Security Breach
The latest Security Breach coverage — news, analysis, and updates from the WindowsNews.AI desk.
8 Chrome, Edge extensions with 2M+ installs stole ChatGPT, Gemini chats
Security researchers have uncovered a startling privacy breach in plain sight: several widely used Google Chrome and Microsoft Edge extensions — marketed as privacy and security tools — were...
Zenity Labs’ AgentFlayer Exposes Zero-Click Exploits: Microsoft Copilot, ChatGPT AI Agents Hijacked Without User Action
At Black Hat USA 2025, security researchers from Zenity Labs pulled back the curtain on a dangerously overlooked attack surface: enterprise AI agents that can be silently hijacked with zero user...
Rising Cyber Threats Exploit Email Link Wrapping Vulnerabilities in Microsoft 365
A sudden spike in sophisticated cyberattacks is shaking the foundations of email security for businesses leveraging Microsoft 365. Recent investigations have revealed an alarming vulnerability within...
EchoLeak: The Critical Microsoft Copilot Vulnerability Reshaping Enterprise AI Security
A storm has swept through the cybersecurity and Windows enterprise communities following the exposure of a critical vulnerability in Microsoft Copilot Enterprise, code-named “EchoLeak.” This...
Global SharePoint Zero-Day Cyberattack 2025: Analysis, Impact, and Security Best Practices
In the wake of a sweeping cyberattack that has compromised tens of thousands of Microsoft SharePoint servers worldwide, both U.S. government agencies and major energy corporations are reeling from...
Golden dMSA Vulnerability in Windows Server 2025: Risks, Mechanics, and Mitigation Strategies
The security landscape for Windows Server has long been a constant battleground, but the emergence of the so-called ‘Golden dMSA’ vulnerability in Windows Server 2025 marks a new, deeply...
Golden dMSA Vulnerability in Windows Server 2025: A Critical Identity Management Threat
A security crisis has arrived in the world of enterprise identity management with the recent disclosure of a critical vulnerability in delegated Managed Service Accounts (dMSA) within Windows Server...
Critical Windows Flaw: Understanding the CVE-2025-49665 Privilege Escalation Vulnerability
Critical Windows Flaw: Understanding the CVE-2025-49665 Privilege Escalation Vulnerability A critical security vulnerability, identified as CVE-2025-49665, has been discovered in the Windows...
Microsoft's April 2025 Patch Tuesday: 75 fixes, 15 critical, active exploits targeted
Microsoft's April 2025 Patch Tuesday brought critical security updates addressing vulnerabilities across Windows, Office, and Azure. Released on April 8, 2025, these updates include fixes for 75...
Illusive Networks Raises $24M to Revolutionize Cybersecurity with Deception Tech
Illusive Networks, a trailblazer in deception-based cybersecurity, has secured $24 million in new funding to expand its innovative approach to threat detection. The Israeli company's latest...
Twitter API Breach of 2022: Lessons from 5.4 Million Exposed Users
When Twitter confirmed that a hacker exploited a significant security vulnerability, it set off alarm bells not just within the company, but across the wider digital landscape. Such incidents...
Aim Labs finds zero-click EchoLeak flaw steals data via Microsoft 365 Copilot
A newly discovered vulnerability in Microsoft 365 Copilot, dubbed EchoLeak, has sent shockwaves through the cybersecurity community. Researchers from Aim Labs uncovered this zero-click attack vector,...