A Windows Defender flaw is waiting on a patch, Mac malware is taking over browser sessions you are already signed into, and ChatGPT's new Mac feature records your clicks and keystrokes
Microsoft is building a Defender patch for a flaw that hands over a whole PC
Microsoft has confirmed it is working on a security update for a flaw in the part of Microsoft Defender that scans for malware. The flaw, tracked as CVE-2026-69414 and referred to publicly as ShieldBreak, lets software already running on a machine with limited permissions raise itself to full system-level control, and it affects Windows 10, Windows 11 including version 25H2, and Windows Server. Defender has to be switched on for it to work, which on most home and small business PCs it is.
Two details set the shape of the risk. Working exploit code has been published, described by the researchers who found it as succeeding every time. But there are no reports of it being used in attacks, and it cannot be the way an attacker gets in — something unwanted has to be running on the machine first.
Why it matters: the fix is not out yet, so the useful action today is the one that decides whether anything gets the foothold this flaw needs. Open Settings, then Windows Update, and confirm updates are set to install automatically so the patch lands without you watching for it. Then treat the first step as the one that counts: do not run installers from download pages you were sent to, and do not paste commands into Terminal, PowerShell or a Run box because a website told you to. Check Windows Update manually in a week if you have automatic updates switched off for any reason.
Mac malware is taking over browser sessions you are already signed into
Security researchers at an Apple device management company have published an analysis of new Mac malware that goes after browsers rather than just files. It arrives through fake download pages, including pages made to look like GitHub, which hand over a password-protected archive and instructions to run something, and it collects saved passwords, cryptocurrency wallet data, keychain contents, notes and documents, along with the Mac's own login password. Profiles can be copied from Chrome, Edge, Brave, Opera, Vivaldi, Arc and Chromium.
The part that is genuinely new is remote control: it can run a hidden copy of your browser and drive your already-authenticated sessions live. An attacker sitting inside a session you have already signed into does not need your password, and does not need to pass your two-step verification, because you already did both.
Why it matters: the delivery method is the weak point, and it is entirely under your control. Never paste a command into Terminal because a web page, download page or error message told you to — that instruction is now one of the most common ways malware gets onto a Mac. Install software from the developer's own site or the App Store, not from a link in a search result or a message. If you have already run something like this, use a different device to change the passwords for your email, bank and any wallet, and use each service's "sign out of all sessions" option, because changing a password does not always end a session someone is already inside.
Sign-in prompts on hotel and conference Wi-Fi are being used to get past two-step verification
A published investigation describes attackers taking administrative control of Wi-Fi equipment at hotels and conference centres and changing the network's DNS settings — the part that decides which server your browser actually reaches when you type an address. Traffic was redirected to convincing copies of the Microsoft 365 sign-in page on lookalike domains, and some people were pushed into a device-code sign-in, where approving the prompt authorises a session the attacker started rather than one you did. That last step is what makes it serious: two-step verification does not stop it, because you are the one approving. Affected venues were found in several US cities, in India and in Saudi Arabia, and the businesses caught by it span finance, legal, healthcare, energy and retail.
Why it matters: this is a working-away-from-the-office problem, so it lands on anyone who travels for a job or a conference. Two rules cover most of it. First, never approve a sign-in prompt, code or notification you did not start yourself — if one appears unprompted, decline it and change your password from a network you trust. Second, do your work-account sign-ins over your phone's hotspot or a full-tunnel VPN rather than the venue Wi-Fi, and reach services by typing the address or using a bookmark instead of following whatever page the network puts in front of you.
ChatGPT's new Mac feature records clicks and keystrokes, and stores it unencrypted
OpenAI has added a feature to the ChatGPT app for Mac that builds a searchable record of what you do on your computer so the assistant can refer back to it. The company's documentation says Computer History records clicks, typing, keyboard shortcuts, app switches and context the Mac's accessibility system exposes, and that it does not capture screenshots, screen recordings, microphone input or system audio. It is off by default, on macOS only, for Pro, Business and Enterprise subscribers — Pro users can switch it on themselves, while on business and enterprise accounts an administrator has to grant access first — and it is not available in the European Economic Area, Switzerland or the UK. Private browsing is never included, collection can be paused, individual apps and websites can be excluded, and history can be deleted in blocks or entirely. Wider reporting notes the record is intended to give both ChatGPT and its coding tool the context of recent work.
One detail in that documentation deserves attention before anyone turns it on. The memories it produces are stored on the Mac as plain-text files, and the company states plainly that they are not encrypted and that other programs running as your macOS user may be able to read them. Temporary event files are kept up to 48 hours; those are not used for training, though chat content drawing on memories follows the account's own data controls.
Why it matters: the trade is genuine — an assistant that remembers what you were doing is more useful — but the record it keeps is a plain-text log of your typing sitting on the machine, and that changes what a single piece of malware like the one above walks away with. If you switch it on, use the exclusion list first and keep out banking, accounting, health and client-record apps, and do not enable it on a Mac account that other people log into. If you run a business on these subscriptions, the administrator setting is the decision point — make it deliberately rather than discovering later that it was available.
Hardware crypto wallet owners' home addresses were taken from shipping partners
Two hardware wallet makers have told customers that data was stolen from companies handling their deliveries. The information taken includes names, home addresses, email addresses and phone numbers, and the concern raised is twofold: targeted phishing sent to those addresses and numbers, and the physical risk that comes from a list of people known to hold cryptocurrency. One of the two breaches has been reported as affecting 39,798 customers, with the stolen information offered for sale.
Why it matters: if you own a hardware wallet, assume the people contacting you know what you bought and where you live, which is exactly what makes the next message convincing. Treat any call, text, email or posted letter about your wallet, a security check or a required firmware step as fraud until you verify it yourself through the manufacturer's own site. Never type, photograph or read out a recovery phrase for any reason — no legitimate company will ever ask for it, and a genuine device never needs it entered into a computer or a web page. The same reasoning applies more widely: a breach at a courier or fulfilment partner can expose a customer list belonging to a business that was never breached itself, so it is worth knowing which suppliers hold your customers' addresses.