Release v0.94.0 · anchore/grype

Added Features Add echo os to grype [#2647 @orizerah] Bug Fixes Nonroot can't load local docker image with docker socket bind [#2721 #2723 @kzantow] "Harden Container Runtime with Non-Root User"...

GitHub

Trend Micro has just closed the door on critical flaws that could’ve let hackers run code in your security setup. Are you up to date with the latest patch fixes?

https://thedefendopsdiaries.com/trend-micro-addresses-critical-vulnerabilities-in-apex-central-and-endpoint-encryption-policyserver/

#trendmicro
#cybersecurity
#vulnerability
#patchmanagement
#remotecodeexecution

A zero-click flaw in #Microsoft365Copilot, dubbed #EchoLeak, lets attackers steal company data through a single email, no user action needed. AI assistants now pose real risks.

Read: https://hackread.com/zero-click-ai-flaw-microsoft-365-copilot-expose-data/

#CyberSecurity #AI #ZeroClick #Vulnerability #CoPilot

New 'Zero-Click' AI Flaw Found in Microsoft 365 Copilot, Exposing Data

Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread

Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto

⚠️ Over 40,000 unsecured internet-connected cameras found worldwide, and the US tops the list. From homes to offices, many feeds are wide open with no passwords or protections.

đź”— https://hackread.com/us-tops-list-unsecured-cameras-exposing-homes-offices/

#CyberSecurity #IoT #SecurityCamera #CCTV #Vulnerability

US Tops List of Unsecured Cameras Exposing Homes and Offices

Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread

Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Smashing Security podcast #421: Toothpick flirts, Google leaks, and ICE ICE scammers - What do a sleazy nightclub carpet, Google’s gaping privacy hole, and an international stu... https://grahamcluley.com/smashing-security-podcast-421/ #smashingsecurity #vulnerability #databreach #lawℴ #dataloss #podcast #privacy #google #ice
Smashing Security podcast #421: Toothpick flirts, Google leaks, and ICE ICE scammers

What do a sleazy nightclub carpet, Google’s gaping privacy hole, and an international student conned by fake ICE agents have in common? This week’s episode of…

Graham Cluley
##AI can be very helpful, and it doesn't care who it is helping. This particular ##vulnerability in ##Copilot has been fixed. I'm sure there aren't any others waiting to be discovered.

Zero-click AI data leak flaw uncovered in Microsoft 365 Copilot
A new attack dubbed 'EchoLeak' is the first known zero-click AI vulnerability that enables attackers to exfiltrate sensitive data from Microsoft 365 Copilot from a user's context without interaction. ...

The attack begins with a malicious email sent to the target, containing text unrelated to Copilot and formatted to look like a typical business document.

The email embeds a hidden prompt injection crafted to instruct the LLM to extract and exfiltrate sensitive internal data. ...

cc:news

đźš— The US CISA reports critical vulnerabilities in SinoTrack GPS devices that could let attackers remotely control vehicles and track locations.

Read: https://hackread.com/cisa-remote-control-flaws-sinotrack-gps-trackers/

#CyberSecurity #Vulnerability #SinoTrack #GPS #IoT

External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network.

đź”— https://vulnerability.circl.lu/vuln/CVE-2025-33053#sightings

#webdav #vulnerabilitymanagement #cve #vulnerability #cybersecurity

CVE-2025-33053

cvelistv5 - CVE-2025-33053

Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.

EchoLeak – 0-Click AI Vulnerability Enabling Data Exfiltration from 365 Copilot

https://www.aim.security/lp/aim-labs-echoleak-blogpost

#HackerNews #EchoLeak #AI #Vulnerability #DataExfiltration #365Copilot #Cybersecurity

Aim Labs | Echoleak Blogpost

The first weaponizable zero-click attack chain on an AI agent, resulting in the complete compromise of Copilot data integrity