‼️🚨 This is alarming: Researchers found a one-click data exfiltration vulnerability in M365 Copilot. A single click on a trusted microsoft[.]com link let attackers pull emails, MFA codes, meeting notes, and SharePoint/OneDrive files, no permissions or second click required.
Microsoft has patched it as CVE-2026-42824, rated critical.
Microsoft Threat Intelligence continues to observe Sapphire Sleet refining their macOS intrusion tactics, following the same previously documented core attack chain, but with a new Teams‑themed lure. https://t.co/1Gtyc7X8Zz
Along with the lure, the new activity also uses updated infrastructure and component naming while maintaining the same user-driven execution model: tricking users into executing trusted system tools to enable credential theft, persistence, and data exfiltration without exploiting vulnerabilities.
We updated our blog to highlight the new Sapphire Sleet campaign, and expanded Microsoft Defender detections and hunting queries to help organizations defend against this new activity.
Run a full coding agent locally.
No API bills. No limits. No data leaving your machine.
Private. Powerful. 100% free.
I made a step-by-step guide anyone can follow in minutes.
To get it, just:
→ Like + Repost
→ Comment “LOCAL”
→ Follow me (so I can DM)
Yesterday a quasi-judicial body in Italy fined @Cloudflare $17 million for failing to go along with their scheme to censor the Internet. The scheme, which even the EU has called concerning, required us within a mere 30 minutes of notification to fully censor from the Internet any sites a shadowy cabal of European media elites deemed against their interests. No judicial oversight. No due process. No appeal. No transparency. It required us to not just remove customers, but also censor our 1.1.1.1 DNS resolver meaning it risked blacking out any site on the Internet. And it required us not just to censor the content in Italy but globally. In other words, Italy insists a shadowy, European media cabal should be able to dictate what is and is not allowed online.
That, of course, is DISGUSTING and even before yesterday’s fine we had multiple legal challenges pending against the underlying scheme. We, of course, will now fight the unjust fine. Not just because it’s wrong for us but because it is wrong for democratic values.
In addition, we are considering the following actions: 1) discontinuing the millions of dollars in pro bono cyber security services we are providing the upcoming Milano-Cortina Olympics; 2) discontinuing Cloudflare’s Free cyber security services for any Italy-based users; 3) removing all servers from Italian cities; and 4) terminating all plans to build an Italian Cloudflare office or make any investments in the country.
Play stupid games, win stupid prizes. While there are things I would handle differently than the current U.S. administration, I appreciate @JDVance taking a leadership role in recognizing this type of regulation is a fundamental unfair trade issue that also threatens democratic values. And in this case @ElonMusk is right: #FreeSpeech is critical and under attack from an out-of-touch cabal of very disturbed European policy makers.
I will be in DC first thing next week to discuss this with U.S. administration officials and I’ll be meeting with the IOC in Lausanne shortly after to outline the risk to the Olympic Games if @Cloudflare withdraws our cyber security protection.
In the meantime, we remain happy to discuss this with Italian government officials who, so far, have been unwilling to engage beyond issuing fines. We believe Italy, like all countries, has a right to regulate the content on networks inside its borders. But they must do so following the Rule of Law and principles of Due Process. And Italy certainly has no right to regulate what is and is not allowed on the Internet in the United States, the United Kingdom, Canada, China, Brazil, India or anywhere outside its borders.
THIS IS AN IMPORTANT FIGHT AND WE WILL WIN!!!
Time do get rubber cement out and start patching an #ivanti flaw is being used to distribute malware. Take a look here to see if you are effective.
https://t.co/UvPRWmpjuS
Warm up the coffee and get to patching. There are 3 active exploits for @VMware that have been placed on the KEV. Read below and put in a Emergency Request.
#vulnerability .
https://t.co/ElQY0OGxf2
Ok FortiPeople time to schedule an update if you use #FortiWLM or #FortiManager. There are two critical RCE vulnerabilities.
Get your sew machines ready and sew that patch on.
https://t.co/1UT7q7RnjQ
Interesting read on a set of attacks on perimeter devices including @Cisco ASA's by @TalosSecurity. There are instructions on what to patch. #securitythreat#CYBER
https://t.co/jFRBbbtsoL