New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration
2026-06-07T07:24:06Z•376bb2a2e1ac5057d77271320a22411c7f134a79d8c9c0c6bbc21b47ca20d7ce
active-exploitationai-securityandroidcloud-compromisecredential-theftdosespionagegithubmacosmalwarenpmproxy-networkrcesupply-chainweb-shellwordpresszero-day
What happened
A broad set of high-impact incidents and vulnerabilities surfaced: multiple actively exploited and high-severity bugs (SolarWinds Serv-U CVE-2026-28318, Cisco Catalyst SD‑WAN CVE-2026-20245, Cisco Unified CM CVE-2026-20230, Everest Forms Pro RCE CVE-2026-3300, Redis RCE CVE-2026-23479) and large-scale supply-chain/malware campaigns (Miasma and IronWorm targeting GitHub/npm, npm package poisoning, PCPJack cloud hijacks). Researchers also reported mass browser and media-library fixes (Chrome 149; AI agent finding 21 FFmpeg zero-days), macOS and Android malvertising/spyware campaigns (FlutterShel
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 376bb2a2e1ac5057d77271320a22411c7f134a79d8c9c0c6bbc21b47ca20d7ce
- Enrichment time
- 2026-06-07T07:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.