ChatGPT advanced account security adds passkeys and hardware keys

2026-05-04T02:51:52Z6239f86d40b516c954f514b42a6e7119bc0b96394a129c345338b116e5a52f0c
AI network trafficAI supply chainAdvanced Account SecurityAutomating Pentest DeliveryBackblazeCVE-2026-41940ChatGPTCiscoDataikuKiji Privacy ProxyLPELinux kernelOpenAIPIIShadow AIaccount recoverycPanelhardware security keysmodel provenancepasskeyspentestingphishing‑resistant authenticationprivacy proxythreat intelligencezero-day

What happened

Collection of Help Net Security items (late Apr–early May 2026). Key highlights: OpenAI introduced Advanced Account Security for ChatGPT and Codex — an opt-in setting that disables password sign‑in and email/SMS recovery, requiring passkeys or hardware security keys (phishing‑resistant authentication). A critical cPanel authentication‑bypass zero‑day (CVE-2026-41940) has been actively exploited since at least Feb 23. Other notable items: a reported high‑severity local‑privilege‑escalation (LPE) in the Linux kernel; Dataiku released Kiji Privacy Proxy, an open‑source gateway to detect and maskP

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
6239f86d40b516c954f514b42a6e7119bc0b96394a129c345338b116e5a52f0c
Enrichment time
2026-05-04T02:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.