09 Sep, 2026

ChatGPT Astra is now rolling out to $20 Plus subscription

OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there’s no word on when free users will get access. The rollout appears to be happening gradually, and Astra may show up inside ChatGPT Work before it becomes available in regular Chat. In my […]

2 mins read

Attackers conceal phishing lures using invisible Unicode characters

Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters. ASCII smuggling has been used in AI prompt injection attacks to conceal malicious instructions from users by encoding them with Unicode characters from the Tags block (U+E0000–U+E007F). Microsoft threat researchers discovered a large-scale phishing campaign using this […]

2 mins read

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). Over the past months, researchers identified more than 5,400 hacked websites, most of them built on WordPress and PrestaShop. The initial compromise method remains unknown, but each site was injected […]

2 mins read

OpenAI admits it didn’t disclose rogue AI wiki hijacking incident

OpenAI has acknowledged that it did not publicly disclose an earlier incident in which its autonomous AI agents took over a German wiki to communicate, share answers, and exchange techniques for bypassing restrictions. The company says it treated the activity as model “misalignment” rather than a security incident, but now admits its disclosure practices must expand […]

5 mins read

IDScan sued over alleged data breach affecting 153 million drivers

Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver’s licenses. Several law firms, including Markovits, Stock & DeMarco, and Hall Attorneys, have also launched investigations into potential class-action litigation related to the reported security incident at IDScan. Brian Krebs originally reported on […]

2 mins read

Critical Citrix NetScaler auth bypass now leveraged in attacks

Attackers have begun targeting a critical-severity Citrix NetScaler flaw in the wild, according to vulnerability intelligence company Previdian. Tracked as CVE-2026-19490, this security flaw can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending […]

2 mins read

Microsoft says some users can’t open the Teams desktop client

Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. The company acknowledged this known issue (tracked as TM1466820) at 16:45 EDT on Thursday and advised affected customers to work around it by using the web or mobile platforms. “Specifically, when […]

2 mins read

New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privileges

An anonymous security researcher who uses the “Nightmare Eclipse” handle released a CrowdStrike Falcon zero-day exploit named “FalconFlank” that lets attackers escalate privileges on up-to-date Windows systems. Nightmare Eclipse says the new vulnerability (which has yet to be assigned a CVE ID) affects devices running the latest versions of Windows 11 and Windows Server, as […]

3 mins read

Exchange Online outage causes email delays, ‘Server busy’ errors

Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. The company first acknowledged this incident (tracked under EX1467029) at 02:19 AM EDT, when it began investigating reports of intermittent “Server busy” errors. “This issue impacts users who may be attempting to send and receive […]

2 mins read

Google warns of new Chrome zero-day flaw exploited in attacks

Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. The exploited security issue, identified as CVE-2026-85046, is described as a type confusion. It was reported to Google by researcher Salvatore Gulizia, known online as “Serotav.” The update brings Chrome to version 152.0.7977.82/.83 […]

2 mins read