[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fW7tY9z8oHZ7JSHaL7KIITTMkh45lVNx00-_gzNdawK4":3},{"article":4,"iocs":59},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"30e7b06d-6377-4492-bb8a-93e9ebb09aef","In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats","in-other-news-15k-icloud-spoofing-bugs-ai-policy-experts-phished-adblocker-spies-5a754e","Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats appeared first on SecurityWeek.","SecurityWeek's weekly cybersecurity roundup covers multiple notable incidents including Microsoft's 2026 Digital Defense Report showing phishing tripling and exploit windows shrinking to under 24 hours, Kiteworks publishing over 100 critical and high-severity advisories in a single day, and SEC Consult disclosing two iCloud spoofing vulnerabilities that bypassed email authentication checks. Additional stories include a Chrome adblocker (Poper Blocker) with 2M+ users secretly collecting ChatGPT and Claude conversations, GitHub Security Lab discovering 24 Android app vulnerabilities, and two US Air Force servicemen sentenced for BEC attacks that diverted over $2.4M.","Weekly roundup: Kiteworks patches 100+ vulns, iCloud spoofing bugs, adblocker spies on AI chats.","SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment. Here are this week’s highlights: Microsoft threat report sees phishing triple as exploit windows shrink Microsoft’s 2026 Digital Defense Report (covering July 2025 to June 2026) says AI has pushed the median time from vulnerability discovery to weaponization well below 24 hours, with a record of roughly 72,000 CVEs expected this year. Phishing rose from 7% to 23% of initial access vectors in Microsoft’s incident response cases, Teams vishing climbed 502%, and ransomware detonations against enterprises increased nearly 16%. Government agencies were the most affected sector, accounting for 27% of observed activity. Advertisement. Scroll to continue reading. Kiteworks publishes over 100 security advisories in a single day Kiteworks published over 100 security advisories on September 30, covering its Core platform, Email Protection Gateway, Secure Data Forms, and MFT Server. A dozen are rated critical, mostly Email Protection Gateway bugs that can lead to account takeover, code execution, or access to internal network resources. Dozens more are rated high severity. The most common issues are information disclosure and arbitrary code execution, followed by privilege escalation. Smuggled headers turned iCloud into an email spoofing tool SEC Consult researcher Timo Longin has disclosed two iCloud vulnerabilities that let attackers send emails from arbitrary icloud.com addresses, and the messages passed SPF, DKIM and DMARC checks. Both stemmed from differences in how two parts of Apple’s outgoing mail pipeline parsed messages, which let a forged From header slip past sender verification. The first issue was reported in May 2024, but Apple’s initial fix was incomplete, and it wasn’t fully fixed until December 2025. Apple paid a $15,000 bug bounty. Poper Blocker’s hidden interpreter siphons AI conversations Bay Area Labs researchers found that Poper Blocker, a featured Chrome adblocker extension with more than 2 million users, collects full browsing history and conversations from ChatGPT, Claude, Gemini and Google’s AI Mode once users are nagged into accepting data sharing. The collection logic is downloaded from the vendor’s server and run by a custom interpreter inside the extension, so the operator can change what is collected, and where it is sent, without pushing an update. GitHub Security Lab turns AI taskflows on Android apps GitHub Security Lab says Android-focused taskflows for its open source AI security agent have uncovered 24 vulnerabilities in Android applications. Examples include an OsmAnd flaw that let any installed app (even one with no permissions) silently change the navigation app’s settings to leak the user’s location and routes, and two Wikipedia app bugs that chain into account takeover through a malicious deeplink. The researchers note that the AI often misjudged severity and flagged unrealistic issues, so findings still need human review. Two US airmen sentenced to prison for BEC attacks Chijioke Timothy Odimegwu and Harafat Mogaji, two Delaware men who were serving in the US Air Force at the time, have been sentenced to 111 and 78 months in prison, respectively. Working with co-conspirators over nearly two years, they phished employee email credentials and used spoofed emails to redirect business payments, diverting more than $1.68 million from an Iowa victim and over $720,000 from an Ohio victim. They were also ordered to pay a combined $1.36 million in restitution. Vulnerability let Cloudflare Containers users peek at other customers’ data Cloudflare has patched a flaw in Containers (and Sandboxes, which is built on it), reported by Accomplish researcher Oren Yomtov, that let a Workers Paid customer recover leftover data from disk blocks other customers’ containers had used on the same host. Because newly allocated storage blocks weren’t zeroed, the researchers found residual material, including directory structures, database pages and complete SQLite databases, on 18 of 24 placements, although they couldn’t target a specific victim. Cloudflare found no evidence of malicious exploitation. Fake AI advisory committee invites used by Chinese cyberspies Proofpoint has detailed TA419, a new China-aligned espionage group that impersonated former White House OSTP Principal Deputy Director Lynne Edwards Parker and economist Heidi Crebo-Rediker in July 2026 to phish AI policy experts at US think tanks, universities and law firms. Targets who replied to the initial benign outreach were sent to a fake OneDrive page that passes the Microsoft 365 sign-in through an adversary-in-the-middle (AitM) proxy, capturing session cookies even when MFA is used. The group also posed as an Anthropic employee in February 2026. Related: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw Related: In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure Written By SecurityWeek News Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from SecurityWeek News RemoteThreat Launches With $7 Million for Offensive Operations PlatformIn Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility ExposureIsland Raises $400 Million at $6.4 Billion ValuationCyera Raises $400 Million at $12+ Billion ValuationIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawVirtual Event Today: Attack Surface Management SummitHackuity Raises $19 Million for AI-Powered Vulnerability ManagementIn Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review Latest News macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD BackdoorCrypto Scammers Hijack Microsoft’s Official X AccountIn Rare Move, Alleged Iranian State Hacker Extradited to USWarlock Expands SharePoint Exploitation in Critical Infrastructure AttacksAI Agents Aimed SQL Injection at US and Canadian Government SitesExploited Fortinet FortiMail Zero-Day Calls for Urgent ActionZero Trust Creator Says Model Holds Firm Against AI-Assisted AttacksOsavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveLumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.David Cass has joined Grayscale Investments as Chief Risk Officer.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for","https:\u002F\u002Fwww.securityweek.com\u002Fin-other-news-15k-icloud-spoofing-bugs-ai-policy-experts-phished-adblocker-spies-on-ai-chats\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2023\u002F10\u002Fcybersecurity-news.jpg","2026-10-02T14:30:00+00:00","2026-10-02T16:00:38.807968+00:00",8,[18,21,23,25,27,30],{"name":19,"type":20},"Microsoft","vendor",{"name":22,"type":20},"Apple",{"name":24,"type":20},"Kiteworks",{"name":26,"type":20},"Cloudflare",{"name":28,"type":29},"Poper Blocker","product",{"name":31,"type":32},"Android","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":33,"icon":35,"name":36,"slug":37},null,"Vulnerabilities","vulnerabilities",[39,44,49,54],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":50},{"id":51,"icon":35,"name":52,"slug":53},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":55},{"id":56,"icon":35,"name":57,"slug":58},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[60],{"type":48,"value":28,"context":61},"Chrome adblocker extension collecting user browsing history and AI chat conversations without explicit consent"]