iCloud spoofing bugs, adblocker spying on AI chats

iCloud spoofing bugs, adblocker spying on AI chats

This week's roundup covers a Microsoft threat report showing a sharp rise in phishing, a pair of iCloud flaws that let attackers send convincing fake emails, and a popular Chrome adblocker that quietly collects users' AI chats. Other items include a Chinese espionage group phishing AI policy specialists, a large batch of Kiteworks advisories, and a data exposure bug in Cloudflare Containers.

Microsoft: phishing triples, exploit windows shrink

Microsoft's 2026 Digital Defense Report covers July 2025 to June 2026. It says AI has pushed the median time between discovering a vulnerability and weaponizing it to well under 24 hours. The company expects a record of roughly 72,000 CVEs this year.

In Microsoft's incident response cases, phishing grew from 7% to 23% of initial access vectors. Voice phishing over Teams rose 502%, and ransomware detonations against enterprises increased by nearly 16%. Government agencies were the most affected sector, accounting for 27% of observed activity.

iCloud flaws enabled authenticated email spoofing

Timo Longin, a researcher at SEC Consult, disclosed two iCloud vulnerabilities that allowed attackers to send emails from any icloud.com address. The forged messages passed SPF, DKIM and DMARC checks, the standard mechanisms mail servers use to confirm that a sender is genuine.

Both bugs came from two components in Apple's outgoing mail pipeline parsing messages in different ways. That mismatch let a forged From header get past sender verification. Longin first reported the problem in May 2024. Apple's initial fix was incomplete, and the issue was not fully resolved until December 2025. Apple paid a $15,000 bug bounty.

Adblocker with a hidden interpreter collects AI chats

Researchers at Bay Area Labs looked at Poper Blocker, a featured Chrome adblocker with more than 2 million users. Once users are nagged into accepting data sharing, the extension collects their full browsing history and their conversations with ChatGPT, Claude, Gemini and Google's AI Mode.

The collection logic is not shipped with the extension itself. It is downloaded from the vendor's server and executed by a custom interpreter built into the extension. This means the operator can change what data is collected, and where it goes, without releasing an update.

Chinese spies pose as AI policy figures

Proofpoint detailed TA419, a new China-aligned espionage group that phished AI policy experts at US think tanks, universities and law firms. In July 2026, the group impersonated Lynne Edwards Parker, former Principal Deputy Director of the White House Office of Science and Technology Policy (OSTP), and economist Heidi Crebo-Rediker. The lure was an invitation to an AI advisory committee.

Targets who answered the harmless first message were directed to a fake OneDrive page. That page routed the Microsoft 365 login through an adversary-in-the-middle (AitM) proxy, which captured session cookies even when multi-factor authentication was enabled. TA419 also posed as an Anthropic employee in February 2026.

Kiteworks releases more than 100 advisories

On September 30, Kiteworks published over 100 security advisories for its Core platform, Email Protection Gateway, Secure Data Forms and MFT Server. A dozen are rated critical. Most of these affect the Email Protection Gateway and can lead to account takeover, code execution or access to internal network resources. Dozens more are rated high severity. Information disclosure and arbitrary code execution are the most common issue types, followed by privilege escalation. The release comes shortly after the vendor lifted its shutdown advice over a separate critical flaw.

GitHub's AI agent finds Android app bugs

GitHub Security Lab said Android-focused taskflows for its open source AI security agent found 24 vulnerabilities in Android apps. One OsmAnd flaw let any installed app, even one without permissions, silently change the navigation app's settings to leak the user's location and routes. Two bugs in the Wikipedia app could be chained into account takeover through a malicious deeplink. The researchers said the AI often misjudged severity and flagged unrealistic issues, so human review is still needed.

Cloudflare Containers leaked leftover data

Cloudflare patched a flaw in Containers, and in Sandboxes, which is built on it. Accomplish researcher Oren Yomtov found that a Workers Paid customer could recover leftover data from disk blocks used by other customers' containers on the same host, because newly allocated blocks were not zeroed. The researchers found residual material, including directory structures, database pages and complete SQLite databases, on 18 of 24 placements. They could not target a specific victim. Cloudflare found no evidence of malicious exploitation.

US airmen sentenced for BEC scheme

Chijioke Timothy Odimegwu and Harafat Mogaji, two Delaware men who were serving in the US Air Force at the time, received sentences of 111 and 78 months in prison. Over almost two years, they and co-conspirators phished employee email credentials and used spoofed emails to redirect business payments in a business email compromise scheme. They diverted more than $1.68 million from an Iowa victim and over $720,000 from an Ohio victim, and were ordered to pay a combined $1.36 million in restitution.

Why It Matters

Several of this week's stories share one theme: identity and trust checks are being bypassed rather than broken. The iCloud bugs produced spoofed emails that passed every standard authentication check. TA419's AitM proxy captured session cookies even with MFA in place. Microsoft's figures on phishing and Teams vishing suggest attackers are finding this approach productive.

The Poper Blocker case points to a separate risk. AI chats often contain sensitive business information, and browser extensions with remotely updated logic can change what they collect at any time. Organizations may want to review which extensions are allowed on managed browsers.

It is also worth watching whether Microsoft's sub-24-hour weaponization figure holds in other vendors' data. If it does, patch cycles measured in days will look increasingly out of step with the threat.