Controversy increases over ‘Bribery Pandit’, complaint filed against Netflix; Karan Singh said – the platform is hurting the integrity – Ghooskhor Pandat Controversy Karan Singh File A Complaint Against Netflix In Mumbai Over Manoj Bajpayee Movie

0

Ghooskhor Pandat Controversy: Manoj Bajpayee’s upcoming film ‘Ghushkhor Pandit’ is embroiled in controversies even before its release. Now a complaint has been lodged with the police in Mumbai also regarding this film. Learn about the case in detail…

Ghooskhor Pandat Controversy Karan Singh File A Complaint Against Netflix In Mumbai Over Manoj Bajpayee Movie

bribe taking pundit in controversies – Photo: Amar Ujala

Expansion

Manoj Bajpayee starrer Netflix’s upcoming film ‘Ghooskhor Pandit’ is embroiled in controversies even before its release. Due to the use of the word Pandit in the title of the film, the Brahmin community has come out on the streets and is protesting against it. A petition has also been filed in the Delhi High Court regarding the film. Now regarding this matter, Karan Singh, an officer of Samvidhan Samman Manch, has filed an official complaint against Netflix at BKC Police Station in Mumbai. He says that such content is being given space on this platform, which can affect India’s image and social environment.

Trending Videos

Nicaraguan man allegedly attacks federal agents in Pittsburgh

0

NEWYou can now listen to Fox News articles!

A Nicaraguan man living illegally in Pittsburgh faces up to 20 years in prison after allegedly launching a violent attack on federal agents – ramming a law enforcement vehicle, trying to grab an officer’s gun, and biting an agent – following a failed attempt to buy a firearm.

A federal grand jury in Pittsburgh indicted 33-year-old Darwin Alexander Davila-Perez on Wednesday on a charge of assaulting a federal officer.

The investigation began when the Department of Homeland Security learned that Davila-Perez had tried to buy a gun from a local dealer. During that transaction, he allegedly claimed to be a U.S. citizen.

The sale was blocked after the dealer discovered he was a Nicaraguan national with no legal status in the U.S. Federal law prohibits those in the country illegally from possessing or purchasing firearms.

ICE OFFICER SERIOUSLY INJURED AFTER ILLEGAL IMMIGRANT ASSAULT, USING METAL COFFEE CUP

ICE agents walking together.

A Nicaraguan man in Pittsburgh faces 20 years after allegedly biting an ICE agent and ramming a police car following a failed illegal gun purchase attempt. (Christopher Dilts/Getty Images)

On Dec. 17, 2025, U.S. Immigration and Customs Enforcement agents attempted to pull Davila-Perez over to take him into custody for immigration violations. When agents activated their emergency lights, Davila-Perez didn’t pull over – he fought back, according to authorities.

According to the indictment, Davila-Perez slammed his car into reverse, hitting an occupied law enforcement vehicle before jumping out to run.

TWICE-DEPORTED ILLEGAL IMMIGRANT PEDOPHILE SEVERELY INJURES ICE OFFICER DURING HOUSTON ARREST

ICE agents in garage.

Darwin Alexander Davila-Perez is facing up to 20 years in prison after allegedly launching a violent attack on federal agents, following a failed attempt to buy a gun. (Getty Images)

During the ensuing struggle, he allegedly elbowed one officer in the face, tried to pull an agent’s service weapon from its holster, bit an officer’s arm and struck an agent in the forehead with a pair of handcuffs.

The whole time, officers shouted commands in both English and Spanish for Davila-Perez to stop and show his hands. However, authorities say he ignored those orders until he was eventually subdued.

ICE ARRESTS ILLEGAL IMMIGRANT ARMED WITH KNIFE, CRACK PIPE IN HOUSTON PARKING LOT

Pittsburgh Covered In Snow

Darwin Alexander Davila-Perez tried to buy a gun in Pittsburgh, but the dealer found out he was in the U.S. illegally, acording to authorities. (Getty Images)

The struggle left several agents with bite wounds, scrapes and bruises that required medical treatment.

If convicted, Davila-Perez faces a maximum of 20 years in prison, a fine of up to $250,000 or both.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

He remains in custody pending the resolution of the case.



