meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

Your AI sidekick might be a spy. [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

Tech News, Daily News, News, Technology

4.81.1K Ratings

🗓️ 14 March 2026

⏱️ 24 minutes

🧾️ Download transcript

Summary

This week, we are joined by Or Eshed, Co-Founder and CEO from LayerX Security, discussing their work on "How We Discovered A Campaign of 16 Malicious Extensions Built to Steal ChatGPT Accounts." Researchers uncovered a coordinated campaign of 16 malicious browser extensions posing as ChatGPT productivity tools while secretly stealing user accounts. The extensions intercept ChatGPT session authentication tokens and send them to attacker-controlled servers, allowing threat actors to impersonate users and access their conversations, files, and connected services like Google Drive or Slack. The findings highlight how AI-focused browser extensions are creating a new attack surface, emphasizing the need for organizations to closely monitor and restrict third-party AI tools. The research can be found here: ⁠⁠⁠How We Discovered A Campaign of 16 Malicious Extensions Built to Steal ChatGPT Accounts Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the Cyberwire Network, powered by N2K.

0:10.4

If you're defending a network today, there's a simple question worth asking.

0:16.8

What does the attackers see when they look at your organization?

0:20.6

Nord Stellar helps answer that.

0:22.9

Nord Stellar is a threat exposure management platform that gives security teams visibility into

0:28.1

external risks, including leaked credentials, active session tokens, impersonation attempts,

0:33.9

and exposed assets across the surface web and the dark web.

0:38.4

It's built to help organizations detect the consequences of breaches early, before attackers

0:44.0

turn access into action.

0:46.2

From monitoring for InfoStealer malware logs, to identifying cybersquoting and brand abuse,

0:52.4

Nordsteller helps teams focus on the threats that actually matter.

0:56.7

Executives get clear, actionable insights tied to business risk. Security teams get real-time

1:02.2

alerts and one of the largest deep and dark web intelligence pools in the industry. Cybercriminals

1:08.3

may already be looking for your weak spots. Don't make it easy for them.

1:12.5

Be the one that's prepared. Defend your business with Nordsteller. Use the code Cyberwire 10 to unlock your

1:19.7

exclusive discount. Go to Nordstellar.com slash Cyberwire Daily and learn more.

1:40.5

Thank you.com slash CyberWire Daily and learn more. Hello everyone and welcome to the CyberWire Research Saturday.

1:45.6

I'm Dave Bittner, and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard problems and protecting

1:50.8

ourselves in a rapidly evolving cyberspace. Thanks for joining us.

2:06.8

I think what was interesting here is the scope and motivation of the attacker behind this,

2:09.8

which is a very well-coordinated and orchestrated campaign.

2:13.1

That's all its purpose is actually to steal Chachapiti accounts.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.