- LLMs
CVE-2026-55946 Microsoft Copilot Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an…
No signal on this page matches that topic.
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an…
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a…
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an…
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges…
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a…
Vibe coding is democratizing software development, but it is also creating a massive shadow AI attack surface. Security…
Welcome back to PWNED, the weekly column where we learn important life lessons about how we let cybercrims access our…
The Manhattan District Attorney’s Office has seized the domains of 12 deepfake websites in what it called the largest known seizure of celebrity deepfake sites in history. The sites, which marketed…
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian. There are plenty of signs that…
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median…
OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the…
Spanish data protection agency AEPD reveals the country’s first AI-powered data breach
Global security frameworks are evolving: Security organizations are increasingly leveraging global frameworks to navigate the complexities of AI-enabled threats, balancing the need for standardized…
Smith v. Flock Safety United States District Court Northern District of Ohio, Eastern Division Case No. 5:23-CV-2198…
Release: datasette 1.0a40 Same security fix as 0.65.5, plus some neat new features and bug fixes: Plugins can now…
Release: datasette 0.65.5 Security fix for an issue where a trailing newline in a requested table name could bypass…
The list of dodgy things AI agents can and will do on their own - like stealing people’s credentials, escaping onto the…
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
A modern storefront can look perfectly healthy while malicious JavaScript works underneath: siphoning affiliate…