Source link

Ukraine:’Russia is illegally targeting the power grid’, Ukraine accuses Moscow; Know what the law is – Ukraine Says Russia Is Illegally Targeting The Power Grid Here Is What The Law Says

0

In recent days, Russia has attacked Ukraine’s energy facilities. After which Ukraine has also alleged that Russian missiles and drones are illegally targeting their energy bases. Ukraine alleges attacks on its energy facilities and power grid have left people in the dark and cold during one of the country’s coldest winters ever.
Trending Videos


Ukrainian President Volodymyr Zelensky said on Tuesday, ‘Taking advantage of the coldest days of winter to scare people is more important than diplomacy for Russia.’ Russia says that its attacks are a legitimate part of the military operation. So are attacks on energy installations permitted during war? Let us know what the law says-

What does international law say?
David Crane, former Chief Prosecutor of the United Nations Special Court for Sierra Leone, explained that parties can legally target power grids during a war, but the attack must directly impact a legitimate military target and must not cause significant civilian casualties.

Russia denied violating the law
  • The Russian military has repeatedly said it has targeted energy facilities and other infrastructure that support Ukrainian military industry and armed forces.
  • Also, Russia has denied targeting residential areas.
  • Russia said, ‘Our forces are attacking targets that are linked to military complexes of the Ukrainian government, the operation is ongoing.’

Kyiv’s allegation – Russia wants to break the morale of Ukrainian people
  • At the same time, Kiev alleges that Russia wants to break the fighting spirit of the Ukrainian people by imposing huge hardships on the common citizens who are forced to live in dark, cold houses.
  • Officials say Russia has tried to paralyze Ukraine’s electricity network by targeting substations, transformers, turbines and generators at power plants.
  • Ukraine’s largest private power company, DTEK, said the attack overnight this week was the ninth major attack on the company’s thermal power plant since October.
  • According to an estimate by the World Bank, the European Commission and the United Nations, Ukraine’s energy sector has suffered direct losses of more than US$20 billion due to the war.

Hackers compromise NGINX servers to redirect user traffic

0

Hackers compromise NGINX servers to redirect user traffic

A threat actor is compromising NGINX servers in a campaign that hijacks user traffic and reroutes it through the attacker’s backend infrastructure.

NGINX is open-source software for web traffic management. It intermediates connections between users and servers and is employed for web serving, load balancing, caching, and reverse proxying.

The malicious campaign, discovered by researchers at DataDog Security Labs, targets NGINX installations and Baota hosting management panels used by sites with Asian top-level domains (.in, .id, .pe, .bd, and .th) and government and educational sites (.edu and .gov).

Wiz

Attackers modify existing NGINX configuration files by injecting malicious ‘location’ blocks that capture incoming requests on attacker-selected URL paths.

They then rewrite them to include the full original URL, and forward traffic via the ‘proxy_pass’ directive to attacker-controlled domains.

The abused directive is normally used for load balancing, allowing NGINX to reroute requests through alternative backend server groups to improve performance or reliability; hence, its abuse does not trigger any security alerts.

Request headers such as ‘Host,’ ‘X-Real-IP,’ ‘User-Agent,’ and ‘Referer’ are preserved to make the traffic appear legitimate.

The attack uses a scripted multi-stage toolkit to perform the NGINX configuration injections. The toolkit operates in five stages:

  • Stage 1 – zx.sh: Acts as the initial controller script, responsible for downloading and executing the remaining stages. It includes a fallback mechanism that sends raw HTTP requests over TCP if curl or wget are unavailable.
  • Stage 2 – bt.sh: Targets NGINX configuration files managed by the Baota panel. It dynamically selects injection templates based on the server_name value, safely overwrites the configuration, and reloads NGINX to avoid service downtime.
  • Stage 3 – 4zdh.sh: Enumerates common NGINX configuration locations such as sites-enabled, conf.d, and sites-available. It uses parsing tools like csplit and awk to prevent configuration corruption, detects prior injections via hashing and a global mapping file, and validates changes using nginx -t before reloading.
  • Stage 4 – zdh.sh: Uses a narrower targeting approach focused mainly on /etc/nginx/sites-enabled, with emphasis on .in and .id domains. It follows the same configuration testing and reload process, with a forced restart (pkill) used as a fallback.
  • Stage 5 – ok.sh: Scans compromised NGINX configurations to build a map of hijacked domains, injection templates, and proxy targets. The collected data is then exfiltrated to a command-and-control (C2) server at 158.94.210[.]227.
Overview of the hijacking attack
Overview of the hijacking attack
Source: Datadog

These attacks are hard to detect because they do not exploit an NGINX vulnerability; instead, they hide malicious instructions in its configuration files, which are rarely scrutinized.

