Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

Category: Security & Privacy

New AI Tool creates dossiers of users based on YouTube comments

Posted on June 4, 2025June 4, 2025 by Martin Brinkmann

Many sites support comments. You can leave a comment under videos, articles, or in forums to add your take on something, add something that you think is missing, or, most likely, to correct the original author.

Using public comments or posts is not a new invention. In fact, it goes all the way back to the beginning days of the Internet.

Now, with the rise of new AI tools and capabilities, come tools that take this to a new level.

A report by 404 Media (paywalled) offers insights into YouTube-Tools, a new paid service that uses AI to create reports about any commenter on YouTube. The service is available for $20 per month according to the report.

Subscribers may then point the tool to the comment of any YouTuber on the site to order a detailed report about that user. The AI tool analyses the comment and other posts on the site to reveal information about the geographic location, political leanings or spoken languages.

The developer of the tool notes that it has access to a database containing information about 1.4 billion YouTube users and over 20 billion comments. While the total number of comments on YouTube is not public knowledge, YouTube has almost double the number of users according to 404 Media.

Regardless, advancements in AI pave the way for a new breed of tools that will be used for tracking and the invasion of privacy.

Internet users should be careful when they leave comments, messages or posts that are publicly accessible, especially when that comment might reveal something about them that they would not want to be linked back to them.

Google fixes a 0-day exploit in its Chrome browser that is exploited in the wild

Posted on June 3, 2025June 3, 2025 by Martin Brinkmann

Google released a new security update for its Chrome web browser that fixes three security issues, including one that is exploited in the wild.

The security issue affects the desktop versions of Google Chrome and the Android version. Desktop users may select Menu > Help > About Google Chrome to install the security update immediately. Google says that it may take days or even weeks before updates may be installed automatically on systems running Google Chrome.

Google reveals basic information about two of the three vulnerabilities. The vulnerability that is exploited in the wild is CVE-2025-5419. It is an out of bounds read and write vulnerability in Chrome’s JavaScript engine that is rated high.

Google reveals that it mitigated the issue on May 28th already. It released a configuration change on the day that it “pushed out to Stable across all Chrome platforms”. Many systems running Chrome should have received the update on that day or the following days already.

Google confirmed that the security issue is exploited in the wild, but did not reveal additional information at the time. The scope of the attack and the attack vector are unknown because of this. Google limits access to security information, including information about patched security issues, to avoid giving malware groups and developers additional hints about the issue.

Chrome users may display the current version of the web browser by loading chrome://settings/help on desktop systems. Google displays on the page if Chrome is up to date.

Chrome 137 Security update

The following versions should be displayed after installation of the update.

  • Chrome for Windows or Mac: 137.0.7151.68 or 137.0.7151.69
  • Chrome for Linux: 137.0.7151.68
  • Chrome for Android: 137.0.7151.72

Android users can’t speed up the installation of the update.

Now You: do you use Chrome or have the browser installed? Feel free to leave a comment down below.

Google Search

Chrome 136 update patches security issue that is exploited in the wild

Posted on May 15, 2025May 15, 2025 by Martin Brinkmann

Google released a security update for its Chrome web browser for the desktop and Android that fixes several security issue. One of the issues is rated high and already exploited on the Internet according to Google.

The details:

  • The update is available for Chrome on Windows, Linux, Mac, and Android.
  • It includes fixes for four security issues in total.
  • The update is a point update for Chrome 136.

The security update changes the version of the Chrome web browser to the following versions:

  • Windows and Mac: 136.0.7103.113 or 136.0.7103.114
  • Linux:ย 136.0.7103.113
  • Android: 136.0.7103.125

Google lists just two of the fixed security issues on the official Chrome Releases blog. One of them is CVE-2025-4664, which is rated high and described as a “insufficient policy enforcement in loader” security issue.

Malicious users may exploit the issue to “leak cross-origin data via a crafted HTML page”. Google notes that it is aware of exploits in the wild, but does not provide additional information on the scope of the attacks.

Chrome users are encouraged to update their browser immediately to protect their data against potential attacks targetting the vulnerability.

Desktop users may select Menu > Help > About Google Chrome to run a check for updates. This should pick up the latest version and install it on the device. Android users can’t speed up the installation of the update unfortunately.

It is possible that other Chromium-based browsers are also affected by the issue. Expect security updates for these browsers in the coming hours and days as well.

Malicious Captchas are on the rise

Posted on May 3, 2025May 3, 2025 by Martin Brinkmann

Captchas can be quite annoying, especially if your input is not accepted or if they do not work at all. You may now add malicious captchas to the list of annoyances.

Proton Mail published one example on X recently.

Fake CAPTCHA attacks are on the rise, causing many to fall prey to infostealers injecting malware onto their devices.

Here's how it works, and what you can do to stay safe

๐Ÿ‘‡๐Ÿงต 1/7 pic.twitter.com/gjwIf2YPnl

— Proton Mail (@ProtonMail) May 2, 2025

The malicious captcha tries to convince unsuspecting users to run a command on their Windows machines.

Here is how it works:

  1. The victim lands on a page with the fake captcha, for instance after clicking on a link in an email or chat.
  2. The captcha displays the usual “I’m not a robot” button.
  3. A click or tap on the button copies a PowerShell command to the operating system’s clipboard.
  4. Victim is instructed to use the shortcut Windows-R to open a run box.
  5. Asked to use Ctrl-V to paste the command and to press Enter to execute it.

Doing so downloads malware from a server on the Internet and runs it on the user’s system. This can be infostealers, malicious software that steals personal information, such as logins, financial documents, or photos.

While most, or even all, experienced users may never fall for that, it is almost a given that inexperienced users may. They may have difficulties getting the run box to open or paste the command, but they probably do not suspect foul play.

How to protect yourself

Protection is quite easy.

No legitimate captcha will ever ask you to execute a command on a local system, or to download a file and run it.

That is pretty much all that you need to protect yourself and your data against this type of attack.

Clearly, you may also want to ask yourself whether you trust the site you are on. Even if you conclude that you do, you should not run anything on the local computer when prompted to do so by a captcha.

Now You: how do you handle captchas on the Internet?

About Alphonso: a technology that captures audio samples on mobile devices using the built-in microphone

Posted on April 27, 2025April 27, 2025 by Martin Brinkmann

For advertisers, it may seem like the perfect fit. Integrate a technology into mobile apps, games for the most part, that identifies ads playing on television to push similar ads on mobile, even if the mobile is not used actively.

News about such a system comes just days after LG announced the integration of AI into its televisions to determine the emotions and beliefs of viewers.

The startup Alphonso has apparently created the technology and it is already being used in hundreds of apps and games, some of which are available on Google Play or the Apple App Store.

It works by capturing audio samples using the device’s microphone. These are turned into hashes on the user’s device before they are submitted to a remote server. The hashes are checked against a database of hashes of television ad sound samples to find matches.

A report by The New York Times — you need an account to read it, or archive.is — has additional details.

  • Sound can be recorded even if the mobile phone is in a pocket or if the apps are running in the background.
  • Some of the apps are clearly aimed at children (Alphonso told the NYT that it did not approve of that).

Alphonso told the New York Times that the entire process is highlighted in the application’s description and in the privacy policy. Users need to accept these before the technology can start recording anything.

While technically correct, it is clear that many users do not read the description or privacy policy before hitting the install button in the mobile app stores.

The only way to prevent giving your okay to the recording of audio is to read the description and privacy policy carefully before hitting the install button. A search for Alphonoso may be the quickest option in this regard.

Tor Browser 14.5 brings Connection Assist feature to Android

Posted on April 18, 2025April 18, 2025 by Martin Brinkmann

The developers of the anonymizer Tor Browser have released a new version for all supported operating system. The big feature in this release is the introduction of Connection Assist on Android.

The feature, which has been available in Tor Browser for desktop operating systems for quite some time, aims to help users establish a connection to the Tor network if regular connection attempts do not work.

So, if connecting to Tor fails in the browser, for example when you try to connect from a country that blocks this, then Connection Assist kicks in. It uses so-called bridges to establish a connection. Bridges use different techniques to circumvent censorship.

Android users could use bridges previously, but it was not that comfortable to configure and use.

