A bug has been causing Microsoft Copilot to read and summarise users’ confidential emails, and it’s been happening since late January. Microsoft says the issue stems from a code error that bypassed data loss prevention (DLP) policies designed to stop sensitive information from being accessed in the first place. It was first reported by BleepingComputer. “Users’ email messages with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat,” Microsoft said. Copilot Chat (Microsoft’s AI assistant built into Microsoft 365) debuted in September for business customers across Word, Excel, PowerPoint, Outlook, and OneNote. The idea is simple: let users interact with AI agents inside the tools they use every day. But in…
Kirsten Doyle
Abnormal has discovered a new phishing kit that allows bad actors to steal usernames and passwords with a toolkit that spoofs live login pages and bypasses multi-factor authentication (MFA) protections. Most phishing kits depend on static HTML clones of login pages, which, while effective, are inherently fragile. Even a small interface update from the brand being impersonated can instantly reveal the deception. “A new framework called Starkiller (not to be confused with the legitimate BC Security red team tool of the same name) takes a different approach,” Abnormal researchers said. A Commercial-grade Platform It is being sold openly as a commercial-grade cybercrime platform by…
CISA has warned that a critical security vulnerability (CVE-2026-1670) has been identified in four Honeywell CCTV camera models. “Successful exploitation of this vulnerability could lead to account takeovers and unauthorized access to camera feeds; an unauthenticated attacker may change the recovery email address, potentially leading to further network compromise,” the advisory said. The flaw is classified as “missing authentication for critical function” and has been given a CVSS severity score of 9.8. According to CISA, the vulnerability stems from an unauthenticated API endpoint that lets bad actors remotely change the “forgot password” recovery email address associated with a camera account. CISA advises users to take proactive steps to reduce the…
Security researchers at ESET have uncovered what they describe as the first known case of Android malware abusing generative AI to manipulate a device’s user interface in real time. Dubbed PromptSpy, the newly identified malware family uses Google’s Gemini to analyze on-screen content and dynamically guide malicious actions. While machine learning has previously been used in Android threats (including a recent case discovered by Dr.Web involving ad fraud automation) this is the first documented instance of GenAI being embedded directly into malware execution flow. According to the researchers, PromptSpy is the second AI-powered malware they have found, the first one being PromptLock in August last year, which was the first known instance of AI-powered ransomware. Unlike traditional Android malware, which relies on hardcoded…
APIs made up 17% of 67,058 published vulnerabilities in 2025, a total of 11,053 API-related flaws. The overlap between APIs and AI is even more notable. More than a third (36%) of AI vulnerabilities (786 out of 2,185) were API-related. Of the 245 vulnerabilities identified in the U.S. Cybersecurity and Infrastructure Security Agency’s 2025 Known Exploited Vulnerabilities list, 43% (106) were API-related. Unsurprisingly, 36% of AI-related exploits also corresponded to API vulnerabilities. These were some of the findings of Wallarm’s API ThreatStats Report 2026, which draws on vulnerability and breach data from 2025. The report describes AI as a risk multiplier that has been leveraging existing weaknesses in…
Eurail BV has confirmed that some customer data impacted by the previously reported security incident has been offered for sale on the dark web and a sample data set has been posted on Telegram. The company said it is continuing to investigate the scope and impact. Last month, the company revealed that it had experienced a data breach when bad actors accessed its customer database, which exposed sensitive information such as full names, passport numbers, ID numbers, bank account IBANs, health data, and contact information (email and phone numbers). “We have become aware that the data has been offered for sale on the dark web and…
Modern supply chain attacks are no longer isolated events. Rather, phishing, identity theft, malicious extensions, data breaches, ransomware, and extortion are becoming more and more interrelated steps of a single attack chain, where each step reinforces the next. This was one of the findings of Group IB’s High-Tech Crime Trends Report 2026, based on Intelligence drawn from Group-IB’s Digital Crime Resistance Centers (DCRCs) across 11 countries worldwide, enriched by adversary-focused telemetry, hands-on cybercriminal investigations, and 24/7 global monitoring of underground ecosystems. Other key findings include: Open-source ecosystems are under attack: The package repositories npm and PyPI have become the number one target, with stolen credentials for maintainers and automated malware worms to…
A recent report from Picus Labs, has uncovered a chilling evolution in cyber warfare, that it calls “the rise of the Digital Parasite.” The report analyzed more than 1.1 million malicious files and 15.5 million actions last year, and revealed that bad actors have shifted 80% of their resources toward stealth, evasion, and persistence. The report highlighted distinct, highly sophisticated behaviors that allow malware to inhabit systems for months without detection. These include: Dr. Süleyman Özarslan, Co-founder and VP of Picus Labs, said: ”What we’re observing is the rise of the digital parasite. Attackers have realized it is more profitable to inhabit the host than to destroy it. They are embedding themselves inside environments, using trusted identities and even physical hardware to feed…
Dutch telecoms business Odido has disclosed a cyberattack on its customer contact system that happened on 7 February. The personal information of approximately 6.2 million customers was disclosed, including names, residential addresses, mobile phone numbers, email addresses, account numbers, and ID information such as passports and driver’s licenses. In a statement, the company said no passwords, call details or billing information are involved. “We deeply regret this incident and are fully committed to limiting the impact of this incident and providing our customers with all necessary support. It is important to emphasize that our operational services have not been affected; customers can continue to call, use the internet and watch TV safely,” the statement read. …
Almost 17,000 Volvo employees have had their personal data exposed after attackers breached Conduent, an outsourcing company that manages workforce benefits and back-office services. In a filing with the Maine Attorney General, Volvo Group North America said it learned in late January that employee data had been exposed through systems run by Conduent. In a letter to customers, Conduent said: “On 13 January 2025, we discovered that we were the victim of a cyber incident that impacted a limited portion of our network. We immediately secured our networks and initiated an investigation with the assistance of third-party forensic experts.” Conduent’s investigation determined that an unsanctioned third party had access to its environment betwen 21 October 2024 and 13 January 2025. The bad actors obtained files associated with customers’ current or former health plans. “Given the nature and complexity of the data involved, Conduent…