Also, user traffic still reaches the intended destination, often directly, so the passing through attacker infrastructure is unlikely to be noticed unless specific monitoring is performed.

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.



Source link

Fans race to learn Spanish before Bad Bunny’s Super Bowl half-time show | Bad Bunny

0

Bad Bunny is expected to perform the Super Bowl half-time show on Sunday entirely in Spanish – which has inspired fans to quickly learn the language.

In October, the Puerto Rican singer – born Benito Antonio Martínez Ocasio – kicked off the 51st season of Saturday Night Live expressing pride over the achievement in Spanish, after which he said in English, “If you didn’t understand what I just said, you have four months to learn!”

That declaration further stoked the anger of some conservatives who have vilified Bad Bunny for speaking out against US president Donald Trump’s anti-immigrant policies. The singer canceled the US portion of his tour last year out of fear that Immigration and Customs Enforcement agents would target his fans.

There has been a frenzy online of people posting about Bad Bunny lyrics, including Puerto Ricans explaining slang used by the singer and non-Spanish speakers documenting their journey to learn Spanish.

Anticipation for his half-time performance has only intensified since last weekend, when his album Debí Tirar Más Fotos became the first Spanish-language album to win the Grammy for album of the year. He did not shy away from addressing targeted federal immigration operations at the awards.

“Before I say thanks to God, I’m going to say ICE out,” he said in English after winning his first Grammy for música urbana album. “We’re not savage, we’re not animals, we’re not aliens. We are humans and we are Americans.”

‘Like a form of protest’

Niklaus Miller, 29, has been buckling down on learning Bad Bunny lyrics since the singer’s SNL appearance months ago.

“I am delusional enough to be like ‘this would be easy. I could pick it up pretty quickly,’” Miller said.

The fervor to learn a new language within a short time span highlights the powerful impact of Latino culture in the US despite the president’s anti-immigrant rhetoric and actions.

“It felt like a form of protest,” Miller said. “What can I do right now besides what everyone is doing that is trying to help? It just feels good.”

Miller said he has got messages from people who watch his videos with their parents since he started posting about the process of learning Spanish. They say they feel seen and appreciated.

While Miller has not learned Bad Bunny’s entire discography, he has learned portions of six songs that he feels will be part of the half-time show, including Tití Me Preguntó, DtMF and Baile Inolvidable.

The day after Bad Bunny was announced as the half-time act, O’Neil Thomas, 28, a New York City actor and content creator, started learning the singer’s catalog.

“I was just so excited because he wasn’t an artist that I expected,” Thomas said. “And given how we are right now with the state of the country I think he is the perfect person to headline such a humongous stage.”

The response to his TikTok videos – showing Thomas learning NUEVAYoL and other tracks – have been really positive, Thomas added. Many Puerto Rican people have reached out, saying they are proud that someone outside the community is attempting to learn about their culture.

Latin culture intensifies interest in Spanish

“People were already starting to make the effort with learning Spanish as a result of their interest in Latin music,” said Vanessa Díaz, associate professor of Chicano and Latino studies at Loyola Marymount University. “The Super Bowl itself is an additional push for a trend that was already happening.”

Díaz, who is the co-author of P FKN R: How Bad Bunny Became the Global Voice of Puerto Rican Resistance, says the rise of Latin music over the past decade has pushed non-Spanish speakers to learn the language. Bad Bunny’s clear messaging in his lyrics, videos and performances amplifies that interest, Díaz said.

Spanish is the most spoken language at home behind English in the US – except in three states, according to US census data. More than 13% of residents age five and older speak it.

Niklaus Miller has been learning Bad Bunny lyrics since the singer’s SNL appearance. Photograph: Damian Dovarganes/AP

But Bad Bunny’s booking at the Super Bowl has been divisive from the start. Trump called the selection “ridiculous.” Conservatives have called it anti-American – even though native-born Puerto Ricans are also US citizens. Turning Point USA is putting on an alternative “All-American Halftime Show” with a lineup led by Kid Rock.

This all comes against the backdrop of Latinos and Spanish-speaking communities being targeted in Trump’s immigration crackdowns. His executive actions have vastly expanded who is eligible for deportation and routine hearings have turned into deportation traps for migrants.

Díaz doesn’t think his performance will necessarily shift how Latinos are perceived in the US but she says it will create an interesting conversation depending on “how people are going to grapple with the magnitude of having someone like Bad Bunny on the stage.”

