This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
NewsLayer PulseLIVEBTC$63,066-0.56%ETH$1,883-0.08%SOL$75.4-1.06%XRP$1-0.75%DOGE$0.0698-0.37%ADA$0.18-1.20%Total Cap$2.27T-0.06%Layer Index38 Fear
BreakingExternal ReportingPublié il y a 4 heures

Think Your Mac and Cloud Apps Are Safe? These Crypto Wallet and ChatGPT Hacks Prove Otherwise

Last week was the Black Hat security conference, and if you missed the fun, you can read all of the news and presentations that caught our attention here. Even though it’s over, the show threw us one last curveball as someone on an…

Think Your Mac and Cloud Apps Are Safe? These Crypto Wallet and ChatGPT Hacks Prove Otherwise
Publisher PCMag UK 7 min de lecture
Image via PCMag UK

Layer Index

↓ 6 pts in 24h

Last week was the Black Hat security conference, and if you missed the fun, you can read all of the news and presentations that caught our attention here. Even though it’s over, the show threw us one last curveball as someone on an outbound Delta flight from Vegas decided to spoof the airline wi-fi while in the air, which predictably ruined it for everyone, as the flight crew turned off in-flight Wi-Fi entirely until the spoofed network was shut down. This is why we can’t have nice things. 

It might sound like a harmless prank, but the flight could easily have been diverted, delayed, or even canceled because of the stunt, and the old warning to never trust public, insecure Wi-Fi without using a VPN still stands. That advice is doubly true if you’re in Vegas for Black Hat or DEF CON, where many security pros bring burner devices just so they can communicate without putting any real data at risk. 

In other news, OpenAI announced this week that it’s pausing work on its next-generation model because of cybersecurity concerns. Whether that’s a real risk or just marketing hype to generate interest remains to be seen. Meanwhile, hackers aren’t waiting around: We reported this week that Chinese hackers used open-source, publicly available AI tools to create a near-autonomous attack capable of breaking into government systems to steal data. 

Government systems and public infrastructure have been prime targets for hacking in recent years. Just this week, Suisun City, California, declared a local emergency after an attack there temporarily disabled critical public systems, like 911 routing and other city services. Put that together with attacks against water systems in at least seven states, and you can see where this is going. Meanwhile, this week we also reported on a screen-sharing flaw in Zoom that could give attackers control over your device, but at least there’s an update to fix that one. 

Across the Atlantic in the EU, Valve reported that a logistics provider working with the company to process hardware orders was hacked, with data related to Steam Machine, Steam Controller, and Steam Deck purchases lost in the breach, including names, physical addresses, email addresses, and purchase information (but not payment information). So if you’re in the EU and expecting some Valve hardware to show up at your door, be on the lookout for scams related to your order and stay safe. 

Next up, a pair of very different warnings. First, as we’ve mentioned before, if you’re relying on Microsoft Defender to keep your PC safe, you can do much better, even with free antivirus software, regardless of what Microsoft says. A disgruntled security researcher just disclosed a zero-day vulnerability in Defender, claiming that in the past he’d been poorly treated by Microsoft for bringing bugs to their attention. Second, the FBI has a warning for all of us: Hackers are coming for your nudes, so keep them safe

Now, let’s see what else is going on in the infosec world this week. 


Root Access: How a Researcher Cracked ChatGPT’s Secure Sandbox

The point of a “sandbox” environment in software development is to have a secure area that’s isolated from your live, production systems to do the hard work of testing updates, building new tools, fixing bugs, and doing other important, heads-down dev work before deploying it to your live system, where all of your users can benefit from the work you’ve done. Most importantly, it should be completely isolated and secure. You wouldn’t want your Twitter drafts going live without your knowledge, right? 

