ChatGPT Sandbox Isolation Flaw Created a Hidden Route for Cross-Account Data Theft
Researchers found that a shared internal package service could act as a covert communication channel between isolated ChatGPT containers. The proof of concept combined hidden instructions and connected-app...
FortiGate Exploitation Campaign Plants PivotC2 Malware and Steals Network Credentials
Attackers are exploiting a critical Fortinet vulnerability to install a custom Node.js remote-access framework on exposed appliances. The campaign has reportedly compromised 178 devices and can harvest credentials,...
Microsoft’s September Patch Wave Fixes 973 Flaws and Two Exploited Zero-Days
Microsoft’s September 2026 security release addresses 973 vulnerabilities across Windows, Office, SQL Server and other enterprise products. Two privilege-escalation zero-days are already being exploited, making rapid testing and...
How a Shared ChatGPT Sandbox Turned Into a Covert Channel for Stealing Gmail Data
Check Point Research found that ChatGPT's supposedly isolated code-execution sandboxes all shared access to the same backend package repository, allowing hidden instructions to hop between completely unrelated user...
Microsoft’s September Patch Tuesday Closes 973 Holes, Including Two Zero-Days Already Under Attack
Microsoft's September 2026 security update addresses 973 vulnerabilities — one of its largest releases on record — including two Windows elevation-of-privilege flaws that attackers are actively exploiting. Several...
Fortinet Firewalls Under Siege: New PivotC2 Malware Exploits Critical CAPWAP Flaw
A critical, unauthenticated buffer overflow in FortiOS's CAPWAP service is being actively exploited to plant a custom Node.js post-exploitation toolkit dubbed PivotC2. Researchers say at least 178 devices...
Critical Ivanti Flaws Expose ITSM and Mobile Management Systems to RCE and Admin Takeover
Ivanti has disclosed ten vulnerabilities across EPMM, Neurons for ITSM and Sentry, including unauthenticated remote-code-execution flaws rated 9.8. Cloud instances have been patched, while on-premises customers and Sentry...
Ivanti Patches Nine Critical Flaws Across EPMM, Neurons for ITSM, and Sentry
Ivanti has disclosed a cluster of vulnerabilities spanning Endpoint Manager Mobile, Neurons for ITSM, and Sentry, several rated up to 9.9 in severity and capable of unauthenticated remote...