At a time when “the US is targeting Latinos and migrants and Spanish speakers or even those who are just perceived to be any of those things in a way that we haven’t seen in our lifetimes”, his visibility is powerful, Diaz said.

For Thomas, Bad Bunny’s music offered the perfect opportunity to take on the challenge of learning a new language.

“I love Spanish and I always wanted to learn it,” Thomas said. “So, this has been a fun introduction for me to finally hone in.”

Both Miller and Thomas said that learning Spanish, specifically Puerto Rican Spanish, in a short period of time has been a unique challenge.

Thomas said listening to Bad Bunny’s music casually is a different experience than learning the lyrics.

“Listening to his music is really fun,” Thomas said. “The amount of times I’ve pressed rewind just to get a phrase, I can’t even count.”

Miller said the hard part about learning the songs is that the Puerto Rican dialect tends to chop some words and it is very fast. Miller said if he hasn’t worked on understanding a song for days, he might forget the pronunciation and it’s hard to come back to it.

“It’s fun but then stressful because I am a type-A person, so that’s been hard, honestly,” Miller said. “I’m firing on all cylinders.”



Source link

Teacher of the Year faces charges of indecent behavior with juveniles

0

NEWYou can now listen to Fox News articles!

A Louisiana school “Teacher of the Year” who had been accused of inappropriate behavior with a former student has been arrested again on an additional charge.

Christie Oster, the 38-year-old Broussard Middle School Teacher of the Year, was previously arrested by the Lafayette Police Department on charges of carnal knowledge of a juvenile and indecent behavior with juveniles. Her bond was set for $50,000 on those counts. She was arrested again this week on a new charge of indecent behavior with juveniles, KADN reported. A bond was set for $10,000 on that count.

“We actually work in conjunction with the Lafayette Police Department,” Capt. Zac Gerard of the Broussard Police Department in Louisiana told Fox News Digital during a phone call.

FORMER LOUISIANA HIGH SCHOOL TEACHER INDICTED FOR ALLEGEDLY TRYING TO ENTICE STUDENT INTO SEX

Christie Oster mugshot overlaid on top of image of Broussard Middle School

Christie Oster’s mugshot over an image of Broussard Middle School (Lafayette Parish Sheriff’s Office; KADN)

He explained that an additional charge of indecent behavior with juveniles was added based off of what had occurred within his department’s jurisdiction.

Authorities indicated that the accused woman turned herself in to the Lafayette Parish Sheriff’s Office on the warrant, the outlet reported.

LOUISIANA AUTHORITIES, FEDERAL AGENTS NAB ALL 8 INMATES WHO ESCAPED IN JAILBREAK AFTER MASSIVE MANHUNT

Handcuffs and gun on police belt

A police officer patrols the street in Vail, Colo. ( Robert Alexander/Getty Images)

Oster had been arrested last week, according to the outlet, which added that the Lafayette Police Department indicated that the victim was one of the woman’s former students.

She was placed on leave by the Lafayette Parish School System, the report said.

NAKED WOMAN ALLEGEDLY ASSAULTS DEPUTY WHILE INTOXICATED, CLAIMS SHE WAS ‘TRYING TO BE A MERMAID’

Police car lights

Generic stock image of police car lights shot Sept. 8, 2020.  (Stephen M. Katz/South Florida Sun-Sentinel/Tribune News Service via Getty Images)

CLICK HERE TO GET THE FOX NEWS APP

She had been honored as the middle school’s “Teacher of the Year” for the 2025-2026 school year, according to the outlet.



Source link

Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access

0

Cybersecurity researchers have discovered malicious Google Chrome extensions that come with capabilities to hijack affiliate links, steal data, and collect OpenAI ChatGPT authentication tokens.

One of the extensions in question is Amazon Ads Blocker (ID: pnpchphmplpdimbllknjoiopmfphellj), which claims to be a tool to browse Amazon without any sponsored content. It was uploaded to the Chrome Web Store by a publisher named “10Xprofit” on January 19, 2026.

“The extension does block ads as advertised, but its primary function is hidden: it automatically injects the developer’s affiliate tag (10xprofit-20) into every Amazon product link and replaces existing affiliate codes from content creators,” Socket security researcher Kush Pandya said.

