Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

Category: Security & Privacy

Microsoft confirms: Latest .NET updates may cause printing issues

Posted on August 25, 2026August 25, 2026 by Martin Brinkmann

Microsoft released security updates for .Net on August 11 to address six unique vulnerabilities. After installing the update on supported systems, users may notice printing issues.

Microsoft confirmed the issue in the release notes for the update. There, the company notes that “some WPF applications may fail with a System.IO.FileFormatException when printing or generating PDF/XPS content that uses certain fonts, including Calibri” after installing the update.

WPS refers to Windows Presentation Foundation, “UI framework that’s resolution-independent and uses a vector-based rendering engine, built to take advantage of modern graphics hardware.”

The issue is under investigation currently and there is no workaround for users at the time. App developers, who use WPF, may make use of a workaround to mitigate the issue.

Doing so will “disable security productions introduced in the August 2026 update”, which may increase the exposure to the addressed vulnerabilities.

Uninstalling the update could also restore printing functionality, but I have not tested this as I could not replicate the issue on my devices. Considering that disabling the security fixes is a recommended workaround by Microsoft, I’d say there is a good chance that this could work.

Chrome

The Chrome Web Store has a fake VPN extensions problem

Posted on August 24, 2026August 24, 2026 by Martin Brinkmann

Security researchers at Socket have uncovered a large impersonation and browser traffic redirection campaign in the Chrome Web Store.

According to a news post on the official website, the campaign uploaded 737 VPN extensions to the Chrome Web Store and managed to lure more than 75,000 users to installing them on their devices.

The extensions impersonated 66 legitimate privacy and VPN brands—such as NordVPN, Proton VPN, and Surfshark—to deceive users into downloading them.

Core Threat Behaviors

  • Traffic Interception: Once activated, the extensions route the victim’s entire browser session through a SOCKS5 proxy controlled by a single threat actor. This places the attacker in a position to read and monitor all browser traffic.
  • Subscription Fraud: The extensions funnel users toward a paid subscription tier that promises premium server locations (such as Japan, Canada, and Australia). However, Socket found that none of these premium servers actually exist.

Deceptive Tactics & Evasion

  • DNS-over-HTTPS Evasion: The extensions use Cloudflare and Google’s DNS-over-HTTPS to silently resolve proxy IPs, preventing the victim’s machine from emitting plaintext DNS queries that security software might flag.
  • Store Review Gaming: The developers submitted false justifications to Chrome Web Store reviewers and used post-approval code substitution to sneak in the malicious proxy behaviors.
  • Hidden Domains: An internal developer manual accidentally left inside one of the extensions revealed explicit instructions to staff to never hardcode the actual domains into the extension, ensuring they stay hidden from automated scanners.

The campaign specifically targets Russian-speaking users who are trying to bypass internet censorship to access blocked services like YouTube, Instagram, and ChatGPT. By impersonating trusted anti-censorship tools, the attackers successfully tricked thousands of users into handing over full visibility of their web browsing activity to a threat actor based in Russia.

Chrome may use an extra 20 gigabytes of storage on your devices

Posted on August 19, 2026August 19, 2026 by Martin Brinkmann

Back in May 2026, some users of Google’s Chrome web browser discovered a jump in used storage space on their devices. The culprit at the time was an AI model that the browser downloaded automatically to user devices for on-device artificial intelligence processing.

The main idea here is to allow some AI tasks to run locally only, meaning that no interaction with a Google server is needed to make use of the functionality. The whole download felt forced to some users, who had no say in the matter whatsoever.

Now, Google and also Microsoft have increased the local storage requirements for AI significantly. Instead of 4 gigabytes of free disk space, Google requires a whooping 20 gigabytes as the bare minimum.

Google says that the model is only downloaded if Chrome runs on a device with supported hardware capabilities, but fails to specify what that means.

The best way to check whether your device is eligible is to load chrome://settings/system in the browser’s address bar and check the “On-device AI” setting there.

If it is turned on, the device has the requirements apparently and there is a good chance that a gigabyte-sized AI model has been downloaded to the system.

The model is downloaded to this folder: %LOCALAPPDATA%\Google\Chrome\User Data\OptGuideOnDeviceModel

The AI file is not downloaded in all cases, even with the On-device AI feature enabled. I checked on a test system that had the toggle set to on but no such file on the local hard drive.

