# Socket Weekly: OpenAI Announces GPT-5.4-Cyber

Canonical: https://brew.new/browse/templates/email/pt1_k97pd6wg5vhybqd4gk02tzazdh8e5q60

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: OpenAI Announces GPT-5.4-Cyber](https://cdn.brew.new/email-preview-2398d667d149ab0f-tracking_r57me2j9ac7mkkeam7jrt4wejn8dtrkb-1789015364096.png)

## Email content

socket-weekly-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared C2 Infrastructure

Most users have no real visibility into what their browser extensions are doing. This week, we uncovered a campaign spanning 108 extensions and roughly 20,000 Chrome Web Store installs, all tied to the same C2 infrastructure. These extensions stole Google account data, hijacked Telegram Web sessions, and gave operators a backdoor into victims’ browsers.

MORE NEWS

NIST Officially Stops Enriching Most CVEs as Vulnerability Volume Skyrockets

NIST has officially stopped enriching most CVEs in the National Vulnerability Database, conceding it can no longer keep up with the volume of submissions. Going forward, the NVD will focus on vulnerabilities tied to CISA’s KEV catalog, federal government systems, and software deemed critical under Executive Order 14028. Most other CVEs will be dumped into a “Not Scheduled” bucket without the CVSS and CPE data security teams need to prioritize and map affected software.

OpenAI Announces GPT-5.4-Cyber for Defensive Security Work

OpenAI says it is preparing for more capable models in the months ahead by fine-tuning systems specifically for defensive cybersecurity use cases, starting with GPT-5.4-Cyber, a more cyber-permissive variant of GPT-5.4. The announcement also introduced new Cybersecurity Grant Program recipients, including Socket, Semgrep, Calif, and Trail of Bits, with grant support paired with access to more cyber-permissive frontier models for qualified defenders.

MORE WORTH READING

Vercel April 2026 security incident

GitHub: Secret scanning pattern updates and product improvements

OpenSSF: Using Runtime Context to Win the Vulnerability Management Battle

Europol-supported global operation targets over 75,000 users engaged in DDoS attacks

AI Companies to Play Bigger Role in CVE Program, Says CISA

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97pd6wg5vhybqd4gk02tzazdh8e5q60)

[Browse email designs](https://brew.new/browse/templates)
