Chrome moves to weekly security patches, fake IT calls on Teams end in ransomware, and cheap streaming sticks resell your internet
Chrome is patching far more often, and the fix only lands when you restart
Google says the last two Chrome releases, 149 and 150, fixed 1,072 security bugs between them — more than the previous 23 Chrome releases combined. The jump comes from AI systems that now hunt for flaws across the Chrome codebase every 24 hours and draft candidate fixes for most of what they find. One of the finds was a sandbox-escape flaw that had been sitting in the code for more than 13 years. Google is moving Chrome to a two-week major release cycle with weekly security updates, is piloting two security releases a week, and is building "dynamic patching" that would apply a fix without restarting the browser. BleepingComputer has the release details. Why it matters: faster patching only protects you if the patch actually installs, and Chrome downloads updates in the background but does not apply them until the browser restarts. If you are the sort of person who leaves Chrome open for weeks with forty tabs, you may be running month-old code right now. Today's action: open the three-dot menu → Help → About Google Chrome, let it check, and click Relaunch if it offers. Then make relaunching a weekly habit rather than a monthly one — Chrome restores your tabs.
Attackers are calling employees on Teams pretending to be the IT helpdesk
Security firm Sophos published details of a campaign it tracks as STAC4749 that targeted dozens of North American organizations between February and June 2026. The pattern is consistent: an outside Microsoft Teams account calls an employee posing as internal IT support, using IT-themed lookalike domains and invented staff names. The caller talks the employee into starting a remote support session — early on through Microsoft's built-in Quick Assist tool, later through a commercial cloud support tool — and once connected installs a backdoor, disguises it as an audio driver, and adds second and third remote-access tools so the access survives cleanup. In several cases the intrusions ended in Chaos ransomware. Roughly 95% of the targets were in Canada and the United States, in services, manufacturing, energy, and construction. BleepingComputer reports one intrusion went from first contact to fully encrypted files in under 17 hours. Why it matters: no software flaw is involved here — the whole attack runs on an employee being helpful to someone who sounded like IT. That makes it a policy problem you can actually fix. Make it a stated rule this week that nobody grants remote access to anyone who contacted them first, no matter how urgent the call sounds: hang up, and call back on a number or chat you already had. If your business does not use Quick Assist for support, ask whoever manages your computers to disable it, and turn off calls and chats from outside your organization in Teams if you do not need them.
Cheap streaming sticks are renting out your internet connection
Security researchers at Bitsight found that a category of inexpensive Android streaming boxes and sticks — sold openly through major retailers — quietly runs two businesses on the side, according to a detailed writeup at Krebs on Security. When your TV is on, the device rents your home internet connection out as a "residential proxy," routing strangers' traffic through your address. When the TV is off, it impersonates Samsung, Vivo, Huawei, and Xiaomi phones and clicks ads on automatically generated websites — a scheme the researchers estimate earns roughly $50,000 a day. Researchers observed the behavior by taking over an expired domain the devices were still calling home to. The devices run unofficial versions of Android rather than the licensed Android TV software, and the FBI has previously warned about this class of hardware. Why it matters: other people's traffic leaving your home or shop IP address is not a hypothetical problem — it can get your address blocked by services you use, and it ties your connection to activity you had nothing to do with. If you are buying: stick to known brands and check the listing says the device is Play Protect certified Android TV, or choose a mainstream platform like Roku, Apple TV, or Fire TV. If you already own a no-name box, the safe move is to unplug it and use the apps built into your TV instead.
The FTC sued a telehealth company over tracking code on its health pages
The Federal Trade Commission, joined by Utah and California, sued Hims & Hers on July 29 over how the telehealth company handled customer health information. The complaint alleges the company placed pixel-sized tracking code on its site that captured what customers were seeking care for and sent it to advertising platforms, while telling those customers their information was kept private. TechCrunch reports the recipients named include Meta, Snap, Microsoft, Pinterest, Reddit, and X, and that the categories involved sexual wellness, mental health, and weight loss. The complaint also alleges the company charged for prescriptions almost immediately after an intake form was submitted and made subscriptions hard to cancel. The company says its privacy policy makes clear that users may choose how their data is used, and says it will defend the case. Regulators have brought similar cases against several other telehealth and health app companies. Why it matters: the mechanism here is the ordinary marketing pixel that sits on most commercial websites, including probably yours. It reports what page a visitor was on, and on a health, legal, or financial intake page that page name is the sensitive information. If you run a site, ask whoever maintains it for a list of every tracking script and exactly which pages load it, then remove those scripts from intake forms, checkout, and anything behind a login. As a customer, assume a health or finance site's ad trackers know which pages you visited, and use a browser that blocks third-party trackers when the subject is private.
OpenAI cut prices on its two cheaper GPT-5.6 tiers
OpenAI reduced what it charges for two of the three models in its GPT-5.6 family: the fastest and cheapest tier, Luna, by 80%, and the mid-range Terra by 20%, with the top Sol tier unchanged. Reported figures put Luna at 20 cents per million words of input and $1.20 per million of output, down from $1 and $6, and Terra at $2 and $12, down from $2.50 and $15. The company also said the lower prices are reflected in how usage counts against paid subscriptions in Codex and ChatGPT Work, so the same subscription now covers more work before hitting a limit. The family only became generally available on July 9, putting the price change three weeks into its commercial life. OpenAI attributed the cuts to efficiency gains in how it runs the models and published its own announcement here. Why it matters: if you pay for AI by usage — directly, or through a software vendor that bills you for "AI credits" — the underlying cost of the cheaper models just dropped sharply, and that does not automatically reach your invoice. Two things worth doing: check which model your AI tool actually defaults to, since the cheapest tier is now close to free for routine work like summarizing and drafting, and if a vendor priced an AI feature for you based on per-use costs, this is a reasonable moment to ask them to revisit the number.