > Personalization > Start > Start menu size.
Start menu Recommended: is renamed to Recent.
Hide the name and profile picture in Start under Settings > Personalization > Start > Hide your name and profile picture on Start.
Hide or show Pinned, Recent and All individually.
Windows Search offers better hints about the type of result, e.g., app, setting, files, or web results.
Option to disable Web and Microsoft Store suggestions in Windows Search under Settings > Privacy & security > Search.
Windows indexes the most used folders automatically, which you can stop under Settings > Privacy & security > Search > Automatically find additional relevant locations.
File Explorer Home should launch faster and is more responsive.
Update progress indicators are shown throughout Windows for a “more consistent and modern experience”.
Administrator Protection is introduced to “protect free-floating admin rights for administrators”.
Switching between virtual desktops is now “smoother and more responsive”.
Ah, notifications. The idea behind browser notifications is sound. It allows websites and services to notify you even if you don’t have them open at the time. However, notifications were turned into an abonimation quickly.
Seemingly every site wants you to turn on notifications for them, which is unpleasant enough. The main problem is spam and also malicious abuse of the system.
Whenever I check the browsers of my parents or other users who are not tech-savvy, I notice loads of notifications. It is easy enough to accept notifications, but not nearly as easy to turn them off again.
While you can disable all notifications, which I do on all of my systems, some may prefer to keep some notifications enabled.
Microsoft tests a new protective feature against abusive notifications in its Edge browser. The main idea behind the feature is to automatically unsubscribe Edge users if a notification was used to push scam, phishing, or malware pages.
When that happens, Edge will unsubscribe the user from receiving notifications to stop additional spam or malicious notifications from being received.
The feature is in beta currently and rolled out over time. It may take a while before it lands in stable Edge versions and even then, it may be on a slower rollout.
Microsoft says that users can check edge://settings/privacy/sitePermissions/allPermissions/notifications to see if sites have been blocked automatically by the security of the browser.
My suggestion? Turn them off entirely there right away and be done with them. You can still add some sites to the exceptions there, to allow them to send notifications while all other sites are blocked from even asking.
If you are a regular on Facebook or visit the site at times, you may have noticed the odd-ad slipping past your content blocker’s defenses. Even with the most powerful tools out there, uBlock Origin for Firefox comes to mind, it happens that you may see advertisement on Facebook.
This is not a one-time slip-off, but the result of a battle between a small team of developers and Meta’s billions. The cat and mouse game has come to an end according to a new post by the uBlock Origin team on Reddit.
According to the post, the content blocker won’t support Facebook going forward. The reason given is that Facebook is countering any bypasses the uBlock Origin team finds for blocking ads and trackers on the site.
For example, Facebook was changing ad labels and markers frequently on its site to cause content blockers to miss them entirely. While content blockers managed to find ways to block ads anew, Facebook then developed new bypasses to show ads once again on its site.
In the end, the team notes that it is too small and lacks the resources to go against a billion Dollar behemoth like Meta. While ads may be blocked for the time being, it sounds as if the next bypass won’t be countered by the team anymore.
This means that Facebook users with uBlock Origin installed will see ads on the site in the long run. It is probably fair to say that most other content blockers, regardless of whether they are native or installed as extensions, faces the same issue.
There is not much that you can do about it. Maybe other content blockers continue their fight against Meta and work most of the time, but that would mean some testing to see which do and which don’t. It is the first time, to my knowledge, that a major content blocker has lowered the flag.
While companies like Google and Microsoft have dropped support for classic MV2 extensions already or are about to end support, some developers announced plans to continue supporting some or even all classic extensions.
Of all the major browsers, it is only Firefox that continues to support MV2 extensions. Mozilla has just reiterated that this is the case stating “Firefox support for uBlock Origin is not going anywhere.” on X.
As far as Chromium-based browsers are concerned, Brave plans to continue support for some extensions only, including uBlock Origin. Opera Software also claims to continue supporting MV2 extensions.
There are a few lesser known browsers, Thorium and Supermium, which pledged to continue their support for all MV2 extensions.
The background story
Google announced plans to switch Chromium, the open source part of Google Chrome and most browsers, to a new rules system. Called Manifest V3, or MV3, it was designed to replace the classic extensions system.
Google would not be Google if it would not have tried to pull a stunt on the browsing community by removing capabilities and replacing them half-heartedly. The outcry was big enough for Google to make some concessions, but the result was still a new system that lacked some of the capabilities of the old.
One of the types of extensions hit hardest by the changes were content blockers; exactly the extensions that threatened Google’s main source of revenue.