Google's Chrome browser is rolling out Device Bound Session Credentials (DBSC) to Windows users, with macOS support coming soon. This new feature aims to prevent session theft by cryptographically linking user sessions to a specific device. Previously, stolen session cookies could grant attackers access to accounts without needing passwords, but DBSC makes these exfiltrated cookies unusable, shifting defenses from reactive detection to proactive prevention.

Google's Chrome browser is introducing a new security feature called Device Bound Session Credentials (DBSC) for Windows users, with support for macOS planned for the near future. This development is designed to significantly enhance protection against session hijacking, a common attack vector where attackers gain unauthorized access to user accounts by stealing session cookies.
Traditionally, if an attacker managed to obtain a user's session cookie, they could bypass the need for a password and impersonate the user, accessing their accounts. This often involved sophisticated phishing attacks or malware that could extract these cookies from a user's browser.
DBSC aims to neutralize this threat by creating a cryptographic link between a user's active session and the specific device they are using. This means that even if a session cookie is successfully stolen and transferred to another machine, it will be rendered useless.
The core principle behind DBSC is to ensure that session credentials are bound to the hardware of the device. This binding is achieved through cryptographic means, making it extremely difficult, if not impossible, for an attacker to use a stolen cookie on a different system.
This shift represents a move from a reactive security posture, which relies on detecting and responding to breaches after they occur, to a more proactive approach. By making stolen session cookies inherently unusable outside of their original device, DBSC aims to prevent session theft before it can be exploited.
The implementation of DBSC is expected to bolster the security of online accounts by adding a robust layer of protection against a prevalent attack method. Users will not need to take any specific action to enable this feature, as it will be integrated into the Chrome browser.
The rollout to Windows users is already underway, and the upcoming support for macOS indicates a broader strategy to secure user sessions across different platforms. This feature is a significant step forward in browser security, addressing a long-standing vulnerability in how online sessions are managed and protected.
By cryptographically tying sessions to the device, Chrome is making it substantially harder for attackers to leverage stolen cookies for malicious purposes. This proactive measure is designed to safeguard user data and privacy by rendering exfiltrated session information inert when attempted on unauthorized hardware.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed