Overview
- Microsoft
- Copilot Web
Description
Statistics
- 5 Posts
- 11 Interactions
Fediverse
Von wegen KI: MS Copilot ist strunzdumm
Das Sicherheitsunternehmen Varonis hat eine Sicherheitslücke in Microsoft (MS) Copilot gefunden. Die hat inzwischen auch einen Namen bekommen und eine CVE-Nummer: CVE-2026-24301 oder CoSnitch. Sie ist mit 8,8 von 10 als kritisch eingestuft. Anscheinend gibt es noch keinen Flicken dagegen. Wer diese Lücke ausnutzt, kann Copilot von Ferne heimlich (ohne Interaktion des Opfers) dazu veranlassen, sensible geheime Daten zu senden. Zwar hat Copilot Schutzvorkehrungen gegen solchen Missbrauch, aber die sind unvollständig. Der Trick der Forscher/innen bestand darin, Copilot sich selbst hacken zu lassen! Immer wenn die KI einen ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/08/19/von-wegen-ki-ms-copilot-ist-strunzdumm/
#cybercrime #datenleck #KI #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump
Researchers got Microsoft Copilot to explain its own security bypass just by asking it the right follow-up questions
Varonis Threat Labs disclosed CoSnitch (CVE-2026-24301), a critical flaw in Microsoft Copilot Personal made of three chained weaknesses that let an attacker exfiltrate data from a victim's connected accounts, Gmail, Google Drive,…
CoSnitch : Copilot a lui-même livré la faille qui permet de voler vos données https://www.it-connect.fr/cosnitch-cve-2026-24301-copilot-personal-faille-un-clic/ #ActuCybersécurité #Cybersécurité #Microsoft #Copilot #IA
Overview
- Elementor
- Elementor Pro
Description
Statistics
- 3 Posts
- 8 Interactions
Fediverse
WordPress admins running Elementor Pro:
CVSS 9.8 - CVE-2026-32475
WordPress Elementor Pro Plugin <= 4.2.1 is vulnerable to a high priority Arbitrary File Upload
https://patchstack.com/articles/critical-unauthenticated-file-upload-to-rce-in-elementor-pro-plugin/
Bluesky
Overview
Description
Statistics
- 3 Posts
- 4 Interactions
Fediverse
CVE-2026-33824: CRITICAL RCE in Windows IKE Extension is being actively exploited. All supported Windows 10, 11 & Server are impacted. Patch immediately or block UDP 500/4500 if IKE not used. More at https://radar.offseq.com/threat/critical-rce-flaw-in-windows-ike-extension-now-actively-exploited-e49a0ac6b3ada788 #OffSeq #RCE #Windows #BlueTeam
Bluesky
Overview
Description
Statistics
- 3 Posts
Fediverse
PTC Windchill/FlexPLM (CVE-2026-12569) exploited by Cl0p ransomware: CRITICAL severity, remote code execution, 40+ orgs hit. Patch ASAP to block active data theft & extortion. Full details: https://radar.offseq.com/threat/cl0p-ransomware-group-names-over-40-victims-of-ptc-windchill-campaign-1b708410d1eaf87f #OffSeq #Ransomware #CVE202612569 #Infosec
Bluesky
Overview
- Red Hat
- Red Hat build of Keycloak 26.4
- rhbk/keycloak-operator-bundle
Description
Statistics
- 2 Posts
- 13 Interactions
Fediverse
PSA: Critical unauthenticated account takeover vulnerability in #Keycloak - allows resetting arbitrary users‘ passwords. Update to 26.7.2 immediately or disable password reset. Tracked as CVE-2026-18963. https://github.com/keycloak/keycloak/issues/51833
Guten Morgen an @univention Kund*innen, die unsere #Keycloak App einsetzen! Wir werden demnächst Version 26.7.2 herausbringen. Von dem Account-Takeover-CVE ist unsere App nicht betroffen.
Details findet Ihr hier: https://help.univention.com/t/keycloak-26-7-2-and-cve-2026-18963-potential-account-takeover-nubus-not-affected/25494
Overview
- NetScaler
- ADC
Description
Statistics
- 3 Posts
- 3 Interactions
Fediverse
CVE-2026-19490 (CVSS 9.3) is a critical NetScaler authentication bypass in NetScaler Gateway and ADC. Patch now to block unauthenticated access.
NetScaler CVE-2026-19490 Lets Attackers Bypass Authentication https://www.esecurityplanet.com/threats/netscaler-cve-2026-19490-lets-attackers-bypass-authentication/
Overview
- GitLab
- GitLab
Description
Statistics
- 3 Posts
Fediverse
GitLab Patches Critical CVE-2026-19478 GraphQL Vulnerability https://www.esecurityplanet.com/threats/gitlab-patches-critical-cve-2026-19478-graphql-vulnerability/
Bluesky
Overview
Description
Statistics
- 2 Posts
- 4 Interactions
Fediverse
🚨 Public PoC available for high-severity Android ContactsProvider flaw
https://github.com/qm4rs/cve-2026-0075
CVE-2026-0075 affects Android 14, 15, 16, and 16 QPR2 and can allow access to information from the contacts database through a SQL-related side channel without user interaction.
Researcher QM4RS has now released a controlled Android PoC that intentionally requests neither READ_CONTACTS nor WRITE_CONTACTS.
The issue involves ContactsProvider2 returning detailed SQLite errors to callers that lack contacts permission. Those errors could potentially be abused as an information side channel.
Google's fix strips sensitive JSON-related SQLite exception details from unauthorized callers.
The researcher cautions that the PoC is build-specific and does not demonstrate a universal exploitation path across every Android device.
Devices with the June 5, 2026 Android security patch level or later address the issue.
A public PoC for CVE-2026-0075 shows an Android elevation of privilege in ContactsProvider2 that needs no user interaction.
#CVE20260075 #Android #ElevationOfPrivilege #ContactsProvider #SQLInjection #AndroidSecurity
https://securityonline.info/cve-2026-0075-android-eop/?utm_source=mastodon&utm_medium=jetpack_social
Overview
- Red Hat
- Multicluster Global Hub
- multicluster-globalhub/multicluster-globalhub-agent-rhel9
Description
Statistics
- 2 Posts
Fediverse
Three critical Red Hat ACM/MCE flaws, led by CVE-2026-66792 (CVSS 9.9), allow full compromise of the managed cluster.
#CVE202666792 #RedHat #Kubernetes #PrivilegeEscalation #ACM #ClusterAdmin
Overview
- Splunk
- Splunk MCP Server app
Description
Statistics
- 2 Posts
Fediverse
Splunk MCP Server app v1.2 is impacted by CVE-2026-76404 (CRITICAL, CVSS 9.1) — insecure deserialization lets admin users run arbitrary OS commands. Limit admin access & monitor for misuse until a patch is released. https://radar.offseq.com/threat/cve-2026-76404-the-application-deserializes-untrusted-data-without-sufficiently-verifying-that-the-a0d42d963a9e6a80 #OffSeq #Splunk #Infosec #CVE202676404
Splunk patches CVE-2026-76404, a critical remote code execution flaw in the MCP Server app, plus 16 more bugs across its apps and add-ons.
#Splunk #CVE #RemoteCodeExecution #RCE #MCPServer #Deserialization #InfoSec #PatchNow