Further analysis has determined that Amazon Ads Blocker is part of a larger cluster of 29 browser add-ons that target several e-commerce platforms like AliExpress, Amazon, Best Buy, Shein, Shopify, and Walmart. The complete list is as follows –

  • AliExpress Invoice Generator (FREE) – AliInvoice™️ (10+ Templates) (ID: mabbblhhnmlckjbfppkopnccllieeocp)
  • AliExpress Price Tracker – Price History & Alerts (ID: loiofaagnefbonjdjklhacdhfkolcfgi)
  • AliExpress Quick Currency & Price Converter (ID: mcaglpclodnaiimhicpjemhcinjfnjce)
  • AliExpress Deals Countdown – Flash Sale Timer (ID: jmlgkeaofknfmnbpmlmadnfnfajdlehn)
  • 10Xprofit – Amazon Seller Tools (FBA & FBM) (ID: ahlnchhkedmjbdocaamkbmhppnligmoh)
  • Amazon Ads Blocker (ID: pnpchphmplpdimbllknjoiopmfphellj)
  • Amazon ASIN Lookup 10xprofit (ID: ljcgnobemekghgobhlplpehijemdgcgo)
  • Amazon Search Suggestion (ID: dnmfcojgjchpjcmjgpgonmhccibjopnb)
  • Amazon Product Scraper 10xprofit (ID: mnacfoefejolpobogooghoclppjcgfcm)
  • Amazon Quick Brand Search (ID: nigamacoibifjohkmepefofohfedblgg)
  • Amazon Stock Checker 999 (ID: johobikccpnmifjjpephegmfpipfbfme)
  • Amazon Price History Saver (ID: kppfbknppimnoociaomjcdgkebdmenkh)
  • Amazon ASIN Copy (ID: aohfjaadlbiifnnajpobdhokecjokhab)
  • Amazon Keyword Cloud Generator (ID: gfdbbmngalhmegpkejhidhgdpmehlmnd)
  • Amazon Image Downloader (ID: cpcojeeblggnjjgnpiicndnahfhjdobd)
  • Amazon Negative Review Hider (ID: hkkkipfcdagiocekjdhobgmlkhejjfoj)
  • Amazon Listing Score Checker (ID: jaojpdijbaolkhkifpgbjnhfbmckoojh)
  • Amazon Keyword Density Searcher (ID: ekomkpgkmieaaekmaldmaljljahehkoi)
  • Amazon Sticky Notes (ID: hkhmodcdjhcidbcncgmnknjppphcpgmh)
  • Amazon Result Numbering (ID: nipfdfkjnidadibpbflijepbllfkokac)
  • Amazon Profit Calculator Lite (ID: behckapcoohededfbgjgkgefgkpodeho)
  • Amazon Weight Converter (ID: dfnannaibdndmkienngjahldiofjbkmj)
  • Amazon BSR Fast View (ID: nhilffccdbcjcnoopblecppbhalagpaf)
  • Amazon Character Count & Seller Tools (ID: goikoilmhcgfidolicnbgggdpckdcoam)
  • Amazon Global Price Checker (ID: mjcgfimemamogfmekphcfdehfkkbmldn)
  • BestBuy Search By Image (ID: nppjmiadmakeigiagilkfffplihgjlec)
  • SHEIN Search By Image (ID: mpgaodghdhmeljgogbeagpbhgdbfofgb)
  • Shopify Search By Image (ID: gjlbbcimkbncedhofeknicfkhgaocohl)
  • Walmart Search By Image (ID: mcaihdkeijgfhnlfcdehniplmaapadgb)

While “Amazon Ads Blocker” offers the advertised functionality, it also embeds malicious code that scans all Amazon product URL patterns for any affiliate tag without requiring any user interaction, and replaces it with “10xprofit-20” (or “_c3pFXV63” for AliExpress). In cases where there are no tags, the attacker’s tag is appended to each URL.

Socket also noted that the extension listing page on the Chrome Web Store makes misleading disclosures, claiming that the developers earn a “small commission” every time a user makes use of a coupon code to make a purchase. 

Affiliate links are widely used across social media and websites. They refer to URLs containing a specific ID that enables tracking of traffic and sales to a particular marketer. When a user clicks this link to buy the product, the affiliate earns a cut of the sale.

Due to the extensions searching for existing tags and replacing them, social media content creators who share Amazon product links with their own affiliate tags lose commissions when users who have installed the add-on click those links.

This amounts to a violation of Chrome Web Store policies, as they require extensions using affiliate links to accurately divulge how the program works, require user action before each injection, and never replace existing affiliate codes.

