Friday, April 24, 2026
HomeUncategorized

Uncategorized

Copilot Vulnerability Exposes Audit Logs and Grants Secret Access to Attackers

A critical security vulnerability in Microsoft's M365 Copilot allowed users to access sensitive files without generating audit log entries, effectively enabling insider threats to operate undetected. The vulnerability, discovered in July and quietly patched in August, highlights serious concerns about audit trail integrity and...

Lenovo AI Chatbot Vulnerability Allows Attackers to Execute Remote Scripts on Corporate Machines

A critical security vulnerability in Lenovo's AI-powered chatbot "Lena" has exposed the company's corporate systems to potential cyberattacks, allowing malicious actors to execute unauthorized scripts and steal sensitive session data through simple prompt manipulation. The vulnerability, discovered by Cybernews researchers, demonstrates how inadequate security...

Serial Hacker Sentenced for Breaching and Defacing Multiple Organizations’ Websites

A 26-year-old cybercriminal from South Yorkshire has been sentenced to 20 months imprisonment for orchestrating a global hacking campaign that compromised millions of user accounts and defaced government and news websites across multiple countries. Al-Tahery Al-Mashriky from Rotherham was convicted on August 15, 2025, after...

ShinyHunters Hackers Allegedly Release New Exploit for SAP 0-Day Vulnerabilities

Cybersecurity researchers and organizations worldwide were alerted to the public release of a weaponized exploit targeting critical SAP vulnerabilities, marking a significant escalation in threats against enterprise SAP environments. The exploit, which combines two previously zero-day vulnerabilities in SAP NetWeaver Visual Composer, represents a...

Microsoft Defender AI Identifies Plaintext Credentials in Active Directory

Microsoft has unveiled a groundbreaking AI-powered security enhancement for its Defender for Identity platform that addresses a critical vulnerability plaguing organizations worldwide: exposed plain text credentials stored within Active Directory systems. The new feature, announced on August 14, 2025, represents a significant advancement in...

PyPI to Prevent Domain Resurrection Attacks by Blocking Access Through Expired Domains

The Python Package Index (PyPI) has implemented new security measures to prevent domain resurrection attacks, a sophisticated supply-chain threat where malicious actors purchase expired domains to hijack user accounts through password reset mechanisms. Since early June 2025, PyPI has proactively unverified over 1,800 email...