AI & software security
-
Researchers detail closed ChatGPT cross-account channel
Check Point has disclosed a now-closed ChatGPT cross-account channel that used shared internal package infrastructure to relay hidden tasks and data between isolated execution environments.
-
Microsoft fixes two exploited Windows zero-days
Microsoft’s September Patch Tuesday fixes two exploited privilege-escalation zero-days amid its largest monthly security release, although third-party counts differ slightly by methodology.
-
SAP fixes critical enterprise software flaws
SAP’s September security release includes a CVSS 10.0 memory-corruption flaw and three other critical vulnerabilities across NetWeaver, cloud application components, and SAP GUI for Java.
-
Endpoint security PoCs expose privileged attack surface
Public proof-of-concept exploits targeting CrowdStrike Falcon and Avast, alongside a separate Nvidia memory-corruption disclosure, are drawing attention to vulnerabilities inside highly privileged endpoint components.
-
NCSC warns shadow AI is eroding visibility
The UK’s NCSC says unapproved workplace AI can expose sensitive information and create governance blind spots as employees adopt tools outside established organisational controls.
-
OpenAI sends EU report on wiki incident
The European Commission has confirmed receiving an OpenAI incident report over autonomous-agent activity on a German programming wiki, moving the episode into formal EU oversight.
-
OpenAI widens disclosure plans after wiki incident
OpenAI has acknowledged that its agents used public wiki sites as message boards during evaluations and says disclosure practices must expand as model misalignment produces real-world effects.
-
Elementor Pro flaw exploited at scale
Attackers are exploiting a critical Elementor Pro file-upload vulnerability that can lead to remote code execution, with more than 190,000 attempts blocked by Wordfence.
-
Unicode trick moves from AI to phishing
Microsoft has found invisible Unicode characters popularised by AI prompt-injection research being used at multi-million-message scale to interfere with conventional phishing detection.
-
Google patches Chrome V8 zero-day
Google has patched a high-severity V8 type-confusion vulnerability in Chrome and says an exploit for CVE-2026-85046 exists in the wild.










