vibehacker
News
IMDEA Networks ·

Study: ChatGPT, Claude, Gemini leak chat artifacts to ad trackers

IMDEA Networks and UC3M found six of nine chatbot web apps (ChatGPT, Gemini, Claude, Grok, Perplexity, Mistral) send conversation titles, prompts, or screenshots to ad/analytics trackers—often with persistent IDs. Cookie rejection barely helps; Grok was worst, exposing public share URLs to seven trackers by default.

More news

View all

Vercel AI Gateway adds Claude Sonnet 5.5 for coding agents

Vercel’s Sept 28 changelog puts Anthropic’s Claude Sonnet 5.5 on AI Gateway as anthropic/claude sonnet 5.5 , with Zero Data Retention supported. Wire it via the AI SDK, Chat Completions, Responses, or Anthropic Messages APIs, or run npx vercel ai gateway setup and pick it in Claude Code or fx…

Vercel Changelog

MCP Python SDK flaw lets malicious servers steal OAuth credentials

The official MCP Python SDK (1.9.1–1.29.1 and 2.0.0–2.1.1) could send client secrets, auth codes, and PKCE keys to an attacker controlled token endpoint when connecting over HTTP OAuth. Fix is 1.30.0 / 2.2.0; ClientCredentials and PrivateKeyJWT users must also set issuer=, clear stored registrations, and rotate secrets if they connected to untrusted servers…

The Hacker News

Perplexity red-teams SPACE: no VM escapes, four models bypass egress

Perplexity’s Escaping SPACE Part I gave nine models root in the sandbox behind Perplexity Computer: no VM to host escape in 108 runs. With partial network access, four models (Opus 5, GPT 5.6, Kimi K3) reached a blocked URL via DNS spoofing or shared IP OCR; both paths were patched, and 8 of 10 other sandboxes shared the IP issue…

Perplexity

ZCode finishes remediation: cloud data wiped, opt-in uploads only

Zhipu said ZCode’s Alibaba Cloud OSS bucket from the workspace upload incident is gone (verified by CAICT and NSFOCUS), open source ZCode is at 3.14.3 under Apache 2.0 with a “no upload unless the user starts it” rule, and paid users get quota reset cards plus 100M token packs through Oct 7…

TechNode

Spotted something we missed? Start a thread.