Researchers at Aim Labs have uncovered a zero-click vulnerability in Microsoft 365 Copilot, dubbed “EchoLeak.” This flaw allows threat actors to extract sensitive data from a user’s environment without any user interaction, no clicks, no downloads, no warnings. The finding is the first known instance of a zero-click exploit in a major generative AI assistant, and could be the start of a shift in how malicious actors target AI systems. Researchers at Aim Labs discovered the attack and reported it to Microsoft. The company classified the issue as a critical information disclosure vulnerability, assigning it the identifier CVE-2025-32711. Microsoft resolved…
Kirsten Doyle
The Black Basta ransomware group, once a dominant force in the cyber extortion landscape, disbanded in February 2025 following an unexpected leak of its internal chat logs. The leak, attributed to a disgruntled member known online as “ExploitWhispers,” surfaced shortly after the group breached an unspoken norm: targeting Russian financial institutions. ReliaQuest’s latest research details the group’s sudden downfall and the enduring influence of its tactics. At its peak, Black Basta named up to 50 victims a month on its data-leak site. But by the end of February, that site had disappeared. The group’s infrastructure followed suit. Despite this apparent…
At a time where surveillance is synonymous with safety, the very tools designed to protect us are exposing a growing vulnerability. Internet-connected security cameras installed to monitor homes, businesses, and public spaces are increasingly being found wide open to the world. The consequences are no longer theoretical. From quiet residential streets to the heart of critical infrastructure, unsecured cameras are being co-opted, exploited, and in some cases, weaponized. Cameras as a Threat Vector At first glance, some of these exposures may seem trivial. Cameras streaming serene beachfronts or remote bird feeders are sometimes meant to be public. Services like EarthCam…
Security researchers at AppOmni have discovered five zero-day vulnerabilities and 15 severe but avoidable misconfiguration traps in Salesforce Industry Cloud. These issues, if unaddressed, expose sensitive data to unauthorized access and threaten compliance across industries relying on Salesforce’s low-code architecture. The findings affect core components used by tens of thousands of entites, many in regulated sectors such as healthcare, financial services, and government. The vulnerabilities were responsibly disclosed to Salesforce, which rapidly confirmed and remediated them. Three have been patched at the platform level. The remaining two require customer intervention. If organizations don’t follow the instructions sent by Salesforce, these…
United Natural Foods, Whole Foods’ primary distributor, has been hit with a cyberattack that may leave some grocery store shelves empty. In a statement, the company said: “We have identified unauthorized activity in our systems and have proactively taken some systems offline while we investigate. As soon as we discovered the activity, an investigation was initiated with the help of leading forensics experts and we have notified law enforcement.” With systems offline, and no clear timeline for them to be back up and running, stock on Whole Foods’ shelves may soon start to run out. The computer system was used…
The disclosure was not supposed to happen like this. Originally slated for release after a responsible disclosure period, the details of a critical vulnerability in Roundcube (CVE-2025-49113) are being published early. Not out of haste, but out of necessity. Within 48 hours of a patch landing quietly on GitHub, attackers had already reverse-engineered the fix, weaponized the exploit, and begun selling it on underground forums. In this case, silence would serve the wrong side. To level the field for defenders, a full technical breakdown has been made public by Fears Off researchers. It’s not ideal. But with active exploitation underway…
Trump Signs Executive Order Overhauling Federal Cybersecurity Policy, Refocusing on Technical Defense and Threat Mitigation President Donald Trump has signed a new Executive Order aimed at reinforcing the country’s defenses against foreign cyber threats. The order strips away what the administration describes as “political distractions” from previous directives, prioritizing hands-on technical safeguards over bureaucratic mandates. The new order amends and replaces key elements of two Obama- and Biden-era Executive Orders (14144 and 13694) declaring a return to cybersecurity fundamentals: protecting digital infrastructure, defending against state-backed cyber campaigns, and preparing the U.S. for next-generation threats like quantum computing. A Return to…
Getty Images is suing Stability AI for allegedly stealing its photos to train a machine. And it’s not a small spat. This could be the case that rewrites how copyright law handles artificial intelligence. Kicking off yesterday, 9 June 2025, in London’s High Court, Getty’s lawsuit accuses Stability AI of grabbing over 12 million copyrighted images without permission. The images were allegedly used to train Stable Diffusion, the text-to-image generator that’s sparked a thousand headlines and almost as many lawsuits. It’s not Getty’s first rodeo. The company is already pursuing a similar case against Stability AI in the U.S. This…
A new investigation into several high-profile Chrome extensions has revealed that many transmit sensitive user data over unencrypted HTTP, leaving users wide open to profiling, interception, and even manipulation by malicious actors lurking on the same network. The names involved are familiar. SEMRush Rank. PI Rank. MSN New Tab. DualSafe Password Manager. Even Browsec VPN. Together, these extensions have tens of millions of users. They’re pitched as tools to improve your browser, protect your privacy, or simplify your workflow. But under the hood, they tell a different story. Researchers discovered that these extensions transmit data like browsing domains, machine IDs,…
Your company’s stance on AI bots could make (or cost) you revenue, rankings, and visibility. The rise of AI web scraping has thrown businesses into uncharted waters. On one side, scraping fuels AI-powered discovery tools and generative search. On the other, it raises alarms about content ownership, intellectual property, and competitive advantage. According to a new study by Liquid Web, 43% of businesses believe AI scraping benefits their competitors more than themselves, while one in five have actually seen a revenue boost. The data paints a divided picture, one part opportunity, one part risk, and makes one thing clear: if…