“The disclosure describes a coupon/deal extension with user-triggered reveals. The actual product is an ad blocker with automatic link modification,” Pandya explained. “This mismatch between disclosure and implementation creates false consent.”

“The extension also violates the Single Purpose policy by combining two unrelated functions (ad blocking and affiliate injection) that should be separate extensions.”

The identified extensions have also been found to scrape product data and exfiltrate it to “app.10xprofit[.]io,” with those focusing on AliExpress serving bogus “LIMITED TIME DEAL” countdown timers on product pages to create a false sense of urgency and rush them into making purchases so as to earn commissions on affiliate links.

“Extensions that combine unrelated functionality (ad blocking, price comparison, coupon finding) with affiliate injection should be treated as high-risk, particularly those with disclosures that don’t match the actual code behavior,” Socket said.

The disclosure comes as Broadcom-owned Symantec flagged four different extensions that have a combined user base exceeding 100,000 users and are designed to steal data –

  • Good Tab (ID: glckmpfajbjppappjlnhhlofhdhlcgaj), which grants full clipboard permissions to an external domain (“api.office123456[.]com”) to enable remote clipboard-read and clipboard-write permissions
  • Children Protection (ID: giecgobdmgdamgffeoankaipjkdjbfep), which implements functionality to harvest cookies, inject ads, and execute arbitrary JavaScript by contacting a remote server
  • DPS Websafe (ID: bjoddpbfndnpeohkmpbjfhcppkhgobcg), which changes the default search to one under their control to capture search terms entered by users and potentially route them to malicious websites
  • Stock Informer (ID: beifiidafjobphnbhbbgmgnndjolfcho), which is susceptible to a years-old cross-site (XSS) vulnerability in the Stockdio Historical Chart WordPress plugin (CVE-2020-28707, CVSS score: 6.1) that could allow a remote attacker to execute JavaScript code

“While browser extensions can provide a wide range of handy tools to help us achieve more online, much care needs to be taken when choosing to install them, even when installing from trusted sources,” researchers Yuanjing Guo and Tommy Dong said.

Rounding off the list of malicious extensions is another network of 16 add-ons (15 on the Chrome Web Store and one on the Microsoft Edge Add-ons marketplace) that are designed to intercept and steal ChatGPT authentication tokens by injecting a content script into chatgpt[.]com. Cumulatively, the extensions were downloaded about 900 times, according to LayerX.

The extensions are assessed to be part of a coordinated campaign due to overlaps in source code, icons, branding, and descriptions –

  • ChatGPT folder, voice download, prompt manager, free tools – ChatGPT Mods (ID: lmiigijnefpkjcenfbinhdpafehaddag)
  • ChatGPT voice download, TTS download – ChatGPT Mods (ID: obdobankihdfckkbfnoglefmdgmblcld)
  • ChatGPT pin chat, bookmark – ChatGPT Mods (ID: kefnabicobeigajdngijnnjmljehknjl)
  • ChatGPT message navigator, history scroller – ChatGPT Mods (ID: ifjimhnbnbniiiaihphlclkpfikcdkab)
  • ChatGPT model switch, save advanced model uses – ChatGPT Mods (ID: pfgbcfaiglkcoclichlojeaklcfboieh)
  • ChatGPT export, Markdown, JSON, images – ChatGPT Mods (ID: hljdedgemmmkdalbnmnpoimdedckdkhm)
  • ChatGPT Timestamp Display – ChatGPT Mods (ID: afjenpabhpfodjpncbiiahbknnghabdc)
  • ChatGPT bulk delete, Chat manager – ChatGPT Mods (ID: gbcgjnbccjojicobfimcnfjddhpphaod)
  • ChatGPT search history, locate specific messages – ChatGPT Mods (ID: ipjgfhcjeckaibnohigmbcaonfcjepmb)
  • ChatGPT prompt optimization – ChatGPT Mods (ID: mmjmcfaejolfbenlplfoihnobnggljij)
  • Collapsed message – ChatGPT Mods (ID: lechagcebaneoafonkbfkljmbmaaoaec)
  • Multi-Profile Management & Switching – ChatGPT Mods (ID: nhnfaiiobkpbenbbiblmgncgokeknnno)
  • Search with ChatGPT – ChatGPT Mods (ID: hpcejjllhbalkcmdikecfngkepppoknd)
  • ChatGPT Token counter – ChatGPT Mods (ID: hfdpdgblphooommgcjdnnmhpglleaafj)
  • ChatGPT Prompt Manager, Folder, Library, Auto Send – ChatGPT Mods (ID: ioaeacncbhpmlkediaagefiegegknglc)
  • ChatGPT Mods – Folder Voice Download & More Free Tools (ID: jhohjhmbiakpgedidneeloaoloadlbdj)

With artificial intelligence (AI)-related extensions becoming increasingly common in enterprise workflows, the development highlights an emerging attack surface where threat actors weaponize the trust associated with popular AI brands to deceive users into installing them.

