TheCyberExpress

TCE Weekly Roundup: Iran Bounty, Airline Leak, ChatGPT Flaw


This weekly roundup covers a bounty offer targeting an alleged Iranian cyber official, a massive data-exposure incident affecting airline travelers, a breach of an education platform used by students, a flaw exposing ChatGPT users’ Gmail data, and a new EU compliance deadline for connected-product manufacturers. 

From nation-state attribution efforts to AI-model exploitation and airline record exposure, this week’s developments show how identity data, cloud misconfigurations, and AI infrastructure all remain prime attack surfaces — while regulators tighten disclosure timelines. 

The Cyber Express Weekly Roundup 

US Offers $10 Million for Alleged Iranian Cyber Chief 

The State Department is offering $10 million for information on Amir Yaryab, accused of directing the IRGC-CEC’s Cyber Operations Command and overseeing groups including CyberAv3ngers, which has previously claimed attacks on industrial control systems and critical infrastructure in the US, Israel, and elsewhere, including exploitation of default credentials on Unitronics PLCs. Read more… 

Mathspace Breach Exposes Data on Over 1 Million Users 

A vulnerability in a self-hosted Metabase reporting tool let attackers gain administrator access without logging in, exposing names, emails, and account metadata for more than 1 million students, parents, and teachers in Australia and New Zealand. Passwords and authentication tokens were not affected, and Mathspace has notified regulators in both countries. Read more… 

220 Million Airline Passenger and Crew Records Exposed 

A misconfigured, inconsistently secured Elasticsearch cluster left roughly 220.8 million passenger and crew records — including passport numbers and full itineraries spanning nine years — reachable over the internet before researchers helped get it secured in June. The server’s origin remains unconfirmed, though it was linked to Vietnamese IP space. Read more… 

ChatGPT Sandbox Flaw Let Attackers Read Victims’ Gmail 

Check Point Research found that a shared internal package-caching system let separate ChatGPT sessions pass messages to each other, allowing a planted prompt to instruct a victim’s session to fetch Gmail data and hand it to an attacker’s account — without any visible confirmation step. OpenAI has since decommissioned the affected instance. Read more… 

EU’s 24-Hour Vulnerability Reporting Rules Take Effect 

Manufacturers of connected products sold in the EU must now report actively exploited vulnerabilities within 24 hours under the Cyber Resilience Act, more than a year ahead of the law’s full 2027 rollout. Non-compliance can draw fines up to €15 million or 2.5% of global revenue. Read more… 

AI Just Broke Crypto: What’s Next for Defenders and Attackers Alike

Weekly Cybersecurity Takeaway 

This week’s developments show attackers and regulators converging on the same weak points: identity data sitting in exposed or under-secured systems, and AI platforms whose infrastructure — not their models — created the exploitable gap. The Mathspace and airline incidents both trace back to unpatched or misconfigured backend systems rather than sophisticated intrusion techniques, while the ChatGPT flaw shows that shared infrastructure underlying AI services can become a cross-account attack surface even when the model itself behaves correctly. 

Meanwhile, the Yaryab bounty and the EU’s new reporting clock reflect a parallel push on the policy side — attribution efforts aimed at raising the cost of state-linked attacks, and regulation aimed at compressing how long vulnerabilities can sit unreported. Organizations should treat backend admin tools and internal caching layers with the same scrutiny as customer-facing systems, and multinational manufacturers should confirm their incident-response playbooks account for the new EU timelines now in effect. 



Source link