You can turn off the functionality, which has three consequences according to Google:

  • Any AI model downloaded automatically to the local system is removed.
  • Chrome won’t download AI models.
  • Features that rely on the functionality won’t work.

The main features that are not available when you turn off local AI are:

  • Help with writing or rephrasing text
  • Warn you about scams
  • Summarize web pages
  • Organize your tabs

While local AI processing is without a doubt beneficial to privacy, companies like Google should consider giving their customers a clear choice before they start downloading gigabyte-sized files to their devices.

Microsoft Edge may unsubscribe you from certain notifications automatically now

Posted on August 15, 2026August 15, 2026 by Martin Brinkmann

Ah, notifications. The idea behind browser notifications is sound. It allows websites and services to notify you even if you don’t have them open at the time. However, notifications were turned into an abonimation quickly.

Seemingly every site wants you to turn on notifications for them, which is unpleasant enough. The main problem is spam and also malicious abuse of the system.

Whenever I check the browsers of my parents or other users who are not tech-savvy, I notice loads of notifications. It is easy enough to accept notifications, but not nearly as easy to turn them off again.

While you can disable all notifications, which I do on all of my systems, some may prefer to keep some notifications enabled.

Microsoft tests a new protective feature against abusive notifications in its Edge browser. The main idea behind the feature is to automatically unsubscribe Edge users if a notification was used to push scam, phishing, or malware pages.

When that happens, Edge will unsubscribe the user from receiving notifications to stop additional spam or malicious notifications from being received.

The feature is in beta currently and rolled out over time. It may take a while before it lands in stable Edge versions and even then, it may be on a slower rollout.

Microsoft says that users can check edge://settings/privacy/sitePermissions/allPermissions/notifications to see if sites have been blocked automatically by the security of the browser.

My suggestion? Turn them off entirely there right away and be done with them. You can still add some sites to the exceptions there, to allow them to send notifications while all other sites are blocked from even asking.

uBlock Origin gives up on playing whac-a-mole with Facebook ads

Posted on August 13, 2026August 13, 2026 by Martin Brinkmann

If you are a regular on Facebook or visit the site at times, you may have noticed the odd-ad slipping past your content blocker’s defenses. Even with the most powerful tools out there, uBlock Origin for Firefox comes to mind, it happens that you may see advertisement on Facebook.

This is not a one-time slip-off, but the result of a battle between a small team of developers and Meta’s billions. The cat and mouse game has come to an end according to a new post by the uBlock Origin team on Reddit.

According to the post, the content blocker won’t support Facebook going forward. The reason given is that Facebook is countering any bypasses the uBlock Origin team finds for blocking ads and trackers on the site.

For example, Facebook was changing ad labels and markers frequently on its site to cause content blockers to miss them entirely. While content blockers managed to find ways to block ads anew, Facebook then developed new bypasses to show ads once again on its site.

In the end, the team notes that it is too small and lacks the resources to go against a billion Dollar behemoth like Meta. While ads may be blocked for the time being, it sounds as if the next bypass won’t be countered by the team anymore.

This means that Facebook users with uBlock Origin installed will see ads on the site in the long run. It is probably fair to say that most other content blockers, regardless of whether they are native or installed as extensions, faces the same issue.

There is not much that you can do about it. Maybe other content blockers continue their fight against Meta and work most of the time, but that would mean some testing to see which do and which don’t. It is the first time, to my knowledge, that a major content blocker has lowered the flag.

Encryption

DiskCryptor 2.0 released: disk encryption software makes a comeback

Posted on July 9, 2026July 9, 2026 by Martin Brinkmann

Remember when the developers of TrueCrypt suddenly stopped the project back in 2014 and recommended that users started looking for alternatives? One of these alternatives was VeryCrypt, a fork of the TrueCrypt. Another Disk Cryptor, which I did use for some years.

Disk Cryptor development stopped about ten years ago and it looked as if the project was dead. However, in 2019, David Xanatos took over and started to released new versions of the software. You may know the developer from some of his other projects, such as Sandboxie Plus. DiskCryptor was first released as beta builds but then also as final builds.

The initial builds of the application were focused on improving compatibility and integrating support for new technologies. As a consequence, DiskCryptor should work fine under the latest versions of Windows 10 and 11.

The developer has released DiskCryptor 2.0 this week (and bug fix release 2.0.1), marking a major milestone in the development of the program.

He writes:

This release introduces substantial improvements across virtually every part of the software, including modern cryptography, hardware-backed security, storage management, performance, reliability, and usability.

A major addition is support for the Argon2id key derivation function, providing a modern, memory-hard alternative to the traditional KDFs for significantly improved resistance against password cracking attacks.

DiskCryptor now also supports optional TPM integration in the DCS bootloader, enabling hardware-backed protection and unattended system unlock configurations. Combined with optional Secure Boot support, this allows systems to take advantage of modern platform security features while maintaining DiskCryptor’s flexible boot architecture.

Since this is a major change, the new version is released as a pre-release at the time to gather feedback and react to any issues that might occur.

Is it ready for broader use again? I’m pretty happy with VeraCrypt at the moment and have no desire to switch to another encryption program at the moment, as it would be time consuming. However, if you still use an earlier version of DiskCryptor or want to start encrypting your drives for better protection, it may be worth a try.

I suggest you wait a bit though until the developer gives the okay that the pre-release phase is over. (via Günter Born)

Opera Browser gets new security feature to protect the Clipboard

Posted on July 6, 2026July 6, 2026 by Martin Brinkmann

Opera Software announced a new feature for its Chromium-based Opera browser: Paste Protect is designed to block suspicious content from accessing the Clipboard of the operating system.

Introduced in Opera One as an experimental feature, Paste Protect is designed to protect against two specific attack types, notes Opera Software in an official blog post:

  1. It actively prevents the malicious code from being copied onto your clipboard.
  2. It lets you know that there was an attempt to copy something onto your clipboard that’s potentially harmful.

The main idea is to protect users from copying malicious code to the Clipboard. In the past, attackers have used this to get Internet users to execute malicious code or instructions on their computer systems.

The developers at Opera describe a common form of attack that exploits this on the blog as well:

  1. The website displays a Captcha and ticking a box to confirm that the user is human.
  2. A second verification prompt is displayed after the check. It copies data to the Clipboard of the system in the background.
  3. Instructions are displayed that ask the user to open the run box (Windows+R) and use the Ctrl-V shortcut to paste the content of the Clipboard. All that is required then is for the user to hit ok to run the instructions on the system.

Opera says that the new Paste Protect feature blocks this type of attack. The company explains how its security feature handles potential threats:

When there is something copied to your clipboard, the Opera browser checks the content for potential threats and harmful commands. If a potential threat is detected, Opera will automatically block the capability for the browser to copy something onto your clipboard from the malicious website and provide you with the option to close the site safely.

The browser displays a red warning icon to indicate that it has blocked a threat. It will recommend to close the tab the attack originated from.

Paste Protect is enabled by default, but only available in Opera One. It follows Hijack Protection, which Opera Software introduced in 2021 in the browser. The feature protected the clipboard from so-called hijacking attempts, such as replacing URLs in the clipboard or replacing a bank account number.

Brave 1.92 launches with support for Containers

Posted on July 3, 2026July 3, 2026 by Martin Brinkmann

Brave Software announced that the latest version of Brave Browser supports the Containers feature now. The main idea behind it is to isolate website data. When you load a website in one container, its data and any third-party data is only accessible in that container. Think of a sandbox for sites.

Containers is not a new feature, as it was originally developed and launched by Mozilla in Firefox. The Brave integration is built-in. I had to enable the feature under chrome://flags/#containers first, but it should be available without that in the coming days.

Visit brave://settings/braveContent then to toggle “Enable Containers” there. This turns the feature on so that it is ready for use in the browser.

Like Firefox, Brave includes a set of default containers — personal, work, social and school — but you can add new containers, remove the defaults or rename them.

Once done, right-click on any link or tab and select “Open in Container”. You get the option to pick one of the existing containers and Brave highlights this with a new container icon in front of the tab and also in the address bar.

You may also right-click on the new tab icon to create a new container directly and without opening another website first.

Last but not least, you may also create temporary containers. Regular containers offer the same functionality as open tabs. Means, unless you close the sites or the container, they persist over sessions and you can restore tabs in them using restore functionality.

The main difference to temporary tabs is that they can’t be restored. When you close them, they are gone for good and tab or session restore options do not work for them.

