Daily Breach

Vulnerability

Claude Desktop Extensions Zero-Click RCE Flaw Exposes Over 10,000 Users to Silent System Takeover

Introduction A newly disclosed zero-click remote code execution vulnerability in Claude Desktop Extensions has revealed a critical security weakness in how modern Large Language Model ecosystems handle trust boundaries. The issue allows attackers to fully compromise a victim’s system using nothing more than a malicious Google Calendar event, with no direct interaction or suspicious prompts […]

Crime & Fraud

UK Regulator Launches Probe Into X Over Grok AI Deepfake Abuse

Introduction The UK’s data protection authority has opened a formal inquiry into X and xAI following reports that the Grok artificial intelligence system was used to generate sexual deepfake images without consent. The move signals escalating regulatory scrutiny over generative AI tools and their misuse. Background and Context The investigation is being led by the […]

Cyber Weekly Legal & Policy

ISO/IEC 27701:2025 — Privacy Takes Center Stage: A Standalone PIMS Standard

Introduction On 14 October 2025 the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) published the second edition of ISO/IEC 27701:2025 — Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance. The revised standard transforms privacy from an extension of information security into a fully standalone, […]