Wednesday , September 17 2025

Recent Posts

Copilot Breaks Your Audit Log, but Microsoft Won’t Tell the customer

Copilot

A significant security vulnerability has been discovered in Microsoft’s Copilot for M365 that allowed users, including potential malicious insiders, to access and interact with sensitive files without leaving any record in the official audit logs. After patching the flaw, Microsoft has reportedly decided against issuing a formal CVE or notifying …

Read More »

0-Day Clickjacking Vuls Found in Password Managers like 1Password, LastPass

password managers

A cybersecurity researcher revealed zero-day clickjacking vulnerabilities in eleven major password managers, risking credential theft for millions of users with just one malicious click. The new attack technique, dubbed “DOM-based Extension Clickjacking,” represents a significant evolution from traditional web-based clickjacking attacks. This technique targets user interface elements created by password …

Read More »

Massive Intel data exposure: hacker harvests 270K employee data

Intel

A whitehat hacker broke into four of Intel’s internal systems and discovered that the sensitive data of 270K Intel employees’ was exposed. Then, he spent months helping the company plug the leaks, only to receive one automated thank-you note. Security researcher Eaton Zveare found a way to bypass authentication on …

Read More »