Roundup: iCloud Spoofing, AI Policy Phishing, and Ad Blocker Data Theft
This week's cybersecurity news includes critical iCloud spoofing bugs, a phishing campaign targeting AI policy experts, and an ad blocker found to be spying on AI chat data.

SecurityWeek's latest roundup highlights several significant cybersecurity developments, including critical vulnerabilities in Apple's iCloud service, a sophisticated phishing operation targeting AI policy experts, and a popular ad blocker extension that has been found to exfiltrate user data from AI chat sessions.
Researchers have uncovered two vulnerabilities within iCloud's email infrastructure that could allow attackers to spoof emails from arbitrary @icloud.com addresses. These spoofed messages successfully bypass sender authentication checks such as SPF, DKIM, and DMARC. The first vulnerability was initially reported in May 2024, but Apple's initial fix was incomplete, requiring a subsequent patch in December 2025. The company awarded a $15,000 bug bounty for the discovery.
In a separate incident, a phishing campaign has been identified that specifically targets AI policy experts. Threat actors, identified as China-aligned group TA419, impersonated prominent figures, including former White House OSTP Principal Deputy Director Lynne Edwards Parker and economist Heidi Crebo-Rediker, to lure targets at think tanks, universities, and law firms. The campaign utilized AI-generated content in its initial outreach and employed an adversary-in-the-middle (AitM) proxy to capture session cookies, even from users employing multi-factor authentication.
Further compounding concerns around AI security, a popular Chrome ad blocker extension named Poper Blocker has been found to be collecting sensitive user data. Researchers discovered that the extension, with over two million users, not only gathers full browsing history but also exfiltrates conversations from AI services like ChatGPT, Claude, and Gemini. The malicious data collection is managed by a custom interpreter within the extension, allowing operators to modify its behavior remotely without requiring an update.
Microsoft's 2026 Digital Defense Report indicates a significant increase in cyber threats, with phishing attacks tripling and the median time from vulnerability discovery to weaponization shrinking to under 24 hours. The report notes that AI is accelerating this trend, with an expected record number of CVEs this year. Government agencies remain the most targeted sector.
Kiteworks has also addressed a substantial number of vulnerabilities in its security advisories, publishing over 100 disclosures on September 30th. A dozen of these are rated critical, primarily affecting its Email Protection Gateway and potentially leading to account takeover or code execution. Numerous other high-severity issues were also detailed.
In other news, two U.S. Air Force members were sentenced to prison for their involvement in Business Email Compromise (BEC) attacks that defrauded victims of over $2.4 million. Separately, a vulnerability in Cloudflare's Containers and Sandboxes services allowed some customers to potentially view residual data from other customers' containers, though no malicious exploitation was found.
Finally, GitHub Security Lab has leveraged AI taskflows to identify 24 vulnerabilities in Android applications, including flaws in OsmAnd and the Wikipedia app, highlighting the growing role of AI in vulnerability discovery, albeit with a need for human oversight.