The new feature integrates the functionality seamlessly into the Android client, making it a much better experience for users who require these.

All users should benefit from “more stable and less error-prone connections” as well, according to the release announcement.

Tor Browser 14.5 includes support three new languages as well. These are Belarusian, Bulgarian, and Portuguese (Portugal) and available in the desktop and Android clients.

Tip: Languages can be set under Settings > General > Language and Appearance > Language on desktop or Settings > General > Language on Android.

Here are other noteworthy changes:

  • Tor logs on desktop have been “enhanced to aid readability”. Also, no longer necessary to close and reopen to refresh logs.
  • Quitting Tor Browser on Android does now a “thorough job of ending background processes and clearing recent tasks”.
  • Improvements to the Connection Assist logic in general.

Tor Browser 14.5 includes several known issues which you find listed on the official issues tracker. Make sure you pay the page a visit before upgrading or installing the new version of the web browser.

You can check out the full release notes here.

Latest Rufus release fixes side-loading vulnerability

Posted on April 9, 2025April 9, 2025 by Martin Brinkmann

Rufus, one of my favorite open source tools, is now available in a new version. Rufus 4.7 is a security release that includes new features and non-security fixes.

The developer fixed a side-loading vulnerability in the application that allowed an attacker to load a malicious DLL with escalated privileges.

For this to work, the attacker had to plant the malicious DLL file into the same directory as the Rufus executable. The impact seems low, but it is still good that the issue got fixed.

Here is the info provided on the Rufus Security forum:

A DLL hijacking vulnerability in Rufus 4.6.2208 and earlier versions allows an attacker loading and executing a malicious DLL with escalated privileges (since the executable has been granted higher privileges during the time of launch) due to the ability to inject a malicious cfgmgr32.dll in the same directory as the executable and have it side load automatically. Versions 4.7 and later are not affected by this vulnerability.

So, it is recommended to update Rufus to the latest version to patch the issue.

Note that the internal update finder may not find the update yet. You can download it manually from the project’s GitHub repository in the meantime.

As far as other features are concerned, there are a handful:

  • Ability to detect and download updated DBXs from the official UEFI repository.
  • Support for ztsd compression for disk images added.
  • Exclusion feature in Settings to “ignore disk with a specific GPT GUID”.

There are also some fixes included, which you find listed here.

Gmail’s new end-to-end encryption feature is atrocious for non-Gmail users

Posted on April 7, 2025April 7, 2025 by Martin Brinkmann

Google announced support for end-to-end encrypted emails on Gmail for organizations and later this year for end users last week. This allows Gmail users to encrypt emails so that only the recipient can read them.

Gmail is far from being the first email provider to offer such a feature. Proton Mail, for instance, supported end-to-end encrypted emails from the get-go.

When you read Google’s announcement, you may stumble upon the explainer on how this is implemented. Not technically, but how it works from the user’s perspective.

According to Google, end-to-end encrypted emails on Gmail work differently depending on whether you are a Gmail user or not, and whether an administrator has configured use of the restricted Gmail version for all users.

So, here are the different scenarios when someone sends an encrypted email from Gmail.

  • When the recipient is a Gmail user, the user may read it in their inbox. The email is decrypted when it reaches the inbox and the email can be read.
  • When the recipient is not a Gmail user, they receive an invitation to open the email in a guest Google Workspace account. This allows them to view and reply to the email in a restricted version of Gmail.
  • If S/MIME is configured, Gmail sends the encrypted email via S/MIME.

Google Workspaces administrators may furthermore configure encrypted emails to always require the restricted version of Gmail.

Here is why that is bad

Some emails, all end-to-end encrypted ones, no longer land in your inbox, if you do not use Gmail or when the admin enabled restricted mode. You furthermore need to sign in using an invite link and a pin. Organizations may furthermore limit access to emails by revoking access at any time.

To be fair, this is not all that different from how Proton Mail handles sending encrypted emails to non-Proton users.

Still, if you are not a Gmail user, you may have to read some emails on the Gmail website in the future using the guest account feature of Google Workspaces. This may have severe consquences:

  • When you search emails in your dedicated client or web service, encrypted email content is not included.
  • Filters may not work correctly, as they may only apply to the public part of the email and not the body.
  • Security tools can’t scan the emails.

