Загрузка видео...

Не удалось загрузить видео

На главную

‼️🚨 This is alarming: Researchers found a one-click data exfiltration vulnerability in M365 Copilot. A single click on a trusted microsoft[.]com link let attackers pull emails, MFA codes, meeting notes, and SharePoint/OneDrive files, no permissions or second click required. Microsoft has patched it as CVE-2026-42824, rated critical.

143,911 просмотров • 3 месяцев назад •via X (Twitter)

Комментарии: 35

Фото профиля International Cyber Digest
International Cyber Digest3 месяцев назад

Source:

Фото профиля Apropos
Apropos3 месяцев назад

Found another malware spreading through GitHub

Фото профиля Cybernorse
Cybernorse3 месяцев назад

Organizations must verify that CVE‑2026‑42824 is fully patched across M365 Copilot to block one click data exfiltration of emails, MFA codes, and files. This critical zero‑day reinforces the need for robust AI security controls and prompt injection defenses. #Cybernorse

Фото профиля Alien
Alien3 месяцев назад

give an assistant standing access to everything and one trick drains everything

Фото профиля AiX
AiX3 месяцев назад

Messed up since it’s Microsoft products and have access to so called the best models for security

Фото профиля International Cyber Digest
International Cyber Digest3 месяцев назад

Mythos strikes again.

Фото профиля Tseng
Tseng3 месяцев назад

Thats quite a stretch one has to go through to fall for that, like not getting suspcisious about the email with the code AND click a link in a suspicious mail that comes directly after it. At this rate you could have as well entered the code on attackers website with same result

Фото профиля International Cyber Digest
International Cyber Digest3 месяцев назад

What are you talking about. It’s just one click. Link has Microsoft domain in it as well 💀

Фото профиля Tseng
Tseng3 месяцев назад

Yea,but a person must be incredibly stupid,at the IQ level of a Trump,to click any Link that follows an unrequested (here Slack) code request. Plus you have to be utterly stupid to wait long enough for the LLM to process it and does a call back to t he UI after clicking it...

Фото профиля Tseng
Tseng3 месяцев назад

In the demo video it takes fucking 15 seconds of LLM processing until its calling out the exfiltration endpoint. If you click on a link and see LLM prompt runing and dont close your tab/browser within 3 seconds you shouldn't be on the internet.

Фото профиля Niko_6657
Niko_66573 месяцев назад

If you have AnySecura Web Access Control and Email Control installed in your PC, the attacker can not do harm to your system.

Фото профиля Jacob P
Jacob P3 месяцев назад

How did Mythos not find this? Or was Microsoft not part of Project Glasswing.

Фото профиля Tabatha Vickery
Tabatha Vickery3 месяцев назад

When are y'all gonna get it that this is far from over? It's in every users phone everywhere! All tools, masking, AI takeovers, device highjacking, all platforms, banks, network servers and the list goes on. It's people aren't connecting the dots still. Cut the feed global!

Фото профиля International Cyber Digest
International Cyber Digest3 месяцев назад

Welcome to the shit show!

Фото профиля Tabatha Vickery
Tabatha Vickery3 месяцев назад

I've been living this bullshit for too long in my phone. I'm not a tech, I'm a victim that has been treated like IDK what I'm talking about. I've had to learn and teach myself shit I never cared about to find out what's happening to me. Just to be invalidated, but not now!

Фото профиля Maxprotect
Maxprotect3 месяцев назад

The core issue is semantic trust, Copilot treats instructions inside an external link with the user's full privilege. Until enterprise AI architectures can deterministically separate data from execution code, traditional access controls cannot stop this ex filtration vector.

Фото профиля MT
MT3 месяцев назад

And who is surprised by this? Biggest cloud lies: 1. We are secure 2. We are redundant 3. We care about our customers data

Фото профиля Anonymouse
Anonymouse3 месяцев назад

God forbid Teams is useable

Фото профиля Jelani
Jelani3 месяцев назад

microslop

Фото профиля PsyOp_Socrates
PsyOp_Socrates3 месяцев назад

Who the hell use microsoft services? Disable all or at keast what ever you can

Фото профиля International Cyber Digest
International Cyber Digest3 месяцев назад

Almost every corporation uses MS.

Фото профиля Sara Blu
Sara Blu3 месяцев назад

One click on a trusted domain and MFA codes are gone. This is why we can't rely on domain trust alone. Patch now.

Фото профиля Guardian Digital, Inc.
Guardian Digital, Inc.3 месяцев назад

That’s concerning, especially since attackers could pull MFA codes with just one click. Curious, how did Microsoft address potential lingering risks for users still vulnerable to social engineering tactics?

