Latest news

  1. AI Security via HIPAA Journal

    Free Webinar: Is AI Putting Your Practice at Risk?

    AI tools are already in your practice. The question is whether you know about it and whether they are HIPAA compliant. Most practices are using AI in some form already…

  2. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-55946 Microsoft Copilot Information Disclosure Vulnerability

    Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a…

  3. AI Security via Adversa AI

    Why vibe coding security is the next enterprise nightmare

    Vibe coding is democratizing software development, but it is also creating a massive shadow AI attack surface. Security teams cannot rely on bans to address this risk…

  4. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-70009 Azure Arc Elevation of Privilege Vulnerability

    Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  5. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69865 Microsoft Container Registry Elevation of Privilege Vulnerability

    Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.

  6. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-77903 Microsoft Dataverse Elevation of Privilege Vulnerability

    Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.

  7. AI Security via Microsoft Security Response Center

    CVE-2026-68791 Azure Machine Learning Information Disclosure Vulnerability

    Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

  8. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-85885 Microsoft 365 Copilot Elevation of Privilege Vulnerability

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

  9. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-83944 Azure Logic Apps Elevation of Privilege Vulnerability

    Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

  10. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-78501 Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability

    Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose…

  11. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-87701 Azure Cosmos DB Elevation of Privilege Vulnerability

    Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges…

  12. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-70200 Azure Logic Apps Elevation of Privilege Vulnerability

    Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

  13. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-85889 Azure AI Foundry Elevation of Privilege Vulnerability

    Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

  14. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-85917 Azure AI Foundry Elevation of Privilege Vulnerability

    Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

  15. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69671 Microsoft Office Word Remote Code Execution Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…

  16. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69678 Microsoft Office PowerPoint Remote Code Execution Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…

  17. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69686 Microsoft Office Word Remote Code Execution Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…

  18. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69722 Microsoft Office Word Remote Code Execution Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…

  19. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69734 Microsoft Office Word Information Disclosure Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…

  20. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69724 Microsoft Office SharePoint Remote Code Execution Vulnerability

    Updated an acknowledgement. This is an informational change only.