Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chrome Extension Secretly Collects AI Interactions

Chrome Extension Secretly Collects AI Interactions

Posted on July 28, 2026 By CWS

A Chrome extension, installed by around 100,000 users, is discreetly capturing inputs and responses across nine leading AI platforms. Despite its listing claiming no data collection, “Prompt Optimizer – SecondBrain” (ID: aajjgdpofhhcjmjoombjdfepplndhgcp, version 2.3.1) is actively recording interactions on platforms like ChatGPT, Claude, and Gemini.

Unveiling the Hidden Monitoring

Unlike traditional spyware, this extension activates without user input post-installation. Immediately upon loading, it modifies internal settings to assume user consent, enabling data collection and disabling protections. This operation raises significant privacy concerns as it continues to monitor user activity across all browser tabs.

The extension’s capture mechanism is embedded within a file deceptively named chatgpt_context_fetch_diagnostics.js. It overrides key browser functions to intercept network traffic, allowing it to operate across all nine AI platforms. This includes replacing functions like window.fetch and XMLHttpRequest, effectively capturing data before it reaches any AI service.

Security Risks in Corporate Environments

In corporate settings, the extension poses severe risks, particularly targeting Microsoft 365’s Copilot. By intercepting SignalR protocol frames, it extracts internal communications, creating potential data breaches. Organizations allowing this extension face the risk of sensitive information leaking outside their secure boundaries.

The data collected is encrypted and sent to ingest.secondbrain.is, but the encryption key is managed by SecondBrain, enabling them to decrypt all captured data. This capability has been confirmed through decrypted traffic analysis, revealing serious discrepancies between stated policies and actual data handling practices.

Enterprise Measures Against Data Breaches

To mitigate these risks, security teams should take immediate action. Blocking the extension by ID using Google Chrome and Microsoft Edge policies is crucial. Additionally, monitoring network logs for connections to SecondBrain’s servers can help identify unauthorized data transmissions.

For enterprises utilizing Microsoft 365 Copilot, treating this extension as a significant threat is essential. Rather than viewing it as a minor privacy concern, organizations should acknowledge its potential for extensive data exfiltration and adjust their security measures accordingly.

Overall, the discrepancy between SecondBrain’s privacy claims and its technical practices underlines the importance of rigorous security audits and proactive monitoring of browser extensions and network activities to protect sensitive data.

Cyber Security News Tags:AI platforms, AI security, Chrome extension, Cybersecurity, data collection risks, data privacy, enterprise security, Microsoft 365, privacy policy, SecondBrain

Post navigation

Previous Post: Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks

Related Posts

OpenAI Banned ChatGPT Accounts Used by Chinese Hackers to Develop Malware OpenAI Banned ChatGPT Accounts Used by Chinese Hackers to Develop Malware Cyber Security News
Critical Apple 0-Day Vulnerability Actively Exploited in the Wild Critical Apple 0-Day Vulnerability Actively Exploited in the Wild Cyber Security News
Top 10 ITDR Solutions to Watch in 2026 Top 10 ITDR Solutions to Watch in 2026 Cyber Security News
Researchers Detailed North Korean Threat Actors Technical Strategies to Uncover Illicit Access Researchers Detailed North Korean Threat Actors Technical Strategies to Uncover Illicit Access Cyber Security News
New Python Malware DEEP#DOOR Targets Windows Systems New Python Malware DEEP#DOOR Targets Windows Systems Cyber Security News
Attackers Hijacked 200+ Websites Exploiting Magento Vulnerability to Gain Root-level Access Attackers Hijacked 200+ Websites Exploiting Magento Vulnerability to Gain Root-level Access Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chrome Extension Secretly Collects AI Interactions
  • Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks
  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts
  • Claude AI Unveils Breakthrough in Cryptanalysis

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chrome Extension Secretly Collects AI Interactions
  • Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks
  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts
  • Claude AI Unveils Breakthrough in Cryptanalysis

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark