OAuth Attacks in Entra ID Can Leverage ChatGPT to Compromise User Email Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are always looking for new ways to abuse trusted platforms, and Microsoft Entra ID is increasingly becoming a target through a technique known as OAuth consent abuse. A …

CISA Confirms Active Exploitation of FileZen Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Confirms Exploit FileZen Vulnerability U.S. authorities have confirmed that threat actors are actively exploiting a critical vulnerability in FileZen by Soliton Systems K.K.. Due to the high risk associated …

Microsoft to Extends DLP Support for Copilot to Prevent Sensitive File Processing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Purview Data Loss Prevention (DLP) controls are being expanded to block Microsoft 365 Copilot from processing sensitivity-labeled files across all storage locations, including local devices. The change aims to close …

SolarWinds Critical Serv-U Vulnerabilities Enables Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SolarWinds Serv-U Vulnerabilities An urgent security update has been released for the Serv-U file server software to fix multiple critical vulnerabilities that could allow attackers to fully compromise affected systems. …

Microsoft to Stop Support for Windows Server 2016 and Windows 10 2016

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Stop Support Windows Server 2016 and Windows 10 2016 Organizations are being reminded that three Windows releases first introduced in 2016 are nearing end-of-support. After receiving their final monthly …

Multiple Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Allow Root Access and Credential Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Multiple vulnerabilities have been discovered in CryptoPro Secure Disk (CPSD) for BitLocker, a widely used encryption solution. These flaws could allow an …

Microsoft Warns of Hackers Attacking Developers with Malicious Next.js Repositories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A coordinated attack campaign is actively targeting software developers through malicious repositories disguised as legitimate Next.js projects and technical assessment materials. The attackers rely on job-themed lures, presenting fake recruitment …

Microsoft Released Updates for Windows 11, Version 25H2 and 24H2 Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Released Updates Windows 11 25H2 and 24H2 An optional non-security update, KB5077241, has been released for Windows 11 versions 25H2 and 24H2, improving overall functionality, performance, and reliability without …

Threat Actors Exploit Apache ActiveMQ Server Vulnerability to Gain RDP Access and Deploy LockBit Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Apache ActiveMQ has been actively exploited by threat actors, leading to a full LockBit ransomware deployment across an enterprise network. Attackers leveraged CVE-2023-46604, a remote code …

GitHub Copilot Exploited to Perform Full Repository Takeover via Passive Prompt Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical AI-driven vulnerability in GitHub Codespaces, dubbed RoguePilot, that enabled attackers to silently hijack a repository by embedding malicious instructions inside a GitHub Issue. The flaw, uncovered by researchers …