Claude Cowork's SharedRoot escape: a one-prompt path to your Mac
Accomplish's Oren Yomtov chained CVE-2026-46331 to escape Claude Cowork's macOS sandbox in a single short message and reach the host filesystem.
Category
Accomplish's Oren Yomtov chained CVE-2026-46331 to escape Claude Cowork's macOS sandbox in a single short message and reach the host filesystem.
Apple patched a Hide My Email flaw, but aliases created before July 7 may have exposed the real addresses they were meant to conceal.
California's DROP tool wipes a resident's data from 614 brokers with one form. Here's what's covered, what isn't, and what to try if you don't live there.
A Go-based botnet is scanning exposed Ollama, ComfyUI, n8n, Open WebUI, Langflow, and Gradio instances for AWS keys and Kubernetes tokens, QiAnXin XLab says.
Hugging Face disclosed a July 2026 breach run end-to-end by an autonomous agent. The defender was an open-weight model.
ICE's five-year, $25M/year CLEAR contract pulls in names, SSNs, ethnicity, social-media posts and geolocation for 'voter fraud' enforcement.
The EU's DMA orders Google to share anonymised Search data with eligible AI chatbots and open Android assistant features to rivals.
Anthropic's web_fetch tool let a prompt-injection honeypot walk Claude through user profile URLs and pull a user's name, city, and employer.
Cereblab caught Grok Build CLI uploading whole repos, with .env files and git history, to a Google Cloud bucket. Opt-out did not work until after disclosure.
LAPD OIG audit of Aug-Sep 2025 found 161 innocent drivers stopped after ALPR false alerts from 210.5M plate reads. LAPD let its Flock contract expire.
EFF's two-part series argues automated content moderation is now permanent at platform scale, while transparency, human review, and appeal have not kept up.
Patreon has joined Cloudflare's content-independence push, blocking AI training crawlers across its creator network. Here's what changes next.
A Meta patent published July 2 describes a wearable that records all-day audio, infers mood from sighs and laughter, and includes bystanders by design.
Noma Labs' GitLost write-up shows a single public-repo issue can coerce GitHub's coding agent into leaking private repo contents.
EU Council voted an identical copy of the expired April Chat Control regulation back into law via written procedure, ahead of the summer recess vote.
Alibaba banned Claude Code effective July 10, citing embedded backdoors. The ban lands days after Anthropic accused three Chinese labs of distilling Claude.
Citizen Lab finds former PEGA committee member Stelios Kouloglou was hacked with Pegasus twice while the EU Parliament was investigating that very spyware.
Fable 5 ships with a four-tier classifier and a Cyber Jailbreak Severity scale from CJS-0 to CJS-4, the first concrete numbers on jailbreak risk.
Proton rebuilt its privacy-first AI assistant from scratch. Here is what zero-access encryption actually means for an LLM, and where the limits still sit.
EFF found Grindr auto-enrolls users in AI training on profile photos, age, taps, and display names. The only button on the opt-out notice says 'Proceed.'
Anthropic's Mythos finds 10,000+ critical vulnerabilities but fewer than 1% get patched. Mandiant says exploits now arrive a week before fixes.
Google's always-on AI agent watches everything, Canada finds OpenAI broke privacy law, and a US bank fed customer SSNs to a chatbot.
Intruder scanned 2 million hosts and found 1 million exposed AI services with no authentication. Plus: teenagers are using ChatGPT to hack governments, and OpenAI launches Daybreak.
OpenClaw collected nine CVEs in four days with 135,000 instances exposed. Plus: GitHub RCE, Flowise exploitation, and CrewAI trust failures.