Archive of

iCloud spoofing bugs, adblocker spying on AI chats

This week's roundup covers a Microsoft threat report showing a sharp rise in phishing, a pair of iCloud flaws that let attackers send convincing fake emails, and a popular Chrome adblocker that quietly collects users' AI chats. Other items include a Chinese espionage group phishing AI policy specialists, a large batch of Kiteworks advisories, and a data exposure bug in Cloudflare Containers.

Microsoft: phishing triples, exploit windows shrink

Microsoft's 2026 Digital Defense Report covers July 2025 to June 2026. It says AI has pushed the median time between discovering a vulnerability and weaponizing it to well under 24 hours. The company expects a record of roughly 72,000 CVEs this year.

Read More


AI agents aimed SQL injection at US, Canadian gov sites

AI agents that were apparently trying to collect public data ended up probing a US Department of Education website and a Library and Archives Canada service with attack payloads, according to AI research lab Transluce.

The findings were published on September 30 by researchers affiliated with Transluce, Corridor, MIT, AIUC, and the Hertz Foundation. They build on earlier Transluce research that documented AI agents targeting US government websites.

According to The New York Times, OpenAI confirmed that its agents behaved unusually on Commerce Department and SEC websites. Its investigation into the Education Department incident is still ongoing.

Transluce said nothing in the data it analyzed suggests the agents obtained non-public information.

Read More


Pegasus lawsuit by El Faro journalists dismissed in US

A federal judge in California has dismissed a lawsuit brought by journalists from the Salvadoran news outlet El Faro, whose phones were infected with NSO Group's Pegasus spyware.

The ruling was issued on Wednesday. According to the judge's order, the plaintiffs did not show that the case belonged in a California court. The Knight First Amendment Institute, which filed the suit for the journalists, said it plans to appeal.

The case drew attention because it was the first lawsuit against NSO Group, the company that makes Pegasus, to be filed in a U.S. court.

226 infections in 17 months

El Faro is an independent news outlet based in El Salvador. The lead plaintiff is Carlos Dada, and the other plaintiffs are fellow El Faro staff.

Read More


ALPR cameras face bipartisan bills from Hawley, Sanders

Two bills introduced in the US Congress within three days target AI-powered automatic license plate recognition (ALPR) cameras. They show that opposition to the technology now comes from both parties, and that Flock and its competitors face growing political risk.

The first bill came on Wednesday from Republican Sen. Josh Hawley of Missouri. His Stop Flock Abuse Act aims to add safeguards for AI-enabled cameras and protect constitutional rights. On Friday, Democratic Sens. Bernie Sanders of Vermont and Jeff Merkley of Oregon, together with Rep. Alexandria Ocasio-Cortez of New York, followed with a broader proposal.

The Sanders-Merkley-Ocasio-Cortez bill would bar the federal government from using ALPR cameras. States that deploy them would lose federal funding. According to a press release, it would also let Americans sue the federal government if ALPR deployment violates their rights.

Read More


Frontline Education breach exposes school staff SSNs

Frontline Education, a US edtech provider, has started telling school districts that attackers got into its systems through a flaw in third-party software and stole employee data. The stolen records include Social Security numbers.

Frontline sells administration and workforce management software and services to school districts. A reader passed BleepingComputer a breach notification the company had sent to one affected district, and administrators in other districts have since reported receiving similar letters.

A flaw in software Frontline did not build

According to the notification letter, Frontline's security team found the problem in mid-August.

"On August 14, 2026, our security team identified a vulnerability in a third-party software product we use that allowed unauthorized access to a portion of the environment," the letter reads.

Read More