Tech News from Simmons Systems
  • Home
  • About
chrome

Chrome Adds Device-Bound Credentials to Block Session Cookie Theft

12 Aug 2026 • 1 min read

Google's Chrome browser introduces a powerful new feature called device-bound session credentials (DBSCs) that combats a growing method of account takeover. As users adopt stronger protections like two-factor authentication and passkeys, attackers increasingly shift to stealing session cookies instead. These cookies allow websites to remember logged-in users, and criminals exploit them by swiping the cookies and pasting them into their own browsers.

DBSCs counter this threat by tying session cookies directly to the physical device running the browser. Chrome generates a unique encryption key stored inside a hardware security fortress built into the machine. On Windows computers, this is the Trusted Platform Module (TPM), while Mac devices use the secure enclave. These hardware components isolate keys so they cannot be extracted or copied by malicious software.

When a user visits a website, the browser must send a version of the session cookie signed with the locally stored key. Since attackers lack physical access to the original device, stolen cookies become useless on their own machines. The feature is now available in recently released versions of Chrome for both Windows and macOS, offering what may be the strongest defense yet against infostealer malware and adversary-in-the-middle attacks.

Read More at the original source →

Data Broker Radaris Loses Its Domains in New Jersey Privacy Law Case

The consumer data broker Radaris loses control of its core web properties after a court orders radaris.com and more than a dozen other domains transferred to plaintiffs who sue under Daniel's Law, a New Jersey statute that lets law enforcement officials, judges, government personnel, and their families
17 Sep 2026 1 min read

Spain Receives First Reported Data Breach Carried Out by AI Agent

Spain's Data Protection Agency (AEPD) receives its first notification of a data breach allegedly carried out by an AI agent powered by a known large language model. The reporting organization says the agent searches for flaws, logs into systems, probes applications for additional vulnerabilities, and ultimately modifies personal
16 Sep 2026 1 min read

Cisco Rushes Patches as Actively Exploited ISE Zero-Day Bypasses Authentication

Cisco is urging customers to patch a maximum-severity zero-day vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products, warning that attackers are actively exploiting the flaw in the wild. The vulnerability, tracked as CVE-2026-76460, allows remote attackers to bypass authentication by sending a crafted request
16 Sep 2026 1 min read
Tech News from Simmons Systems © 2026
  • Sign up