Latest news
-
AI Security via HIPAA Journal
Free Webinar: Is AI Putting Your Practice at Risk?
AI tools are already in your practice. The question is whether you know about it and whether they are HIPAA compliant. Most practices are using AI in some form already…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-55946 Microsoft Copilot Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a…
-
AI Security via Adversa AI
Why vibe coding security is the next enterprise nightmare
Vibe coding is democratizing software development, but it is also creating a massive shadow AI attack surface. Security teams cannot rely on bans to address this risk…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-70009 Azure Arc Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69865 Microsoft Container Registry Elevation of Privilege Vulnerability
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-77903 Microsoft Dataverse Elevation of Privilege Vulnerability
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
-
AI Security via Microsoft Security Response Center
CVE-2026-68791 Azure Machine Learning Information Disclosure Vulnerability
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-85885 Microsoft 365 Copilot Elevation of Privilege Vulnerability
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-83944 Azure Logic Apps Elevation of Privilege Vulnerability
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-78501 Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-87701 Azure Cosmos DB Elevation of Privilege Vulnerability
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-70200 Azure Logic Apps Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-85889 Azure AI Foundry Elevation of Privilege Vulnerability
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-85917 Azure AI Foundry Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69671 Microsoft Office Word Remote Code Execution Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69678 Microsoft Office PowerPoint Remote Code Execution Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69686 Microsoft Office Word Remote Code Execution Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69722 Microsoft Office Word Remote Code Execution Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69734 Microsoft Office Word Information Disclosure Vulnerability
Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69724 Microsoft Office SharePoint Remote Code Execution Vulnerability
Updated an acknowledgement. This is an informational change only.
