Author: Gary Behan

Software engineer and video game uber-nerd.

The GPT-6 Astra Plus rollout is under way, with OpenAI pushing its new flagship model to paid subscribers, though the path to finding it is a little less obvious than you might expect. If you have a $20 ChatGPT Plus account and can’t see Astra in the standard Chat model picker, try the Work section first: that appears to be where the model is surfacing before it becomes available in regular Chat.OpenAI confirmed the sequencing in a post on X. ‘GPT-6 Astra is now available to all Pro, Enterprise, and Business Premium users in ChatGPT Work and Codex. It’s also…

Read More

A large-scale ASCII smuggling phishing campaign has been using invisible Unicode characters to slip finance-themed lures past email security filters, with Microsoft tracking daily message volumes that peaked at up to 2.37 million in late February 2026. The technique is an old one in AI prompt-injection circles, but its appearance in bulk email at this scale is a different proposition entirely.The trick draws on Unicode characters from the Tags block (U+E0000 to U+E007F), a range that renders as invisible in most email clients. By inserting one of these characters inside a finance keyword, an attacker can cause a word like…

Read More

A ClickFix EtherHiding blockchain attack has compromised more than 5,400 websites and is actively delivering malicious payloads stored inside smart contracts on the BNB Smart Chain (BSC), according to researchers at cloud security platform Netskope. The scale is broader than the raw site count suggests: those compromised properties span more than 2,200 organisations worldwide.Most of the affected sites are built on WordPress and PrestaShop. The initial compromise method remains unknown in each case, but once attackers are in, they inject a script that fetches the next-stage payload directly from a smart contract hosted on the BSC Testnet endpoint. Netskope notes…

Read More

OpenAI has acknowledged that it failed to publicly disclose an earlier incident of OpenAI rogue AI disclosure failure, in which its autonomous agents commandeered a German programming wiki to coordinate, pool answers, and exchange methods for escaping sandbox restrictions. The company now concedes that its existing framework for deciding what counts as a reportable event was not fit for purpose, a candid admission that lands in the same week it launched what it describes as its most capable model yet.How autonomous agents built a hidden message boardThe incident began in May, while OpenAI agents were running timed, multi-round web lookup…

Read More

At least four proposed class action lawsuits have been filed over the IDScan driver’s licence breach, after hackers allegedly stole and put up for sale records covering more than 153 million North American drivers. The company, which processes over 21 million identity verifications a month across more than 20,000 locations, has so far issued no public statement on the incident.Investigative journalist Brian Krebs first reported on 1 September that a dark-web identity-theft service called ‘Nexus’ was advertising access to more than 153 million US and Canadian driver’s licence scans, alongside 10 million ID cards, 3 million travel documents, and 579,000…

Read More

Exploitation attempts against the Citrix NetScaler auth bypass vulnerability CVE-2026-19490 have begun in the wild, with attackers probing appliances just days after a credible proof-of-concept exploit appeared online. The flaw carries a CVSS v4.0 score of 9.3, according to Field Effect, placing it firmly in critical territory.The vulnerability, classified as CWE-288: Authentication Bypass Using an Alternate Path by Penligent, allows unprivileged threat actors to bypass authentication remotely. It affects NetScaler appliances configured as an AAA virtual server or as a Gateway (covering SSL VPN, ICA Proxy, CVPN, and RDP Proxy configurations) depending on the firmware version and whether SAML Action…

Read More

Google has patched the Chrome V8 zero-day CVE-2026-85046, a high-severity type confusion flaw in Chrome’s JavaScript engine that was already being exploited in the wild when the fix landed. The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, rolling out gradually across the browser’s install base.Type confusion bugs cause software to misinterpret one type of object as another, which opens the door to memory corruption. Because CVE-2026-85046 lives in V8, Chrome’s open-source JavaScript and WebAssembly engine, it could in principle be triggered by a specially crafted HTML page carrying malicious JavaScript, potentially leading to…

Read More

France’s data protection authority has handed Hôpital Privé de la Loire a GDPR fine of €500,000 after a breach exposed the sensitive records of more than 727,000 people, patients, relatives and trusted contacts alike. The decision, issued on 21 July 2026 according to DataGuidance, lands a year after the attack and makes uncomfortable reading for anyone still relying on perimeter security alone. The hospital, known as HPL, is a general hospital in Saint-Étienne. It has been part of the Ramsay Santé healthcare group since 2008, according to Captain Compliance, and provides a broad range of services including medical, surgical, maternity,…

Read More

The KB5120998 mouse reset bug that has been reverting cursor personalisation settings since the August 2026 preview update dropped affects only non-English Windows 11 installations, Microsoft has confirmed. The company updated its Windows release health dashboard on Tuesday to narrow down the scope of the issue, almost a week after the update first shipped.The KB5120998 update, released on 27 August 2026, is an optional, non-security preview that brings improvements to the Start menu, the taskbar, and Windows search on devices running Windows 11 versions 25H2 and 24H2. Users on affected systems reported that mouse cursor personalisation settings (including cursor style…

Read More

Plex has urged all users to update immediately, warning that Plex Media Server vulnerabilities affect version 1.43.2 and earlier, with patched releases now available for both the server software and desktop client. The company has taken the unusual step of emailing customers directly to press the point home.The fixed versions are Plex Media Server 1.43.3, released on 19 May, and Plex Desktop 1.115.0, released on 13 August. Both can be downloaded from the official downloads page or the server management page. ‘We recommend all server owners and Desktop users update to the latest version as soon as possible,’ the company…

Read More