Last seen August 28, 2026

Google Authentication Bypass

New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis The Hacker News

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis The Hacker News

Why This Matters

The evidence matters to defenders using Google because it could allow access without the expected authentication controls.

Recommended Action

Confirm whether jun is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Aug 28, 2026 16:50

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

AppleBraveGoogleMicrosoftMozillaOpenAI

Authoritative Intelligence

CVE CVE-2026-58231 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ€” it does not fetch or display exploit code.

Timeline

  • Incident first seen
    Jun 25, 2026 12:30

    BugSkan first recorded this incident.

  • New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis - The Hacker News
    Jun 25, 2026 12:30

    news.google.com ยท Vulnerability

  • Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
    Aug 28, 2026 16:50

    thehackernews.com ยท Data Leak

  • Latest observed development
    Aug 28, 2026 16:50

    Most recent source or update associated with this incident.

Sources

New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis - The Hacker News

news.google.com ยท Jun 25, 2026 12:30

New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis The Hacker News

Open publisher source
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

thehackernews.com ยท Aug 28, 2026 16:50

ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence