AI attacks, SaaS leaks, Public WiFi, and Critical Patches

by | Jul 31, 2026 | Security Alerts | 0 comments

Five security stories stood out this month with each pointing to practical steps businesses can take:

  • Generative AI is now acting on its own. We learned this month that both Claude and OpenAI’s models escaped their sandbox and autonomously attacked at least 4 unsuspecting businesses.
  • Default settings in SaaS systems may expose your organization to unexpected risk. We learned that a default setting in SharePoint online could allow unauthorized users and AI agents to access documents. We also learned that settings in Claude AI could allow users to inadvertently share private chats to the internet making them available in search results.
  • Public guest WiFi networks are being used to steal user credentials. We learned how attackers are compromising public WiFi Captive Portals to capture credentials to online accounts like Google and Microsoft.
  • What’s in your office? IoT devices can lead to real harm and data disclosures for homes and businesses. We learned that a Shark vacuum flaw allowed a potential attacker to gain control over other vacuums and map homes and businesses and potentially access video, audio, and location data.
  • This month also brought an unusually high volume of critical security updates requiring timely patching. Microsoft, Apple, Google, Zoom, 7-zip, Unifi and others continue their drumbeat of releases.

 

Here’s what happened, why it matters and what to do.

  1. News broke that Hugging Face, an open-source AI repository, was attacked by OpenAI’s AI model compromising their systems and taking services offline. The OpenAI model had escaped an isolated testing environment by discovering a vulnerability in the JFrog repository available within the environment. It also came to light that Claude’s AI model had also breached real company systems during its testing.

    What do I need to do: The terrifying thought of losing control of AI and it attacking legitimate businesses and people is unescapable.  However, business should treat this risk like any other risk and have a practiced Incident Response plan. The reality is OpenAI and Claude didn’t discover a novel vulnerability to execute their attack. They used known vulnerabilities and misconfigurations. The best defense remains a mature security program supported by a practiced incident response plan.

 

  1. Microsoft disclosed that a default SharePoint Online configuration can allow unintended access to document libraries. A feature called Everyone except external users or EEEU is a security group that includes all internal users. The EEEU group gets applied to all Microsoft Group Document libraries. Default settings allow all users to create Public Groups tied to Teams. Many users may not understand that anything within that group is discoverable by other users, Microsoft Copilot, enterprise search, and any attacker who compromises a single account.

It was disclosed this month that personal Claude chats, some with sensitive information, were available in search engine results. This is due to the Share chat feature, which generates a URL that can be shared with other people. The URL is a long unique string that would not be discoverable on its own. However, when placed in other publicly accessible locations like social media, and forums, search engines will discover the full content and make them available in search results.

What do I need to do: Businesses should not assume that the default settings in SaaS or Cloud platforms are secure. Reviewing and hardening settings in any hosted solution is critical to ensuring businesses mitigate and understand their risk. Specifically:

    • Claude business accounts can limit Public Sharing settings. At a minimum, sharing should be limited to internal organizational users. Similar settings should be enabled in OpenAI ChatGPT.
    • Users should not be using personal or free AI accounts. Business accounts should be used to enforce policies to manage and limit risk and exposure.
    • Businesses that utilize Microsoft 365 should audit their SharePoint sites for any sites with the EEEU user security group and remove it unless there is a specific business case. Businesses should evaluate if limiting Group creation to only specific users is an option.
  1. Public WiFi can be risky, and NO, privacy VPNs do not provide meaningful security with them. Attackers are leveraging public WiFi to steal credentials by compromising Captive Portals. Captive Portals are the screens that pop up requesting you register or supply authentication information to access the free WiFi. Many Captive Portals will ask for your Cloud based credentials. While they may be redirecting you to legitimate Microsoft, Google, Apple or other Cloud based systems, because they control the session, they’re able to steal session keys and other sensitive information in the transaction.
    What do I need to do: Educate users about the risks of using public WiFi and provide guidelines on their safe use. Users should never provide personal information or Cloud credentials in a Captive Portal. Develop and distribute policy around public WiFi use and issue personal hotspots to users who travel frequently and require secure Internet.
  1. A security researcher discovered that he could use a Shark Vacuum to access other vacuums by using the secure session his vacuum used to talk with the Shark online systems. By doing so, he could access other vacuums in his region, access mapping data and video streams and potentially spy on his neighbors. We also know that in many office buildings we see a proliferation of smart TVs, vending machines with cameras, microphones and other connected devices. All these IoT connected devices may be introducing risk to our businesses we hadn’t considered. Where do privileged conversations take place? Do we have confidential or sensitive information on white boards?

What do I need to do: Ask yourself, what’s in your office? Consider whether sensitive conversations, whiteboards, or confidential information could be exposed through connected devices. If you have work from home users having sensitive conversations, are they at risk of exposing company data? Specifically you should:

    • Have a policy around physical spaces and where and what information can be shared.
    • Limit the use of IoT devices in corporate spaces.
    • Have a policy and discuss with Work from Home users about securing their environments and not having private conversations in public spaces.
  1. Microsoft, Google, Apple, Adobe, Zoom, 7-Zip, and Unifi all disclosed many high severity patches this month.  Microsoft released patches for a record 570 flaws including 3 zero day vulnerabilities. Apple released patches for almost 200 vulnerabilities across it’s MacOS and iOS devices. Google released patches to address 1,072 bugs.

 What do I need to do: For clients using our security and management tools, supported computers should already be receiving updates. Users should install updates promptly and avoid postponing or dismissing update prompts. Updates can be manually installed following the directions below:

QuickTip: NEVER post personal information or financial data into AI chatbots like ChatGPT, Gemini or Claude. It may be tempting to use AI for financial, legal, HR, or other sensitive questions, but doing so may expose confidential information and produce inaccurate or misleading guidance.

I’d appreciate your feedback on the new format. My goal is to make these alerts as focused, practical, and actionable as possible.

Full sourcing available if you want to dig into any of these — just ask.

 

Related posts

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *