P0 Labs found that ChatGPT's Markdown rendering can turn any page a user asks it to summarize into a phishing form. Trust in the AI's output is the attack surface.
securitySunday, June 21, 2026
ChatGPT phishing, AI agent flaws, and Secure Boot deadline
Today's security roundup is a triple threat: AI interfaces are now being weaponized for phishing, three major AI agent frameworks have critical exploits in the wild, and a Secure Boot certificate deadline looms. Plus, an unpatchable iPhone exploit and a $7.5 million MEV bot heist add to the chaos.
AI as attack surface
Two stories today show AI systems themselves becoming the vector, not just the target.
Three popular AI agent frameworks, LangGraph, Langflow, LangChain, have SQL injection and path traversal bugs being actively exploited. Attackers can steal API keys and achieve RCE on servers.
Supply chain and hardware
Meanwhile, foundational trust mechanisms are cracking, from silicon to certificates to code provenance.
The usbliter8 exploit targets an unpatchable SecureROM flaw in A12/A13 chips. No software fix can close this door on iPhone XR through 11.
Three Microsoft-signed Secure Boot certificates expire June 24. Systems that don't update may fail to boot or lose protection against UEFI malware.
Booz Allen warns that code from Chinese AI models may contain hidden vulnerabilities, introducing supply chain risks for U.S. developers and federal agencies.
Also today3
DLL Sideloading Unmasked: How Attackers Hijack Trusted Windows Processes And How You Can Stop Them + Video -undercodetesting.com
Ethereum's biggest 'sandwich' bot drained of $7.5 million in ironic exploitwww.coindesk.com
When The 'Report Phishing' Button Becomes The Phishing Link – A Deep Dive Into The Irony Ofundercodetesting.com
More roundups that day
war & conflict roundupUkraine strikes deep into Russia and Crimea
privacy roundupLicense plate readers get Bluetooth tracking
privacy & surveillance roundupFacial recognition and license plate tracking expand
AI fighter jets and legal token boom
comics roundupSpider-Man #1000 cover drama dominates comics news
ai ethics roundup