On November 26th, Microsoft patched four vulnerabilities detected in Dynamics 365 Sales, the Partner.Microsoft.Com portal, Microsoft Copilot Studio and Azure PolicyWatch.
Microsoft Copilot Studio, a platform for developers to create AI agents and speed up coding with automation, had a critical vulnerability rated 9.3 out of 10 (CVE-2024-49038). Microsoft has fully addressed this issue, and users do not need to take any action.
By infosecbulletin
/ Friday , May 9 2025
Microsoft has fixed critical vulnerabilities in its core cloud services, including Azure Automation, Azure Storage, Azure DevOps, and Microsoft Power...
Read More
By infosecbulletin
/ Thursday , May 8 2025
The cyber threat landscape is rapidly changing, with a notable increase in ransomware activity in April 2025, driven by the...
Read More
By infosecbulletin
/ Thursday , May 8 2025
SonicWall has released patches for three security flaws in SMA 100 Secure Mobile Access appliances that could allow remote code...
Read More
By infosecbulletin
/ Thursday , May 8 2025
From April 2024 to April 2025, Flashpoint analysts noted that the financial sector was a major target for threat actors,...
Read More
By infosecbulletin
/ Thursday , May 8 2025
Cisco has issued a security advisory for a critical vulnerability in its IOS XE Software for Wireless LAN Controllers (WLCs)....
Read More
By infosecbulletin
/ Wednesday , May 7 2025
Attackers linked to the Play ransomware operation deployed a zero-day privilege escalation exploit during an attempted attack against an organization...
Read More
By infosecbulletin
/ Wednesday , May 7 2025
Hackers are exploiting an unauthenticated remote code execution vulnerability in the Samsung MagicINFO 9 Server to take control of devices...
Read More
By infosecbulletin
/ Tuesday , May 6 2025
CISA added the Langflow vulnerability, CVE-2025-3248 (CVSS score 9.8), to its Known Exploited Vulnerabilities catalog. Langflow is a popular tool...
Read More
By infosecbulletin
/ Tuesday , May 6 2025
Google has released its monthly Android security updates, addressing 46 vulnerabilities, including one that has been actively exploited. CVE-2025-27363 (CVSS...
Read More
By infosecbulletin
/ Tuesday , May 6 2025
The Cyber Security Club, representing the Department of Computer Science and Engineering at the University of Asia Pacific (UAP), has...
Read More
Partner.Microsoft.Com, the official Microsoft partners’ portal, experienced a serious vulnerability (CVE-2024-49035) with a severity rating of 8.7/10, allowing for elevated privileges.
Microsoft has discovered that an improper access control flaw is being exploited. Unauthenticated attackers can use it to gain higher privileges on a network. No action is required from users as automatic patches are being released over the next few days.
Microsoft Azure PolicyWatch, a service for managing policies in Microsoft Azure, has a critical flaw rated 8.2/10 (CVE-2024-49052).
Microsoft confirmed that the vulnerability has been fully fixed, so users do not need to take any action.
Microsoft Dynamics 365 Sales, a cloud-based CRM solution, has a significant spoofing vulnerability rated 7.6 out of 10 (CVE-2024-49053).
Attackers could alter a vulnerable link to redirect victims to a malicious site, but they needed to be authenticated (not necessarily with admin privileges). Victims had to click a specially crafted URL to be at risk.
Microsoft said, “The vulnerability is in the web server, but the malicious scripts execute in the victim’s browser on their machine.”