Several recent disclosures highlight risks spanning email authentication, browser extensions, cloud isolation and targeted phishing campaigns.
Apple addressed two flaws in its iCloud mail infrastructure that could have allowed attackers to send messages appearing to originate from arbitrary iCloud addresses. According to researcher Timo Longin of SEC Consult, inconsistencies in the handling of message headers allowed forged sender information to pass SPF, DKIM and DMARC checks. The issues were initially reported in 2024, but a complete remediation was not deployed until late 2025. Apple awarded a $15,000 bounty for the findings.
Researchers at Bay Area Labs also reported that the Chrome extension Poper Blocker could collect users’ browsing histories and conversations with AI services, including ChatGPT, Claude and Gemini, after users accepted its data-sharing prompts. The researchers said the extension downloaded collection logic from the operator’s servers and executed it through a custom interpreter, potentially allowing its behavior to change without a conventional extension update.
Phishing and cloud issues
Proofpoint attributed a July campaign against US AI-policy specialists to TA419, a China-aligned espionage group. The operation reportedly used invitations to a purported AI advisory committee, impersonating prominent policy figures. Recipients who engaged with the messages were directed to a fraudulent OneDrive sign-in page that used an adversary-in-the-middle framework to steal session cookies, including from accounts protected by multifactor authentication.
Cloudflare fixed a separate issue in its Containers and Sandboxes services after a researcher found that newly assigned storage blocks could contain residual data from previous customers. Testing reportedly recovered remnants such as database pages and SQLite files on some placements. Cloudflare said it found no evidence of abuse.
Additional developments
- Kiteworks released more than 100 security advisories affecting products including its Core platform, email gateway and managed file transfer server. Several flaws were rated critical.
- GitHub Security Lab said AI-assisted Android testing workflows identified 24 application vulnerabilities, while cautioning that human validation remained necessary because the system produced inaccurate or impractical findings.
- Microsoft’s latest Digital Defense Report described rising phishing activity and faster vulnerability weaponization, trends it linked in part to attackers’ use of AI.
Separately, two former US Air Force members received prison sentences for their roles in business email compromise schemes that redirected payments through stolen credentials and spoofed email messages.