Well, thanks to reporting from Dark Reading, we learned that at Black Hat last week, a researcher from Palo Alto Networks demonstrated a proof-of-concept attack chain against OpenAI’s secure sandbox environment for ChatGPT. Worse, Simcha Kosman, the researcher who made the discovery, was able to bypass the LLM’s supervisor entirely and obtain persistent root access to the sandbox. It’s important to note that this isn’t indicative of any real attacks or hackers with access to the environment: It’s a proof-of-concept, and companies usually pay close attention to talks at conferences like Black Hat for help securing their systems. Sure enough, an OpenAI representative told Dark Reading that they learned about the issue from Kosman prior to his talk, and were grateful for his findings. Even so, it’s yet another reminder that sometimes when it comes to AI development, speed trumps security. 


Don't Fall for the CAPTCHA: New Mac Malware Drains Crypto Wallets

Whenever I find malware aimed at macOS, I like to highlight it, mostly because the myth that Macs don’t get malware persists, and, worse, macOS malware is often aggressively targeted for specific purposes and can be very complex if you don’t know what you’re looking at. If you’re a Mac user who takes security seriously, I applaud you. In this case, IT Security Guru reports that researchers at Huntress discovered malware that profiles a user’s computer and, if a crypto wallet with a balance is found, opens it and transfers either part of the wallet or the full balance to the attacker’s account.

At its core, the malware uses ClickFix, a well-known scam, to get onto the user’s computer. ClickFix works by tricking you into performing an action on your computer that stealthily downloads and installs malware. In this case, the trick is a surprise CAPTCHA you find while browsing the web, claiming that you need to complete the CAPTCHA and then copy and paste some string of text into your Mac’s terminal in order to access whatever you were looking for. And that’s the key here: the attacker has to trick you into getting the malware on your PC somehow. Even worse, this particular malware profiles your Mac before doing anything, and while it could be configured to steal passwords and other data, it’s focused entirely on crypto, and stealing it from the people who own it. 


Timing Is Everything: Ransomware Cripples Colombia Ahead of Inauguration

On August 2, 2026, Colombia’s Ministry of Justice confirmed that a ransomware attack had infected and encrypted files on several public-facing servers, mostly disrupting services around drug monitoring and other drug-related legal processes, according to Dark Reading. At any other time, it would just be another ransomware attack on a government system, the kind we’ve become all too familiar with in recent years. Unfortunately, the country was scheduled to inaugurate a new president five days later. The ministry denied at the time that any information had actually been stolen, but the encryption was serious enough, and government security teams were working to recover the data. 

Latin American countries have been targeted by cyberattacks recently, especially Colombia and Venezuela, as hackers look to steal data, cripple government systems, or just take advantage of unrest, elections, or other national events. Additionally, security researchers suggest that some of these attacks are extremely organized and automated, and may be carried out by state-sponsored hackers. 


Have a Security Question? Ask Me About It!

Do you have a question about online privacy or security? I'm here to help! You can submit your question here, and I may answer it in an upcoming SecurityWatch column and newsletter. If you're not subscribed to the newsletter, head here to sign up, and check back each week for the latest updates from PCMag's security team. Now, on to this week's question!

Geoff T asks: "Hi Alan. What is the hardest combination of [password] characters you have seen used on a public website? I've not seen one higher than 14 characters personally."

Hi Geoff, thanks for your question! In my experience, 12 to 14 characters is pretty standard across the public web, although I did see a forum once that required a 20-character password, which I found both funny, given the forum wasn’t exactly important or sensitive, and a good testament to the security-mindedness of its owners. 

I’ve definitely seen sensitive systems that demand even stronger passwords, and I checked with Kim Key, PCMag's senior security writer who handles password manager reviews, and we both recommend setting your password manager to generate passwords that are at least 20 characters long, complete with letters of mixed case, numbers, and special characters. That should cover your bases no matter where you roam on the web, including spots you want to keep secure, like banking sites, shopping sites you use frequently, email accounts, and anywhere else you want to keep safe. Although I’ll admit I did stumble upon one banking website where 20 characters were actually too strong, and I had to dial it back to 14. That was a little disappointing! 

Dernière Minute

Ne manquez aucune actualité de dernière minute

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Sourced by

Originally reported by PCMag UK

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

Articles Liés