Skip to content

Latest alerts

RSS feed

Microsoft Copilot for Word Hidden Prompts Risk

A researcher described how hidden instructions in Word files can be copied into Microsoft 365 Copilot drafts and alter document content. The issue requires a Copilot editing or drafting step rather than malware execution.

JetBrains TeamCity RCE: CVE-2026-63077 Explained

JetBrains warns that CVE-2026-63077 can allow authentication bypass and lead to TeamCity remote code execution on TeamCity On-Premises. Cloud customers don’t need action, but administrators should patch quickly.

AI-Based Misuse and Phishing: ThreatsDay Overview

This ThreatsDay roundup shows how AI-based abuse and social engineering increasingly pair with real intrusion paths. From Chrome weaknesses to DNS hijacking and credential stuffing—here are the key takeaways.

Samsung stops Smart TV proxies: why it matters

New research shows that some Samsung Smart TV apps may contain Smart TV proxies. Samsung is taking steps and removing apps that share users’ internet connections with third parties.

FOMO in the SOC: Where AI Platforms Fit

AI platforms in the SOC can boost productivity, but they aren’t built to investigate every alert 24/7. A layered approach turns AI FOMO into better security outcomes.

SonicWall SMA1000: patched flaws behind ransomware

Two newly reported SonicWall SMA1000 vulnerabilities (CVE-2026-15409 and CVE-2026-15410) have been exploited in ransomware incidents. Security teams urge rapid patching and active threat hunting.

CaptiveCrunch: how Russian APT Wi‑Fi gateway hacks work

Microsoft reports the CaptiveCrunch Wi-Fi gateway campaign uses hacked public Wi‑Fi gateway appliances to manipulate captive portal traffic. Attackers intercept Microsoft 365 sign-ins and steal credentials and sessions.