LastPass Hit by Third-Party Data Breach: What You Need to Know About the Klue Incident

Posted on June 25, 2026June 25, 2026 by Martin Brinkmann

Anyone still using LastPass? If so, you need to be aware about a new security incident that has been confirmed by the company this week.

In the modern SaaS ecosystem, a digital fortress is only as secure as the side door left open for third-party vendors. Password management firm LastPass has disclosed a new data breach that involved the intelligence platform Klue.

According to an official incident report published on the LastPass blog, threat actors recently compromised Klue’s systems to steal OAuth tokens, granting them unauthorized access to LastPass’s Salesforce environment.

What the Attackers Obtained

The threat actors compromised Klue’s systems to steal OAuth tokens, which they then used to access LastPass’s Salesforce environment. The exposed data was limited to standard CRM and business contact information:

  • Customer names
  • Email addresses
  • Phone numbers
  • Physical addresses
  • Support case data
  • Sales-related data

What They Did NOT Obtain

The core architecture of LastPass remained unbreached. The attackers did not gain access to:

  • Customer Vaults: All stored passwords, secure notes, and saved data remained encrypted and secure
  • Master Passwords: Because of LastPass’s zero-knowledge architecture, master passwords are never known or stored by the company, and they were not exposed here.
  • Core Systems: LastPass products, services, and primary infrastructure were entirely unaffected

LastPass reveals that the information can be used for phishing attacks and other social engineering attempts. It recommends that “customers remain vigilant” and “exercise caution regarding unsolicited communications, including emails, phone calls, or requests for sensitive information.”.

For LastPass users suffering from breach fatigue, this latest headline likely induces a familiar sense of dread. However, when put into perspective, the Klue incident is a far cry from the devastating, back-to-back breaches of 2022, where threat actors successfully made off with encrypted customer vault backups and proprietary source code.

Still, while this is fundamentally a story about a third-party CRM leak rather than a critical product failure, the stolen contact information arms hackers with exactly what they need to launch highly convincing phishing campaigns.

uBlock Origin extension bypasses no longer working in Chrome: your options

Posted on June 15, 2026June 15, 2026 by Martin Brinkmann

We all knew that the time would eventually come. Google is removing bypasses in Chromium and Google Chrome that allowed users to run legacy extensions in the browser.

Google moved to a new extension rules system, called Manifest V3, which turned out to be a very controversial move. The company claimed that this was all for performance and security, but the change had the fortunate side effect that it would impact content blocker extensions more than any other extension type.

Google modified the rule set several times, which would have killed content blockers more or less in the beginning, and content blockers continue to be available.

However, Chrome users who have enabled bypasses to continue using these extensions will soon realize that they can’t anymore. The reason is simple: Google removed them.

This is not the end of content blocking in Chrome and other Chromium-based browsers. Here are the options that you have going forward:

  • Switch to a MV3 extension: Browser extensions such as uBlock Origin Lite are available. These continue to block ads in Chrome, but they lack some of the advanced features of the classic blocker.
  • Use a Chromium-based browser that continues to support MV3 extensions: Brave, Vivaldi and Opera all pledged to support MV2 extensions going forward. It remains to be seen whether this is going to be the case once the bypasses are removed.
  • Switch to Firefox: Firefox supports MV2 and MV3 extensions. You can install uBlock Origin in Firefox and get the best level of protection out of any version of the extension.
  • Use a browser with a built-in content blocker: Plenty of options, Brave, Opera or Vivaldi all come with the functionality.

  • 1
  • 2
  • 3
  • 4
  • …
  • 14
  • Next

Support This Site

If you like what I do please support me!

Any tip is appreciated. Thanks!
  • August 29, 2026 by Martin Brinkmann Another Windows Issue: Microsoft Defender Antivirus is turned off notification, but it is actually enabled
  • August 28, 2026 by Martin Brinkmann Brave Accounts and Email Aliases launch
  • August 25, 2026 by Martin Brinkmann Microsoft confirms: Latest .NET updates may cause printing issues
  • August 24, 2026 by Martin Brinkmann The Chrome Web Store has a fake VPN extensions problem
  • August 23, 2026 by Martin Brinkmann Microsoft is worsening classic Media Player to get users to upgrade

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2026 Chipp.in Tech News and Reviews