Sunday, June 7, 2026
Daily digest
New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration
OpenAI is rolling out a Lockdown Mode for ChatGPT that restricts tool access to reduce data exfiltration risk from prompt injection attacks. The feature targets users and organizations handling sensitive data. Admins in controlled environments should evaluate whether this mode aligns with CUI handling policies before permitting ChatGPT use on managed endpoints.
Critical Everest Forms Pro flaw exploited to take over WordPress sites
Attackers are actively exploiting CVE-2026-3300, a critical vulnerability in the Everest Forms Pro WordPress plugin, to achieve full site takeover. If any WordPress instances exist in your environment — including vendor portals or internal sites — patching or disabling the plugin should be treated as urgent. Active exploitation means this is not a wait-and-see situation.