Aggregator
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
3 days 7 hours ago
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session.
The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced
The Hacker News
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
3 days 7 hours ago
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts.
According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows -
The Hacker News
Крупнейший сбой в Рунете: авария в районе М9 и падение Рег.ру отключили тысячи сайтов
3 days 7 hours ago
Рунет посыпался после проблем с электричеством в Москве, след ведет к ТЭЦ-20.
Medical Imaging Backup From Beijing's 301 Hospital Offered for Sale, With an Unverifiable Headline Claim
3 days 7 hours ago
A forum user posting as Knox is offering what they describe as backup data taken from the Chinese PLA General Hospital in Beijing, commonly known as 301 Hospital.
Dark Web Informer
Пользуетесь бюджетным Android смартфоном? Один ответ на видеозвонок дает хакерам полный root-доступ
3 days 7 hours ago
Опасная дыра нашлась в каждом 7-м телефоне мира.
Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
3 days 7 hours ago
The updated warning from the FBI, CISA and HHS draws on a year’s worth of investigations to detail how the group gains initial access and what it does afterward.
The post Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics appeared first on CyberScoop.
Tim Starks
Лидар, прицел и синий луч над подушкой. В Китае создали домашнюю систему ПВО от комаров за тысячу долларов
3 days 7 hours ago
Стартап предлагает выжигать комаров лазером прямо в полете.
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
3 days 7 hours ago
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000.
"In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," GuidePoint Research
The Hacker News
Один тумблер в настройках. В Firefox на iPhone появилась встроенная защита от назойливых баннеров
3 days 8 hours ago
Скачивать сторонние утилиты больше не нужно.
Merchant Data From Hundreds of Stripe Accounts Allegedly Exported Using 1,033 Compromised API Keys
3 days 8 hours ago
A forum user posting as Satanic has published what they describe as 662 datasets totalling 33GB, exported from Stripe merchant accounts using 1,033 compromised API keys.
Dark Web Informer
Один грамм ДНК вмещает 215 млн гигабайт. Теперь из неё собрали работающий чип памяти
3 days 8 hours ago
А ещё она потребляет в 100 раз меньше энергии...
SecWiki News 2026-08-18 Review
3 days 8 hours ago
今日暂未更新资讯~
更多最新文章,请访问SecWiki
更多最新文章,请访问SecWiki
科技云报到:机器流量首次超过人类,互联网进入“三体流量时代”?
3 days 9 hours ago
科技云报到
Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed
3 days 9 hours ago
The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher
Один файл — и телефон уже чужой. Иранские спецслужбы получают полный доступ к смартфонам израильских журналистов
3 days 9 hours ago
Handala два года изображали независимых борцов за правду, а оказалось — государственная разведка на зарплате.
勒索软件花招:重启进安全模式绕过EDR,却意外搞崩自身加密程序
3 days 9 hours ago
Windows 安全模式很多人都接触过,系统出故障的时候我们会进入安全模式排查问题,但现在勒索攻击者盯上了这个
BGP Role model: tracking the adoption of RFC 9234
3 days 9 hours ago
RFC 9234 lets routers reject route leaks on their own, using BGP Roles and the Only to Customer attribute. We measured who has deployed it, and found two Tier 1 networks unexpectedly stripping OTC.
Bryton Herdes
Крупнейший налоговый скандал в истории Франции. Хакеры дважды вскрыли системы фискального ведомства
3 days 9 hours ago
Итог двух взломов налоговой Франции.
Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities
3 days 9 hours ago
Enterprise software creation has accelerated as vulnerability levels rise, Sonatype finds