loader image
CoPhish Breach Uses Microsoft Copilot to Steal Tokens

A new phishing campaign, dubbed CoPhish, exploits Microsoft Copilot Studio to steal OAuth tokens by mimicking legitimate Microsoft services. The CoPhish breach uses Microsoft Copilot’s customizable AI agents hosted on trusted domains to disguise malicious OAuth consent attacks, increasing the likelihood that users will approve harmful app permissions. According to Datadog Security Labs, attackers build […]

**EDR-Redir Tool Outsmarts Defenses Using Windows Driver**

A newly released exploit tool called EDR-Redir allows attackers to reroute or isolate the executable folders of leading endpoint detection and response solutions. The EDR Redir Tool Outsmarts traditional protections by exploiting Windows’ Bind Filter and Cloud Filter drivers, enabling advanced redirection tactics without needing kernel-level access. The technique uses Windows 11’s Bind Link feature, […]

EU Charges Meta, TikTok With Major DSA Breaches

The European Commission has formally accused Meta and TikTok of breaching the Digital Services Act, marking a significant regulatory move as the EU charges Meta TikTok over systemic failures in platform governance. Investigators allege that both companies failed to mitigate the spread of harmful content and did not provide sufficient transparency in their content moderation […]

OpenAI Atlas Jailbroken by Malicious Prompt URLs

OpenAI’s new AI-powered browser, ChatGPT Atlas, has been compromised by a vulnerability that allows attackers to disguise malicious prompts as URLs. The exploit, revealed by security firm NeuralTrust, enables threat actors to jailbreak the system by embedding harmful instructions in malformed web addresses, a flaw now referred to as OpenAI Atlas Jailbroken. These deceptive strings […]

Phishing Attack Uses UUID Trick to Evade Email Security

A new phishing attack uses UUID-based techniques to bypass Secure Email Gateways, exploiting dynamically generated identifiers and randomized domains to evade detection. Security researchers at Cofense identified the campaign in early February 2025, highlighting its use of JavaScript scripts embedded in HTML attachments or spoofed services like SharePoint, OneDrive, and Adobe Acrobat Sign. Unlike conventional […]

Cyber Decoys Trap Hackers as Detection Tech Advances

As cyber threats grow more advanced, traditional defenses like firewalls struggle to keep pace. Cyber decoys trap hackers by luring them into fake environments, allowing defenders to detect and respond to threats before real systems are compromised. Deception technology now plays a pivotal role in proactive cybersecurity strategies, offering early detection, low false positives, and […]

North Korea Hacks EU Drone Firms in Data Theft Blitz

State-sponsored hackers from North Korea’s Lazarus group have launched a cyberespionage campaign targeting European firms in the unmanned aerial vehicle sector. The operation, which began in March 2025, compromised three defense-related organizations in Central and Southeastern Europe. This marks another development in the series of North Korea hacks targeting EU drone technology. The attackers used […]

China-Backed Hackers Share Logins in Spyware Alliance

China-backed hackers share logins through a newly uncovered program dubbed “Premier Pass-as-a-Service,” according to a report from Trend Research. The report highlights a surge in coordination among China-aligned advanced persistent threat (APT) groups, marking a significant evolution in global cyberespionage tactics. These groups are now exchanging credentials and network access, enabling wider infiltration across targeted […]