A prompt injection flaw in the AI feature of the workforce collaboration suite makes malicious queries of data sources appear legitimate.
Автор: Elizabeth Montalbano, Contributing Writer
Microsoft Copilot Studio Exploit Leaks Sensitive Cloud Data
A server-side request forgery (SSRF) bug in Microsoft’s tool for creating custom AI chatbots potentially exposed info across multiple tenants within cloud environments.
US Intelligence Blames Iran for Hack on Trump Campaign
Feds confirmed Iran’s involvement in email attack against Roger Stone after Microsoft, Google reported Iranian APT action against both presidential campaigns.
Google: Iran’s Charming Kitten Targets US Presidential Elections, Israeli Military
The threat group tracked as APT42 remains on the warpath with various phishing and other social engineering campaigns, as tensions with Israel rise.
GitHub Attack Vector Cracks Open Google, Microsoft, AWS Projects
Cloud services and thus millions of end users who access them could have been affected by the poisoning of artifacts in the development workflow of open source projects.
FBI Shuts Down Dozens of Radar/Dispossessor Ransomware Servers
Computer infrastructure in the US, UK, and Germany associated with the cybercriminal group, which targeted SMBs using double extortion, is officially out of commission.
FBI Shuts Down Dozens of Radar/Dispossessor Ransomware Servers
Computer infrastructure in the US, UK, and Germany associated with the cybercriminal group, which targeted SMBs using double extortion, is officially out of commission.
APT41 Spinoff Expands Chinese Actor’s Scope Beyond Asia
Earth Baku, yet another subgroup of the highly active and increasingly sophisticated collective, is moving into EMEA with new malware and living-off-the-land (LOL) tactics.
‘0.0.0.0 Day’ Flaw Puts Chrome, Firefox, Mozilla Browsers at RCE Risk
Attackers can use a seemingly innocuous IP address to exploit localhost APIs to conduct a range of malicious activity, including unauthorized access to user data and the delivery of malware.
Chameleon Banking Trojan Makes a Comeback Cloaked as CRM App
The evolving malware is targeting hospitality and other B2C workers in Canada and Europe with capabilities that can evade Android 13 security restrictions.