# Socket Weekly: 737 Fake VPN Extensions, NIST Bets on AI, Private…

Canonical: https://brew.new/browse/templates/email/pt1_k97wb5j4cxvbwx4r1vz6svwhwh8e4fds

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: 737 Fake VPN Extensions, NIST Bets on AI, Private…](https://cdn.brew.new/email-preview-b0e0315b4e84d85a-tracking_r57gaawxc2trz0jabkazpnex4s8dvzgc-1789057662366.png)

## Email content

socket-weekly-new-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

Socket's research team traced 737 free Chrome VPN extensions to a single operator, many posing as brands like Proton and NordVPN, all routing a user's full browser session through the operator's own proxies. Most target Russian speakers trying to reach blocked services, the people with the most to lose if that traffic is watched. The same operator sells a paid VPN service in Russia, and the free extensions funnel users toward it.

MORE NEWS

NIST Proposes AI-Enabled NVD Overhaul After Cutting Routine CVE Enrichment

NIST is asking the security community how AI should reshape the National Vulnerability Database, and has begun building a tool called V-etalon to enrich vulnerability data. The move follows NIST's decision earlier this year to stop routinely enriching most CVEs, which left the majority of new records without severity scores or affected-version data.

White House Authorizes Private Companies to Conduct Offensive Cyber Operations

A new presidential memorandum lets vetted U.S. security firms hack, surveil, and disrupt foreign cybercrime groups under government contract, going well beyond the malware analysis and attribution work they already do for law enforcement. Every operation needs written DOJ or DHS approval, though critics note the same firms would identify the threats, propose the operations, and get paid to carry them out.

MORE WORTH READING

ETSI launches approval process for 17 European Standards supporting the Cyber Resilience Act

Why Open Source Matters for AI

Multiple redirect URIs and token refresh for OAuth apps

Patterns and problems in emerging multiagent systems

AI swarms are starting to pose indirect takeover risk

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97wb5j4cxvbwx4r1vz6svwhwh8e4fds)

[Browse email designs](https://brew.new/browse/templates)