It is probably only a matter of time before malware campaigns start to use the new feature.

Now You: what is your take on this? Do you use encrypted email already? Feel free to leave a comment down below.

KeePass 2.58

KeePass 2.58 password manager is out

Posted on March 4, 2025March 4, 2025 by Martin Brinkmann

A new version of the password manager KeePass for Windows is now available. KeePass 2.58 is the first release of the password manager in 2025. The last version, KeePass 2.57.1, was released in October 2024.

The update is a smaller one. It introduces a few minor features and changes. Good news is that no security issues needed fixing, which is why this is a non-security update for the password manager.

The list of changes is relatively long, and it may be confusing to navigate the listing. Here is a quick overview of the most important or useful changes in the release:

  • You may now use the keyboard shortcut Ctrl-H to toggle password visibility in report dialogs. Note that this works when viewing passwords in the table-like interface, but seemingly not, when you display a single password.
  • The preview tab of the password generator displays the average estimated quality of the passwords now and has the number of passwords increased to 50.
  • KeePass will abort the preview generation of passwords if the operation is taking too long.
  • User-Agent header for web requests added.
  • On systems with Microsoft Edge uninstalled, the browser no longer appears in the URL(s) menu.

Again, there is more to discover but these look to be the highlights of the release.

How to update KeePass: this is relatively easy. Since there is no integrated update system that you may use to download and install updates, you need to visit the developer website, download the latest release, and install it manually.

If you like winget, you could also run winget upgrade DominikReichl.KeePass to download and install the latest version using the built-in software package manager.

Now it is your turn. What is your favorite password manager right now and why? Feel free to leave a comment down below.

uBlock Origin working in Chrome

More Chrome users are getting “this extension was turned off” notifications

Posted on February 25, 2025February 25, 2025 by Martin Brinkmann

Google has been hard at work to establish Manifest V3 as the new and only set of rules for Chrome extensions. Report suggest that Google has shifted the process into a higher gear and is disabling classic extension support for more Chrome users.

The effect is the following: any extension that is not compatible with Manifest V3 will be disabled. Chrome displays “was turned off” messages to users in that case on start. A check of the extensions management page reveals a similar message: “This extension was turned off because it’s no longer supported”.

Most Chrome users will probably experience this with the popular uBlock Origin extension. It cannot be ported fully to Manifest V3, as Google changed core functionality.

In other words, the change has a very positive effect for Google, as it gets rid of what is probably the most popular content blocker for Chrome.

While there is uBlock Origin Lite by the same developer, it is limited in some regards to the classic version. It is better than no content blocking, but still inferior.

Users who really need to use Chrome can postpone the death of uBlock Origin and other Chrome extensions that are not compatible with Manifest V3 by setting a policy. This will work only until mid-2025 though, unless Google pushes the change back a bit.

Your options

In the end, it may be better to switch to a browser that is still offering support. If you prefer Chromium, you could give Brave or Opera a try. Both companies have pledged to support Manifest V2 extensions, at least some of them, even after Google ends support in Chrome.

Another option is to switch to Firefox or a Firefox fork, like Mullvad Browser. Mozilla said that it is going to support Manifest V2 extensions and V3 extensions at the same time in Firefox. Means, you can run good old uBlock Origin in Firefox without having to worry about it suddenly being turned off.

  • Previous
  • 1
  • …
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • …
  • 14
  • Next

Support This Site

If you like what I do please support me!

Any tip is appreciated. Thanks!
  • August 29, 2026 by Martin Brinkmann Another Windows Issue: Microsoft Defender Antivirus is turned off notification, but it is actually enabled
  • August 28, 2026 by Martin Brinkmann Brave Accounts and Email Aliases launch
  • August 25, 2026 by Martin Brinkmann Microsoft confirms: Latest .NET updates may cause printing issues
  • August 24, 2026 by Martin Brinkmann The Chrome Web Store has a fake VPN extensions problem
  • August 23, 2026 by Martin Brinkmann Microsoft is worsening classic Media Player to get users to upgrade

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2026 Chipp.in Tech News and Reviews