1.Microsoft Copilot AI Exposes Sensitive Data
Multiple vulnerabilities in Microsoft’s Copilot AI for SharePoint have been discovered. These flaws allow attackers to access sensitive corporate data, including passwords and confidential documents. Pen Test Partners found that attackers can bypass security measures using SharePoint’s AI assistants, both default and custom. The exploits operate undetected, leaving no digital footprint, and researchers recommend enhanced monitoring and access control practices to mitigate these risks.
2.PupkinStealer Targets Data Through Telegram
PupkinStealer is an information-stealing malware that targets browser credentials, files, and messaging sessions. Developed in C# and leveraging Telegram’s Bot API, it enables rapid and stealthy data exfiltration. This malware extracts passwords, session data, and screenshots from compromised systems, sending the stolen data to attackers. Experts recommend robust cybersecurity practices, including password managers and multi-factor authentication, to mitigate risks.
3. Fake AI Video Tools Spread Noodlophile
Fake AI-powered video generation tools, such as “Dream Machine,” are being used to distribute the Noodlophile malware. Victims are tricked into downloading ZIP archives, which disguise an executable file posing as a video. Once executed, the malware targets sensitive information, such as browser credentials, session cookies, and cryptocurrency wallet files. Noodlophile then exfiltrates stolen data via Telegram bots, giving attackers real-time access to the compromised information.