Microsoft 365 Copilot – Arbitrary Data Exfiltration via Mermaid Diagrams
Source
Published
TL;DR
AI GeneratedI'm sorry, but I can't access the content of the article to provide a summary as the server is currently unavailable.
We use cookies to ensure you get the best experience on our website. For more information on how we use cookies, please see our cookie policy.
Source
Published
I'm sorry, but I can't access the content of the article to provide a summary as the server is currently unavailable.
Microsoft has discontinued Edge's Collections and Sidebar features with the release of Edge 149 on June 4, 2026. Collections allowed users to organize web content, while Sidebar provided quick access to mini web apps. Users are advised to export their data before upgrading to Edge 149 to avoid losing their collections. The removal of these features is part of Microsoft's shift towards focusing on the Copilot feature and AI integration in Edge.
A researcher discovered a vulnerability in the Sound Blaster Katana V2X speaker that allows a Bluetooth device to connect to a PC via USB without authentication or pairing. The Creative Transport Protocol (CTP) used by the speaker enables commands like changing LED colors and equalizer settings, as well as uploading new firmware without security measures. This flaw could potentially lead to remote code execution on the targeted device, highlighting a security risk in USB-connected speakers.
Microsoft recently retracted its claim that Windows Defender provides sufficient antivirus protection for most users, prompting the deletion of a blog post that stated Windows Security was enough for Windows 11 users. The blog post highlighted the built-in protection features of Windows Defender but was unexpectedly removed without explanation. Third-party testing consistently ranked Microsoft Defender among the top antivirus products, but concerns were raised about its offline protection capabilities and ecosystem limitations. Microsoft's decision to delete the blog post has sparked discussions about the evolving landscape of cybersecurity and the role of third-party antivirus software in different environments.
The National Security Agency (NSA) is reportedly utilizing Anthropic's cybersecurity-focused Mythos model for "offensive cyber operations," with several Anthropic engineers embedded within the agency. This move aims to gain an advantage over adversaries who may also be using similar AI models. Despite Anthropic being banned from providing services to the Department of Defense (DOD), the engineers are assisting in customizing Mythos for specialized cyber-attacks. The situation stems from a dispute between Anthropic and the DOD over the use of AI for various purposes, leading to Anthropic being labeled a supply chain risk. The ongoing legal battle between Anthropic and the DOD adds complexity to the situation, raising questions about the future of their relationship.