Cyberattack Prevention
The latest Cyberattack Prevention coverage — news, analysis, and updates from the WindowsNews.AI desk.
EchoLeak Zero-Click Flaw in Microsoft 365 Copilot Exposes Sensitive Data
In January 2025, security researchers at Aim Labs uncovered a critical zero-click vulnerability in Microsoft 365 Copilot AI, designated as CVE-2025-3271 and dubbed "EchoLeak." This flaw allowed...
EchoLeak: Critical Microsoft Copilot Vulnerability Exposes Enterprise Data
A newly discovered security flaw in Microsoft Copilot, dubbed 'EchoLeak,' has sent shockwaves through the enterprise security community. Researchers at cybersecurity firm Varonis uncovered that this...
EchoLeak Zero-Click Vulnerability in Microsoft 365 Copilot: Risks & Mitigation
A newly discovered zero-click vulnerability in Microsoft 365 Copilot, named EchoLeak, has sent shockwaves through the enterprise security community. Security researchers at Aim Labs uncovered this...
CVE-2025-32711: EchoLeak zero-click flaw in M365 Copilot lets emails exfiltrate data
In June 2025, cybersecurity researchers uncovered a critical zero-click vulnerability (CVE-2025-32711) in Microsoft 365 Copilot, marking one of the most severe AI-assisted security flaws to date....
Microsoft Copilot security flaws expose AI prompt injection and data leak risks in business apps
Microsoft's Copilot, an AI-driven assistant integrated into the Microsoft 365 suite, has recently been at the center of significant security concerns. These issues not only highlight vulnerabilities...
Microsoft June 2025 Patch Tuesday: 76 fixes, 3 zero-days, SMBv3 critical flaw
Microsoft’s latest June Patch Tuesday for 2025 has arrived, delivering a comprehensive set of security updates and performance improvements across its ecosystem. This month’s release addresses 76...
Patch CVE-2025-33053 now—Microsoft confirms active WebDAV zero-day exploits.
Microsoft has issued an emergency security update to patch a critical zero-day vulnerability, CVE-2025-33053, which is currently being exploited by cybercriminals. This flaw affects multiple Windows...
Microsoft Outlook to Block .library-ms & .search-ms Files in 2025 Security Update
Microsoft is tightening Outlook's security measures by blocking two potentially dangerous file types—.library-ms and .search-ms—starting July 2025. This move aims to counter sophisticated...
Critical WebDAV & SMB flaws patched June 2025—exploits active, CVSS 9.8
Microsoft’s June 2025 Patch Tuesday addresses two critical vulnerabilities—CVE-2025-XXXX in Windows WebDAV and CVE-2025-YYYY in SMB—that could allow remote code execution and privilege...
Actively Exploited Windows WebDAV Zero-Day CVE-2025-33053: Patch Now
Microsoft has recently disclosed a critical zero-day vulnerability in its Web Distributed Authoring and Versioning (WebDAV) protocol, tracked as CVE-2025-33053, which is already being actively...
Critical Microsoft Word Vulnerability (CVE-2025-32717): How to Protect Against Malicious Document Exploits
A newly discovered critical vulnerability in Microsoft Word, tracked as CVE-2025-32717, is being actively exploited in the wild, putting millions of users at risk of remote code execution attacks....
Microsoft Word CVE-2025-47168: Critical RCE Vulnerability & How to Stay Protected
A newly discovered critical vulnerability in Microsoft Word, tracked as CVE-2025-47168, has sent shockwaves through the cybersecurity community. This use-after-free flaw allows attackers to execute...