OWASP has released the GenAI LLM Top 10 for 2026, reframing AI risk around what happens when models are allowed to act with too much autonomy. Prompt injection and sensitive information disclosure remain the top two issues, but “excessive agency” jumps sharply in the ranking. The update also shifts focus from system-prompt leakage toward “hidden context exposure,” broadening the set of information defenders must protect.
For security teams, the headline is clear: defenses must expand beyond classic prompt injection mitigations and start treating AI workflows as systems with consequences—where tool use, permissions, and agent action paths are primary risk drivers.
Source: Checkpoint Blog
Apple patches iOS/macOS and addresses widespread vulnerability load (incl. WebKit/Safari-risk surface)
Apple released updates covering iOS/iPadOS and macOS, with security fixes for 108 vulnerabilities reported in the macOS release. The updates come shortly after a prior macOS screen-sharing fix, emphasizing that screen-sharing and related remote access paths are still a moving target. Even if many flaws are not directly exploitable in all environments, cumulative patching at this scale is a strong signal that attackers are actively probing end-user surfaces.
Patch prioritization should include any macOS systems used for remote work, support, or screen-share features, plus any devices with public-facing management or remote access tooling.
Source: SANS ISC
Mac screen sharing flaw exploited in the wild to gain root and deploy Monero cryptominers (CVE-2026-65400)
Security reporting indicates attackers are actively exploiting a macOS Screen Sharing vulnerability to bypass authentication, achieve root access, and install cryptominers. The reported guidance points users to upgrade macOS versions including Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1). This is a classic “patch-now” scenario because exploitation appears to be ongoing rather than theoretical.
If you manage fleets, treat Screen Sharing settings, firewall rules, and remote access permissions as immediate containment controls while patches roll out.
Source: Help Net Security
Operation ASTERIX: crypto fraud pipeline uses AI-assisted development plus prompt “jailbreak” attempts
Rapid7 describes a cryptocurrency fraud operation that combined vishing and phishing with fake wallet applications designed to steal seed phrases and other high-value credentials. A rare artifact set shows AI being used during development (code scaffolding/obfuscation) and even an attempt to bypass an LLM’s safety controls using a crafted prompt. The operational playbook also includes target enrichment and workflow chaining across email and phone to increase trust before credential theft.
The key takeaway for defenders: adversaries are treating “model restrictions” like another engineering constraint to overcome, and the end-to-end scam workflow (not just the malware) is where detection opportunities exist.
Source: Rapid7
GitLab emergency patch: critical unauthenticated GraphQL flaw could modify/delete public projects (CVE-2026-19478)
GitLab issued a critical update addressing an unauthenticated GraphQL vulnerability (CVE-2026-19478, CVSS 9.4). The flaw could allow attackers to remotely modify or delete public projects and user data under certain conditions, meaning impact is not limited to account compromise. Since the issue is unauthenticated, exposure depends more on reachability and configuration than on valid credentials.
Organizations running self-managed GitLab should treat this as an urgent patch and verify that affected instances are updated and not reachable from unnecessary networks.
Source: Security Affairs
France DGFiP data breach: attackers exposed tax data tied to ~678,000 individuals
France’s tax authority (DGFiP) disclosed a breach in which attackers accessed internal systems, exposing data for approximately 678,000 individuals and professionals. Reporting also notes claims from an actor (alias “ZeroBytes”) about additional data extraction and forum postings offering stolen datasets for sale. The incident illustrates how identity and credentialed access can turn routine governmental portals into high-impact data exposure events.
Defenders should focus on credential hygiene, monitoring for anomalous access patterns to tax/admin systems, and incident readiness for data exfiltration scenarios.
Source: Help Net Security
You May Also Be Interested In...
SafePal warns of a breach affecting nearly 40,000 customers
Irregular says “human oversight” responsible for AI sandbox escape incidents
Hacking public Wi‑Fi DNS to steal credentials