GPT-5.6 incorrectly deletes the $HOME environment variable instead of a temporary directory when operating in full-access mode without sandbox protection, prompting OpenAI to announce technical safeguards.
Phishing emails with fake compliance notifications attempt to lure LastPass and Bitwarden users to malicious websites to steal master passwords or distribute malware.
Uncontrolled code in web applications poses data protection and security risks that can be addressed through CSP, script whitelisting, and continuous monitoring.
Starting in September 2024, the Cyber Resilience Act mandates the reporting of security vulnerabilities within 24 hours to authorities, requiring fundamentally changed incident response processes.
CVE-2026-42533 in NGINX 1.30.3, 1.31.2 and older NGINX Plus versions enables denial-of-service and potentially code execution — immediate update to 1.30.4, 1.31.3, or Plus 37.0.3.1 required.
The popular HTTP header extension ModHeader contained code to capture browser history that could have been activated through a simple update without additional permissions.