📝 Show notes
CyberAware Daily — 2026-09-09
- Microsoft patches nearly 1,000 security holes in latest update, urging users to restart devices
- ChatGPT flaw allows planted prompts to forward Gmail data to third parties
- 'Slim Spider' steals crypto custody secrets from Brazilian financial institution
- Liquid hackers return part of stolen Bitcoin but still hold over $47 million
- Actionable tip: Review app permissions and complete Windows updates today
More at https://cyberawareuk.co.uk
📄 Full transcript
Morning, everyone, and welcome to CyberAware UK.
I am your host, and today is Wednesday, which means we're digging into the freshest intel
from our Darkwatch feeds.
And, as always, Alex is here to keep me honest.
That's right.
And we've got some big ones today.
Microsoft has plugged nearly a thousand security holes.
That sounds like a lot of patchwork, doesn't it?
It does, but it's actually just the regular monthly round of updates.
Think of it like a big spring clean for your software.
The key is to make sure your Windows devices actually install these updates, because cyber
criminals are always counting on the fact that you won't.
So, patching is still the boring, but vital task we all need to do.
But what else is new?
I heard something about a ChatGPT flaw that could actually send your Gmail data to someone
else.
You're right, Alex.
Researchers found that a planted prompt, a sneaky instruction hidden in a web page, could
trick ChatGPT into forwarding a victim's Gmail data to another account.
It's a reminder that even AI tools need a careful eye on what they're allowed to access.
That's scary, because I use ChatGPT for loads of stuff.
What can I do to protect myself?
First, avoid clicking sketchy links while you're logged into ChatGPT.
Second, check which apps and services have permission to access your email.
If something doesn't need that access, revoke it.
It's like checking who has the keys to your house.
Good advice.
And there's a story about a Brazilian crypto firm that lost custody secrets to a group they're
calling Slim Spider.
Exactly.
This group targeted a financial institution in Brazil and walked away with the secrets to
their crypto custody system.
The lesson for everyone, even in the UK, is that crypto platforms are high-value targets.
If you hold crypto, use a hardware wallet or a reputable exchange that keeps most funds offline.
And what about the liquid hackers?
They returned some Bitcoin after a bug, but they're still holding millions.
That story is a classic.
Hackers exploited a flaw in the exchanges system and made off with a huge sum.
They returned a fraction of it, probably to try to reduce the heat,
but they're still sitting on nearly $47 million worth of Bitcoin.
It's a reminder that crypto exchanges are not banks, and they're not insured in the same way.
So, what's the one thing we should all do today, after listening to this?
Make a cuppa, sit down, and check your digital permissions.
Go through your Google account, your ChatGPT settings, and your social media,
and revoke access for any app you don't recognize or no longer use.
And then, if you haven't already, restart your computer to finish those Windows updates.
That's the single best defense against a whole load of scams.
Simple.
I am on it after this.
Thanks for joining us, and remember, stay alert, stay safe, and stay savvy.
And if you found this helpful, share it with someone who needs it.
We'll see you tomorrow for another deep dive.
Take care.
Take care.