Google Chrome adds session cookie theft protection for all users
2026-05-29T13:23:34Z•720c86e1865582662723fec3da3b61c771a35b80693b663d65ff816d2fbc577e
ai-generated-luresai-model-securityandroid-ratanthropic-mythosauthentication-bypassbtmobcarnival-corporationcharter-communicationschrome-dbsccve-2026-35616data-breachdevice-bound-session-credentialsekz-infostealerfbififa-fraudforticlient-emsgogs-zero-daygreyvibepersonal-data-theftphishing-builderpolymarket-insider-tradingrcesession-cookie-theftshinyhunterssiem-msps
What happened
A roundup of security news: Google Chrome has enabled Device Bound Session Credentials (DBSC) broadly to mitigate session-cookie theft and account takeovers. Multiple large data breaches and extortion incidents tied to the ShinyHunters gang affect major victims (Charter ~4.9M accounts, Carnival ~6M). A North Carolina man was sentenced over selling data on 7M elderly Americans; other legal actions include sentences for a Romanian hacker and a sextortionist, and a Google engineer charged with Polymarket insider trading. Active threats and vulnerabilities include exploitation of an authentication
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 720c86e1865582662723fec3da3b61c771a35b80693b663d65ff816d2fbc577e
- Enrichment time
- 2026-05-29T13:23:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.