#cybersecuritynews

6 posts · Last used 11d

Back to Timeline
Cyber Security News @Cybersecuritynews@infosec.exchange · Jul 30, 2026
‼️Microsoft Teams, Entra ID, and Copilot all sit on Cosmos DB. A single flaw called CosmosEscape could have handed attackers the keys to all of them. Vulnerability Details: https://cybersecuritynews.com/cosmosescape-vulnerability/ #cybersecuritynews #Azure #Vulnerability
0
0
0
Cyber Security News @Cybersecuritynews@infosec.exchange · Jul 24, 2026
🛡️ Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers Source: https://cybersecuritynews.com/bing-images-vulnerability/ Three critical remote code execution (RCE) vulnerabilities in Microsoft's infrastructure, with two flaws in Bing Images allowing attackers to hijack backend image-processing servers using nothing more than a crafted SVG file. Bing's reverse image search could be tricked into fetching an attacker-controlled URL from its backend, a classic server-side request forgery (SSRF) pattern that on its own looked low-impact. Researchers confirmed the fetch by observing outbound requests from Bing infrastructure carrying a bingbot/2.0 user agent, then noticed inconsistent HTTP 500 errors that hinted the backend was doing more than just retrieving an image. #cybersecuritynews #vulnerability
0
0
0
Cyber Security News @Cybersecuritynews@infosec.exchange · Jul 24, 2026
⚡️ Microsoft Confirms No Bloatware Ads in Windows 11; LG Disables McAfee Pop-ups Source: https://cybersecuritynews.com/microsoft-confirms-no-bloatware-ads-windows-11/ Microsoft has moved quickly to shut down unwanted antivirus advertising after users discovered that connecting an LG monitor could silently install companion software and trigger a McAfee trial pop-up on Windows 11. The issue surfaced when owners of premium LG displays reported that plugging in their monitors caused Windows Update to deliver the LG Monitor App Installer. Once installed via the Microsoft Store path, the app later surfaced a McAfee trial promotion an unexpected ad experience on machines that had never requested antivirus software. #cybersecuritynews
0
0
0
Cyber Security News @Cybersecuritynews@infosec.exchange · Jul 24, 2026
⚠️ Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users Source: https://cybersecuritynews.com/acrobat-extension-flaw-whatsapp-chats/ A newly disclosed flaw in the Adobe Acrobat Chrome extension allowed attackers to silently harvest WhatsApp Web chats, contacts, and profile data from any user who simply visited a malicious webpage no clicks, downloads, or credential theft required. The flaw, dubbed “HermeticReader,” and officially tracked as CVE-2026-48294 with a CVSS score of 7.4. The bug is classified as a universal cross-site scripting (UXSS) issue that lets a malicious site bypass the browser’s same-origin policy and read data tied to a victim’s active session in another tab. #cybersecuritynews
0
0
0
Cyber Security News @Cybersecuritynews@infosec.exchange · Jun 30, 2026
🛡️ Multiple AirDrop & Quick Share Vulnerabilities Allow Attackers to Crash Devices Source: https://cybersecuritynews.com/airdrop-and-quick-share-vulnerabilities/ Multiple newly disclosed vulnerabilities in Apple’s AirDrop and Google/Samsung Quick Share proximity-sharing protocols allow attackers within wireless range to crash or disrupt nearby devices without user interaction repeatedly. A systematic reverse-engineering and protocol-aware fuzzing study of AirDrop and Quick Share across macOS, iOS, Android, and Windows. Their research uncovered six distinct issues, several of which enable remote denial-of-service (DoS) attacks by crashing critical system daemons responsible for file-sharing and continuity features. #cybersecuritynews
0
0
0

You've seen all posts