Because such tools often require elevated execution context within the browser and have access to sensitive data, seemingly harmless extensions can become a lucrative attack vector, permitting adversaries to obtain persistent access without the need for exploiting security flaws or resorting to other methods that may trigger security alarms.

“Possession of such tokens provides account-level access equivalent to that of the user, including access to conversation history and metadata,” security researcher Natalie Zargarov said. “As a result, attackers can replicate the users’ access credentials to ChatGPT and impersonate them, allowing them to access all of the user’s ChatGPT conversations, data, or code.”

Browsers Become a Lucrative Attack Vector 

The findings also coincide with the emergence of a new malware-as-a-service toolkit called Stanley that’s being peddled on a Russian cybercrime forum for between $2,000 and $6,000, and allows crooks to generate malicious Chrome browser extensions that can be used to serve phishing pages within an HTML iframe element while still showing the legitimate URL in the address bar.

Customers of the tool gain access to a C2 panel for managing victims, configuring spoofed redirects, and sending fake browser notifications. Those who are willing to spend $6,000 get a guarantee that any extension they create using the kit will pass Google’s vetting process for the Chrome Web Store.

These extensions take the form of innocuous note-taking utilities to fly under the radar. But their malicious behavior is activated when the user navigates to a website of interest to the attacker, such as a bank, at which point a full-screen iframe containing the phishing page is overlaid, while leaving the browser’s URL bar intact. This visual deception creates a defensive blind spot that can dupe even vigilant users into entering their credentials or sensitive information on the page.

As of January 27, 2026, the service appears to have vanished – likely prompted by the public disclosure – but it’s very much possible that it can resurface under a different name in the future.

“Stanley provides a turnkey website-spoofing operation disguised as a Chrome extension, with its premium tier promising guaranteed publication on the Chrome Web Store,” Varonis researcher Daniel Kelley noted earlier this week. “BYOD policies, SaaS-first environments, and remote work have made the browser the new endpoint. Attackers have noticed. Malicious browser extensions are now a primary attack vector.”



Source link

‘Treacherous assassination’: Who was Saif al-Islam Gaddafi? | Muammar Gaddafi

0

NewsFeed

Saif al-Islam Gaddafi, former Libyan leader Muammar Gadaffi’s most prominent son, and his number 2 between 2000 and 2011, was killed by “four masked men” in his Zintan home in what his political team blasted as a “cowardly and treacherous assassination”. But who was he?



Source link

Trump orders 700 immigration officers to leave Minnesota | US News

0

President Trump has said he’s ordered hundreds of immigration officers to leave Minnesota – although around 2,000 will remain in the state.

The pullback comes amid fury over the deaths of two protesters in altercations with federal officials.

The president’s border czar, Tom Homan, announced the move on Wednesday and said about 700 would leave the state immediately after local officials agreed to hand over arrested immigrants.

Renee Good and Alex Pretti were shot dead in separate incidents last month in Minneapolis, Minnesota’s biggest city, as they protested against the actions of masked agents ordered in by the Trump administration.

Thousands of federal agents were sent to the state in January. Pic: Reuters
Image: Thousands of federal agents were sent to the state in January. Pic: Reuters
Mr Pretti, a nurse, was shot dead. Pic: AP
Image: Mr Pretti, a nurse, was shot dead. Pic: AP

Local officials have attacked heavy-handed tactics that have seen ICE (Immigration and Customs Enforcement) officers grab some people off the street and have made it clear they want them out.

President Trump confirmed to Sky’s US partner, NBC News, he had approved the order to cut numbers, adding: “But it didn’t come from me because I just wanted to do it.

“We have – we are waiting for them to release prisoners, give us the murderers that they’re holding and all of the bad people, drug dealers, all of the bad people.”

Mr Trump added: “We allowed in our country, I say, 25 million people with an open-border policy for four years under Biden, and that group the autopen group, I call them.

“We allowed to come into our country people the likes of which no country would accept. And we’re getting ’em out.”

