Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chrome Extension Secretly Collects AI Interactions

Chrome Extension Secretly Collects AI Interactions

Posted on July 28, 2026 By CWS

A Chrome extension, installed by around 100,000 users, is discreetly capturing inputs and responses across nine leading AI platforms. Despite its listing claiming no data collection, “Prompt Optimizer – SecondBrain” (ID: aajjgdpofhhcjmjoombjdfepplndhgcp, version 2.3.1) is actively recording interactions on platforms like ChatGPT, Claude, and Gemini.

Unveiling the Hidden Monitoring

Unlike traditional spyware, this extension activates without user input post-installation. Immediately upon loading, it modifies internal settings to assume user consent, enabling data collection and disabling protections. This operation raises significant privacy concerns as it continues to monitor user activity across all browser tabs.

The extension’s capture mechanism is embedded within a file deceptively named chatgpt_context_fetch_diagnostics.js. It overrides key browser functions to intercept network traffic, allowing it to operate across all nine AI platforms. This includes replacing functions like window.fetch and XMLHttpRequest, effectively capturing data before it reaches any AI service.

Security Risks in Corporate Environments

In corporate settings, the extension poses severe risks, particularly targeting Microsoft 365’s Copilot. By intercepting SignalR protocol frames, it extracts internal communications, creating potential data breaches. Organizations allowing this extension face the risk of sensitive information leaking outside their secure boundaries.

The data collected is encrypted and sent to ingest.secondbrain.is, but the encryption key is managed by SecondBrain, enabling them to decrypt all captured data. This capability has been confirmed through decrypted traffic analysis, revealing serious discrepancies between stated policies and actual data handling practices.

Enterprise Measures Against Data Breaches

To mitigate these risks, security teams should take immediate action. Blocking the extension by ID using Google Chrome and Microsoft Edge policies is crucial. Additionally, monitoring network logs for connections to SecondBrain’s servers can help identify unauthorized data transmissions.

For enterprises utilizing Microsoft 365 Copilot, treating this extension as a significant threat is essential. Rather than viewing it as a minor privacy concern, organizations should acknowledge its potential for extensive data exfiltration and adjust their security measures accordingly.

Overall, the discrepancy between SecondBrain’s privacy claims and its technical practices underlines the importance of rigorous security audits and proactive monitoring of browser extensions and network activities to protect sensitive data.

Cyber Security News Tags:AI platforms, AI security, Chrome extension, Cybersecurity, data collection risks, data privacy, enterprise security, Microsoft 365, privacy policy, SecondBrain

Post navigation

Previous Post: Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks
Next Post: Critical NGINX Vulnerability Enables Remote Code Execution

Related Posts

CloudEyE MaaS Downloader and Cryptor Infects 100,000+ Users Worldwide CloudEyE MaaS Downloader and Cryptor Infects 100,000+ Users Worldwide Cyber Security News
Access to Anthropic AI Models Restricted by U.S. Government Access to Anthropic AI Models Restricted by U.S. Government Cyber Security News
Critical SonicWall Vulnerability Exploited by Hackers Critical SonicWall Vulnerability Exploited by Hackers Cyber Security News
Hundreds of WordPress Websites Hacked By VexTrio Viper Group to Run Massive TDS Services Hundreds of WordPress Websites Hacked By VexTrio Viper Group to Run Massive TDS Services Cyber Security News
China-Linked Group Targets Asian Infrastructure with ShadowPad China-Linked Group Targets Asian Infrastructure with ShadowPad Cyber Security News
VMware ESXi, Firefox, Red Hat Linux & SharePoint 0-Day Vulnerabilities Exploited VMware ESXi, Firefox, Red Hat Linux & SharePoint 0-Day Vulnerabilities Exploited Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical NGINX Vulnerability Enables Remote Code Execution
  • Chrome Extension Secretly Collects AI Interactions
  • Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks
  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical NGINX Vulnerability Enables Remote Code Execution
  • Chrome Extension Secretly Collects AI Interactions
  • Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks
  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark