TWO notable items in SecurityWeek’s weekly round-up concern iCloud email spoofing flaws and a suite of privacy concerns around AI chat data, alongside several other security briefs. SEC Consult disclosed two iCloud vulnerabilities that allow forging From addresses so emails appear to come from arbitrary icloud[.]com identities, bypassing SPF, DKIM and DMARC checks.
Apple paid a $15,000 bug bounty for the discovery; the issues stem from differences in how two parts of Apple’s outgoing mail pipeline parse messages, with the first vulnerability reported in May 2024 and only fully fixed by December 2025.
In the same briefing, researchers highlighted that a popular Chrome adblocker, Poper Blocker, can siphon full browsing histories and ChatGPT, Claude, Gemini and Google AI conversations via a data-sharing prompt, with the extension executing a custom interpreter loaded from the vendor’s server to control what is collected and where it’s sent.
Additional items cover a range of issues: Microsoft’s 2026 Digital Defense Report notes phishing growing as an initial access vector and that AI has accelerated weaponisation timelines, with a forecast of around 72,000 CVEs for the year and government agencies accounting for a substantial share of observed activity; Kiteworks published over 100 advisories on its Core platform, Email Protection Gateway and other components, with many critical or high-severity flaws tied to account takeover, code execution and internal access.
Other highlights include GitHub Security Lab reporting 24 vulnerabilities in Android apps via its AI security agent, and Proofpoint tracking a China-aligned group phishing AI-policy experts using impersonation and adversary-in-the-middle tactics.