Thursday , August 6 2026

Recent Posts

CVE-2025-43300
Apple Issues Urgent Patch for Zero-Day Vuln Exploited in the Wild

Apple

Apple has issued urgent security updates to fix a zero-day vulnerability that is being actively exploited, warning that attackers may have used it in targeted campaigns. CVE-2025-43300 is a flaw in Apple’s Image I/O framework that allows out-of-bounds writing, affecting how applications manage common image file formats. According to Apple’s …

Read More »

Copilot Breaks Your Audit Log, but Microsoft Won’t Tell the customer

Copilot

A significant security vulnerability has been discovered in Microsoft’s Copilot for M365 that allowed users, including potential malicious insiders, to access and interact with sensitive files without leaving any record in the official audit logs. After patching the flaw, Microsoft has reportedly decided against issuing a formal CVE or notifying …

Read More »

0-Day Clickjacking Vuls Found in Password Managers like 1Password, LastPass

password managers

A cybersecurity researcher revealed zero-day clickjacking vulnerabilities in eleven major password managers, risking credential theft for millions of users with just one malicious click. The new attack technique, dubbed “DOM-based Extension Clickjacking,” represents a significant evolution from traditional web-based clickjacking attacks. This technique targets user interface elements created by password …

Read More »