ChatGPT Sandbox Isolation Flaw Created a Hidden Route for Cross-Account Data Theft
Researchers found that a shared internal package service could act as a covert communication channel between isolated ChatGPT containers. The proof of concept combined hidden instructions and connected-app...
ZTNA in 2026: Ten Platforms Shaping Secure Access Beyond the Traditional VPN
A new 2026 market overview compares ten prominent zero-trust network access platforms for cloud, hybrid and remote environments. Buyers should look beyond feature checklists and test identity, device...
Microsoft’s New Windows Tool Quietly Resets Chrome, Firefox, and Brave to Bing
A newly spotted Microsoft installer called MicrosoftSettings.exe pushes a browser extension that switches Chrome, Firefox, and Brave over to Bing search and the MSN homepage. Security researchers note...
Claude AI’s Shared Chat Links Briefly Turned Up in Google Search, Exposing Private Conversations
Hundreds of Claude AI shared-chat links reportedly became publicly searchable on Google over the weekend, exposing legal advice, proprietary code, and personal conversations to anyone who searched for...
HermeticReader: How a Bug in Adobe’s PDF Browser Extension Could Expose WhatsApp Chats to Any Website
Researchers at Guardio Labs disclosed a flaw in the Adobe Acrobat Chrome extension, installed on roughly 329 million browsers, that let a malicious website silently read a victim's...
Apple’s Unpatched ‘Hide My Email’ Flaw Has Exposed User Identities for Over a Year
An unpatched vulnerability in Apple's Hide My Email feature can expose users' real email addresses behind their iCloud+ anonymization aliases, researcher Tyler Murphy and 404 Media have confirmed....
Android 16 ‘Tiny UDP Cannon’ Flaw Lets Malicious Apps Bypass VPN and Expose Your Real IP Address
A newly disclosed Android 16 design flaw dubbed 'Tiny UDP Cannon' allows any app with basic permissions to bypass VPN lockdown mode and reveal the device's real IP...
Microsoft Edge Stores Your Entire Password Vault in Cleartext Process Memory — Every Session
Security researcher @L1v1ng0ffTh3L4N has revealed that Microsoft Edge decrypts all stored passwords into plaintext process memory at browser launch and keeps them there for the entire session. Unlike...