Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected vendors an opportunity to better understand the impact and address them before they are publ… Continue reading Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

Posted in Uncategorized

Microsoft’s Copilot trust test: Zero findings, more models, wider oversight

Microsoft 365 Copilot and Copilot Chat (Copilot) have been recertified under ISO/IEC 42001:2023 by an independent auditor for the second consecutive year. Copilot first received ISO 42001 certification in March 2025. This year’s recertification recorde… Continue reading Microsoft’s Copilot trust test: Zero findings, more models, wider oversight

Acer Announces New Snapdragon Laptops, Intel-Powered Gaming Handheld

Acer announced new Swift and Aspire laptops powered by Qualcomm Snapdragon processors alongside a Predator gaming handheld.
The post Acer Announces New Snapdragon Laptops, Intel-Powered Gaming Handheld appeared first on Thurrott.com.
Continue reading Acer Announces New Snapdragon Laptops, Intel-Powered Gaming Handheld

MyPillow listed on ransomware gang’s leak site, but denies it has been breached

A notorious ransomware gang claims to have stolen MyPillow’s private data, but CEO Mike Lindell calls it a politically motivated “hit job.” With the countdown ticking toward a massive dark web leak, who is telling the truth?

Read more in my article on… Continue reading MyPillow listed on ransomware gang’s leak site, but denies it has been breached

ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, and enough exposed infrastructure to make you wonder i… Continue reading ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

Posted in Uncategorized

Zapier exploit chain shows how known anti-patterns compose into critical risk

A five-stage exploit chain disclosed by Token Security researchers turned a free Zapier account into write access on Zapier’s public developer SDK packages and on internal packages that load in every authenticated zapier.com session. Each link in… Continue reading Zapier exploit chain shows how known anti-patterns compose into critical risk