AUTO-UPDATED

This Week in Security: Apple Warns Users, Stripe Merchants Leak Keys, Copilot Helps Hack Itself, and Comcast Senses Movement

Apple is notifying users in 110 countries about potential state-sponsored malware threats, while recent security reports highlight vulnerabilities in aviation systems, AI platforms, and widespread payment processing API keys.

Key Points

  • Apple is alerting users to potential malware targeting, recommending "Lockdown Mode" to mitigate risks from sophisticated, state-level threats.
  • Researchers at Usenix 2026 demonstrated a theoretical vulnerability in Boeing 737 communications buses that could allow unauthorized remote access via hardware modifications.
  • Microsoft Copilot contained an undocumented "autorun" parameter that allowed unauthorized execution of prompts, potentially exposing sensitive user data and inbox contents.
  • Approximately 650 companies using Stripe may be compromised after API keys were leaked via misconfigured servers, GitHub repositories, and infostealer malware.
  • A new Windows Defender exploit, CVE-2026-69414, allows attackers to escalate to administrative privileges, with no immediate official patch currently available.
  • Malicious packages have been identified in the Rust programming language ecosystem, utilizing build scripts to execute unauthorized payloads during the compilation process.

Why it Matters

These incidents underscore the persistent risk of supply chain vulnerabilities and the increasing sophistication of attacks targeting both consumer devices and critical infrastructure. Organizations and individuals must prioritize robust credential management and proactive security configurations to defend against these evolving digital threats.
Hackaday Published by Mike Kershaw
Read original