On November 26th, Microsoft patched four vulnerabilities detected in Dynamics 365 Sales, the Partner.Microsoft.Com portal, Microsoft Copilot Studio and Azure PolicyWatch.
Microsoft Copilot Studio, a platform for developers to create AI agents and speed up coding with automation, had a critical vulnerability rated 9.3 out of 10 (CVE-2024-49038). Microsoft has fully addressed this issue, and users do not need to take any action.
By infosecbulletin
/ Saturday , March 29 2025
The Federal Bureau of Investigation (FBI) is probing the cyberattack at Oracle (ORCL.N), opens new tab that has led to...
Read More
By infosecbulletin
/ Thursday , March 27 2025
OpenAI has increased its maximum bug bounty payout to $100,000, up from $20,000, to encourage the discovery of critical vulnerabilities...
Read More
By infosecbulletin
/ Thursday , March 27 2025
Splunk has released a security advisory about critical vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These issues could lead...
Read More
By infosecbulletin
/ Thursday , March 27 2025
As the Eid holidays near, cybercriminals may try to take advantage of weakened security during this time. The CTI unit...
Read More
By infosecbulletin
/ Wednesday , March 26 2025
Operations at Kuala Lumpur International Airport (KLIA) were unaffected by a cyber attack in which hackers demanded US$10 million (S$13.4...
Read More
By infosecbulletin
/ Wednesday , March 26 2025
Unofficial patches are available for a new Windows zero-day vulnerability that allows remote attackers to steal NTLM credentials by deceiving...
Read More
By infosecbulletin
/ Wednesday , March 26 2025
On Tuesday, VMware issued an urgent fix for a security flaw in its VMware Tools for Windows. CVE-2025-22230 allows a...
Read More
By infosecbulletin
/ Tuesday , March 25 2025
Kubernetes users of the Ingress NGINX Controller are advised to fix four newly found remote code execution ( RCE) vulnerabilities,...
Read More
By infosecbulletin
/ Tuesday , March 25 2025
Next.js, a widely used React framework for building full-stack web applications, has fixed a serious security vulnerability. Used by many...
Read More
By infosecbulletin
/ Sunday , March 23 2025
A hacker known as “rose87168” claims to have stolen six million records from Oracle Cloud servers. The stolen data includes...
Read More
Partner.Microsoft.Com, the official Microsoft partners’ portal, experienced a serious vulnerability (CVE-2024-49035) with a severity rating of 8.7/10, allowing for elevated privileges.
Microsoft has discovered that an improper access control flaw is being exploited. Unauthenticated attackers can use it to gain higher privileges on a network. No action is required from users as automatic patches are being released over the next few days.
Microsoft Azure PolicyWatch, a service for managing policies in Microsoft Azure, has a critical flaw rated 8.2/10 (CVE-2024-49052).
Microsoft confirmed that the vulnerability has been fully fixed, so users do not need to take any action.
Microsoft Dynamics 365 Sales, a cloud-based CRM solution, has a significant spoofing vulnerability rated 7.6 out of 10 (CVE-2024-49053).
Attackers could alter a vulnerable link to redirect victims to a malicious site, but they needed to be authenticated (not necessarily with admin privileges). Victims had to click a specially crafted URL to be at risk.
Microsoft said, “The vulnerability is in the web server, but the malicious scripts execute in the victim’s browser on their machine.”