Moment five-year old held by ICE goes home

There have been frequent protests against ICE's presence. Pic: Reuters
Image: There have been frequent protests against ICE’s presence. Pic: Reuters

However, Mr Trump also continued a recent slight softening in some of his language, telling NBC News “maybe we can use a little bit of a softer touch – but you still have to be tough”.

Minnesota governor Tim Walz and Minneapolis mayor Jacob Frey said the cut in numbers was a start – but that the whole operation needed to end quickly.

“We need a faster and larger drawdown of forces, state-led investigations into the killings of Alex Pretti and Renee Good, and an end to this campaign of retribution,” the Democrat governor posted on social media.

Such a hope currently looks unrealistic however.

In his announcement on Wednesday, border chief Mr Homan stressed the effort to remove illegal aliens would continue at pace.

“Let me be clear, ​President Trump fully intends to achieve mass deportations during this administration, and immigration enforcement actions will continue every day throughout this country,” he said.

Vice president JD Vance also said the officers being pulled out were mainly protecting those carrying out arrests.

“We’re not drawing down the immigration enforcement,” he said in an interview on The Megyn Kelly Show.

The mood in Trump country after Minneapolis killings

The operation in Minnesota – Operation Metro Surge – ramped up in January as President Trump looked to fulfill election promises to deport illegal immigrants and people without proper documentation.

ICE, part of the Department of Homeland Security, have also been deployed in cities such as Los Angeles and Chicago, where their presence has also attracted anger from officials and significant protests.



Source link

Illegal immigrant kills motorist in SoCal police chase

0

NEWYou can now listen to Fox News articles!

EXCLUSIVE: An illegal immigrant from Colombia killed a motorist in Southern California last month during a police chase, authorities said. 

Darwin Felipe Bahamon Martinez, 21, was caught entering the United States near San Diego in 2023 and released by the Biden administration, U.S. Immigration and Customs Enforcement (ICE) said. 

“Bahamon Martinez illegally entered the U.S. near Chula Vista, California, in August 2023,” a statement from ICE Los Angeles field office leadership said. “He was released into the U.S. under the Biden administration’s so-called ‘catch-and-release’ policies, but if that hadn’t happened, the innocent 59-year-old driver he allegedly killed may still be alive today.”

DHS HONORS ILLINOIS WOMAN WHOSE CORPSE WAS ALLEGEDLY ABUSED BY ILLEGAL IMMIGRANT FREED UNDER SANCTUARY LAWS

Martinez was driving a Jeep Gladiator in Anaheim on Jan. 21 when police officers initiated a traffic stop for reckless driving. When the officers approached the Jeep on foot, Martinez sped away, authorities said. 

A brief chase ensued before the Jeep collided with a Honda driven by a 59-year-old man in the neighboring city of Placentia. 

The driver was pronounced dead at the scene. 

Another driver, an 83-year-old woman, was taken to a hospital and treated for minor injuries. 

MAJOR COUNTY SHERIFF REJECTS ICE DETAINER ON ILLEGAL IMMIGRANT WHO KILLED YOUNG BOY IN HIT-AND-RUN

Anaheim police cruiser

The Anaheim Police Department’s police vehicle.  ( Jeff Gritchen/MediaNews Group/Orange County Register via Getty Images)

Bahamon Martinez is being held in the Orange County Jail while awaiting criminal proceedings on his homicide charge. ICE lodged an immigration detainer against him Jan. 22.

However, because of California’s sanctuary state laws, local authorities are not compelled to cooperate with ICE to transfer illegal immigrants charged or convicted of crimes into federal custody. 

ICE Agent

California school board members believe there is a lot of “fearmongering” happening over immigration enforcement as teachers unions and major city school districts are scolding U.S. Immigration and Customs Enforcement (ICE). (Getty Images)

“If local officials in Gavin Newsom’s sanctuary California choose to release Bahamon Martinez into the community, they will put ALL Californians at risk,” ICE said in a news release. “California must honor our immigration detainer. Otherwise, ICE will be forced to re-arrest this criminal illegal alien at-large.”

In jurisdictions with sanctuary laws, ICE officers typically have to go into communities to look for illegal immigrants targeted for deportation. The agency has called for greater cooperation with local authorities amid confrontations between federal officers and agitators in Minnesota, where local officials have accused ICE of terrorizing neighborhoods. 

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Meanwhile, critics of sanctuary laws say such laws are responsible for releasing dangerous criminals back onto the street.



Source link