iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

www.news4hackers.com-icloud-spoofing-bugs-ai-policy-experts-phished-adblocker-spies-on-ai-chats-icloud-spoofing-bugs-ai-policy-experts-phished-adblocker-spies-on-ai-chats

SecurityWeek’s weekly cybersecurity news roundup highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, and other noteworthy events.

Microsoft’s 2026 Digital Defense Report

Microsoft’s 2026 Digital Defense Report reveals a tripling of phishing incidents as exploit windows shrink. The report, covering July 2025 to June 2026, notes that AI has accelerated the median time from vulnerability discovery to weaponization to under 24 hours, with an estimated 72,000 CVEs expected this year. Phishing accounted for 23% of initial access vectors in Microsoft’s incident response cases, up from 7%, while Teams vishing saw a 502% increase. Ransomware attacks against enterprises rose nearly 16%, with government agencies experiencing 27% of observed activity.

Kiteworks Security Advisories

Kiteworks issued over 100 security advisories on September 30, addressing its Core platform, Protection Gateway, Secure Data Forms, and MFT Server. Twelve critical flaws were disclosed, primarily in Protection Gateway, which could enable account takeover, code execution, or internal network access. Additional high-severity issues included information disclosure, arbitrary code execution, and privilege escalation.

iCloud Spoofing Vulnerability

A vulnerability in Apple’s iCloud mail system allowed attackers to spoof email addresses by exploiting discrepancies in how two components of the outgoing mail pipeline parsed messages. This enabled forged From headers to bypass SPF, DKIM, and DMARC checks. The first issue was reported in May 2024 but remained partially unresolved until December 2025. Apple awarded a $15,000 bounty for the disclosure.

Poper Blocker Data Collection

Researchers from Bay Area Labs discovered that Poper Blocker, a Chrome adblocker with over 2 million users, secretly collected browsing history and AI chat data from platforms like ChatGPT, Claude, Gemini, and Google’s AI Mode. Users were prompted to consent to data sharing, after which the extension harvested conversations and navigation records.

GitHub Security Lab Findings

GitHub Security Lab’s AI-driven taskflows for Android apps identified 24 vulnerabilities in applications. One flaw in OsmAnd allowed any installed app to alter navigation settings, exposing user location and routes. Two Wikipedia app vulnerabilities enabled account takeovers via malicious deeplinks. The AI system occasionally misclassified issues, necessitating manual verification.

U.S. Air Force BEC Sentences

Two U.S. Air Force members received prison sentences for business email compromise (BEC) attacks. Chijioke Timothy Odimegwu and Harafat Mogaji, who operated with co-conspirators for nearly two years, diverted over $1.68 million from an Iowa victim and $720,000 from an Ohio victim. They were sentenced to 111 and 78 months, respectively, and ordered to pay $1.36 million in restitution.

Cloudflare Data Exposure Patch

Cloudflare patched a flaw in its Containers and Sandboxes services that allowed Workers Paid customers to access residual data from disk blocks used by other users. Researchers found leftover material, including directory structures and SQLite databases, on 18 of 24 test placements. No evidence of malicious exploitation was detected.

Proofpoint’s TA419 Espionage Group

Proofpoint identified a China-aligned espionage group, TA419, which impersonated former White House officials to target AI policy experts. Victims who engaged with initial outreach were redirected to a fake OneDrive page that captured session cookies via an adversary-in-the-middle (AitM) proxy, bypassing multi-factor authentication. The group also posed as an Anthropic employee in February 2026.

Other Developments

Additional developments include a Cloudflare Containers data exposure flaw, a Docker botnet targeting AI keys, and a ransomware developer’s sentencing. Other highlights involve a macOS fake Zoom installer containing the CloudSyncD backdoor, crypto scammers hijacking Microsoft’s X account, and an alleged Iranian state hacker’s extradition to the U.S.

Startup Funding and Industry News

SecurityWeek News RemoteThreat launches with $7 million for offensive operations tools. Island raises $400 million at a $6.4 billion valuation. Cyera secures $400 million at a $12+ billion valuation.

Expert Insights

AI has accelerated attack speeds but not security fundamentals, emphasizing defense-in-depth and application security. Four emerging threats—AI, supply-chain risks, quantum computing, and geopolitical conflict—require proactive preparation. Agentic remediation focuses on resolving known issues rather than speculative risks. Continuous control monitoring is critical to validate security measures in real time. A proposed open standard aims to revoke API keys within 60 seconds of detection.



About Author

en_USEnglish