Фото профиля ʘ ZERO
ʘ ZERO3 месяцев назад

Gov should ban this software for non US citizens

Фото профиля Christopher Levi Wiebold
Christopher Levi Wiebold3 месяцев назад

...did i see that right? Someone just sends a link to someone with a pre-written AI query that executes on their end? 😐

Фото профиля Mchenzie
Mchenzie3 месяцев назад

A lot of people will read this and move on.The smart ones will ask themselves how this applies to their own environment, business, or project.Understanding the risk is one thing; building an effective response is another. Always interesting to see perspectives from others.

Фото профиля Constance Ardiles-Lee
Constance Ardiles-Lee3 месяцев назад

The patch is resolved

Фото профиля International Cyber Digest
International Cyber Digest3 месяцев назад

True. It has been patched. Nevertheless, it's a very interesting attack factor we will see exploited in the coming years.

Фото профиля GuardianStack
GuardianStack3 месяцев назад

The more context an AI assistant has, the more valuable it becomes & the more attractive it becomes to attackers

Фото профиля @
@3 месяцев назад

Obviously co pilot

Фото профиля Paula Vazquez
Paula Vazquez3 месяцев назад

Hey they said “ claw is safe …” truth is 😂 nope real stress test tell and show a different story! Peter will keep dodging real accountability ^ again not attacking ppl just giving cc and poking the bubble on their own words!

Фото профиля ibrahim khorwat
ibrahim khorwat3 месяцев назад

Yikes!

Фото профиля Gon
Gon3 месяцев назад

Last time I got access to Microsoft SSI 🤣

Фото профиля Daniel Friday | ShadowIntern |
Daniel Friday | ShadowIntern |3 месяцев назад

Another addition for the Range force labs!

Фото профиля Vito Botta
Vito Botta3 месяцев назад

The browser makes the leak look like a normal Microsoft flow. That is the part defenders will hate.

Похожие видео

HOW TO JOIN ARCIUM DISCORD GM guys I discovered a rare gem a few months ago, it's . So let me start with the official greeting, gMPC! I checked their X, explored their website and docs to check what they're building This is what I found: Arcium is building an infrastructure that lets apps use encrypted data without exposing it. It is powered by secure Multi-Party Computation (MPC) – which brings about the greeting – gMPC It is a blockchain-based supercomputer that keeps data private, helps build smarter tools, and works across industries. Arcium is basically prioritizing PRIVACY ✦✧✦✧✦✧✦✧✦✧✦✧✦✧✦✧✦✧✦✧✦✧✦ Cool right? It doesn't stop there, you can contribute to this project just like I'm doing with this post There's even a testnet, but I'll get into that in another post This post aims to teach newbies or people that are just exploring this project how to join the discord the right way! You need to join the server so you can start contributing to this awesome project Contributing in the sense of posting quality posts, memes and even arts! → Head to this link → [ → Click all the roles → Click on "horizon", then click "cross the event horizon" → Click on "portal", then click "continue" → Click on "arcium", then click on the Arcium logo That's it! You're in! Then you can go on to pledge your gMPC 😁💜 Honestly, I slept off while trying to join the Discord a few nights ago, so I hope this helps y'all Stay ☂️

Ọlá👨🏽‍💻🟠🔱☂️ (blue tick)

30,851 просмотров • 1 год назад

Microsoft CEO Satya Nadella on why winning against ChatGPT, Gemini, and Claude was never the goal: The Hard Fork hosts ask him directly how Microsoft plans to overtake the competition in the AI model race. His answer reframes the entire question. "Our real goal is to get everyone across the ecosystem to the frontier." Satya explains the problem with how frontier models are currently built. You hill climb, you do reinforcement learning, and then you need data. But at this point, the world has essentially saturated publicly available data. So the only way to keep scaling is to pull data from everywhere. He asks: "What if you turn that around and said no, there's a base model that has reasoning, that has the agent loop, but you can bring it into your RL. Every company." This is where his thinking gets interesting. Satya Nadella argues that the future of the firm runs on human capital and token capital together: "If the future of the firm is human capital and token capital, I want every balance sheet, every income statement in every company to have both." AI becomes a financial asset sitting on a company's books the same way its people do. And Microsoft's role in this? To provide the best possible base model. One that companies build on top of with their own data, their own context, their own weights. One they can even replace. That last part is the striking bit. Satya is explicitly building a platform where customers are free to walk away. He frames it not as a risk, but as the whole point: "I always ask the question — why does Microsoft, or why does the world need Microsoft? And if we are successful, can the world around us be successful? This, I believe, is a more sustainable way to go at it."

Big Brain AI

11,770 просмотров • 2 месяцев назад