Patch these two now: CoSnitch in Copilot, and CVE-2026-65346 in Apple ImageIO
One sat known for eight months. The other needs no interaction beyond receiving an image. Neither is theoretical.
Section
Vulnerabilities worth patching today, breaches worth understanding, and the widening overlap between AI capability and offensive tooling.
One sat known for eight months. The other needs no interaction beyond receiving an image. Neither is theoretical.
Astra approached a "critical" cybersecurity threshold and OpenAI halted training workloads and tightened sandbox isolation. Three weeks earlier it had dissolved the team whose job was to make that call.