‼️🚨 This is alarming: Researchers found a one-click data exfiltration vulnerability in M365 Copilot. A single click on a trusted microsoft[.]com link let attackers pull emails, MFA codes, meeting notes, and SharePoint/OneDrive files, no permissions or second click required.
Microsoft has patched it as CVE-2026-42824, rated critical.
I made a personal black hole that makes you take breaks 🕳️
A shader for Ghostty that spawns a small black hole in your terminal - it drifts around, gravitationally lensing your text. The longer you work without stopping, the bigger it gets, until it's basically demanding you go touch grass
Take a break and it quietly shrinks away
Tracks users with favicons, even in incognito mode,
tracks you even after clearing cache, using VPN, or running ad blockers.
- https://t.co/sKiR0XGgtu
#infosec#cybersec
⚠️Windows Search URI Handler Flaw Leaks NTLMv2 Hashes to Attacker-Controlled Servers
Source: https://t.co/CaxCINR3Ly
A newly disclosed flaw in the Windows search URI handler can silently leak NTLMv2 hashes to attacker-controlled servers with nothing more than a single link click. This behavior is the same bug class as CVE-2026-33829 in the Snipping Tool, but Microsoft has assigned no CVE and shipped no fix for this variant.
That bug allowed attackers to supply a filePath parameter pointing to a remote UNC path, triggering outbound SMB authentication and exposing the victim’s Net-NTLMv2 hash. A user could be tricked into clicking what appeared to be a normal link, and their machine would automatically try to “check in” to an attacker’s SMB server.
#cybersecuritynews
🚨 A security researcher has just disclosed a one-click GitHub token-stealing exploit that abuses a VS Code bug.
https://t.co/pBX7au8tGT
Ammar Askar disclosed a one-click GitHub token-stealing issue affecting https://t.co/4ahrVFQWcw and VS Code webviews, where a victim clicking a crafted https://t.co/4ahrVFQWcw link could be led into a malicious notebook/workspace flow that abuses VS Code’s webview keyboard event handling to install attacker-controlled extension behavior.
According to the researcher, the exposed GitHub token can read and write repositories the user has access to, including private repositories, because https://t.co/4ahrVFQWcw receives a broad OAuth token from GitHub.
The post includes a proof-of-concept, notes that the desktop version of VS Code may also be affected under harder-to-exploit conditions, and recommends clearing https://t.co/4ahrVFQWcw site data as a mitigation while the issue is publicly disclosed.
Introducing HTTP/2 Bomb: a remote DoS in nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora. A single client pins 32GB of server memory in 10s. Found by Codex.
Blog post: https://t.co/WO9MeExoun
PoCs: https://t.co/NpVgEHBHPl
Microsoft just posted a 400-word statement about how much they respect security researchers.
“We have no intention to pursue action against individuals conducting security research.”
They are currently pursuing legal action against Nightmare-Eclipse.
The researcher they banned from GitHub.
Whose account they deleted.
Whose bug bounty they denied.
Who then dropped six zero-days in six weeks.
Three of which were exploited in the wild within days.
Microsoft’s legal team sent this statement to the PR team.
The PR team posted it anyway.
The researchers are still releasing vulnerabilities for free.
The statement did not slow them down.