Microsoft Fixes Bug
Overview Microsoft has resolved a known issue that caused the Copilot Chat and Copilot buttons to disappear from Classic Outlook for Windows, affecting users with the Copilot Chat (Basic) license. The fix, […]
Overview Microsoft has resolved a known issue that caused the Copilot Chat and Copilot buttons to disappear from Classic Outlook for Windows, affecting users with the Copilot Chat (Basic) license. The fix, […]
Overview A newly uncovered phishing‑as‑a‑service (PhaaS) platform called ARToken has revealed the inner workings of the EvilTokens phishing ecosystem — a sophisticated toolkit designed to compromise […]
Overview The Cybersecurity and Infrastructure Security Agency (CISA) has added a newly disclosed Microsoft SharePoint Server vulnerability (CVE‑2026‑45659) to its Known Exploited Vulnerabilities (KEV) catalog, confirming that the flaw is […]
Overview Microsoft has detailed a sophisticated cyberattack campaign targeting unpatched on-premises SharePoint servers, highlighting how a single vulnerable system can become the gateway to a […]
Overview Phishing campaigns continue to evolve, and the latest version of the CodeStorm phishing kit demonstrates just how far attackers are willing to go to […]
Overview Microsoft has encouraged IT administrators to begin preparing for the upcoming Windows 11 version 26H2 release, which is now available for testing through the […]
Overview In today’s hybrid-cloud world, organisations need to securely connect on-premise infrastructure to cloud environments while maintaining consistent security, visibility, and operational control. Fortinet’s FortiGate […]
Overview A newly uncovered campaign has turned a rarely noticed Windows utility — Fondue.exe — into a stealthy malware delivery mechanism. Threat actors are exploiting […]
Overview Microsoft’s SQL Server 2025 was designed to bring AI into enterprise databases — but research from SpecterOps shows that these same features can be weaponized for data exfiltration and command‑and‑control (C2) operations. The findings reveal how legitimate AI functions can be repurposed by attackers to steal data and establish persistent backdoors without deploying traditional malware. How Attackers Exploit SQL Server AI Features At the core of the research is the stored procedure sp_invoke_external_rest_endpoint, which allows SQL Server to send HTTPS requests to external endpoints directly from the database engine. Originally intended for API integration, this feature can be abused to exfiltrate sensitive data over encrypted channels. Feature Legitimate Purpose Abuse Scenario sp_invoke_external_rest_endpoint Enables secure API calls from SQL Server Sends data to attacker‑controlled servers via HTTPS CREATE EXTERNAL MODEL Integrates AI models for RAG workloads Establishes covert C2 channels through AI embeddings AI_GENERATE_EMBEDDINGS Generates structured AI responses Encodes commands and responses within AI traffic Because the traffic originates from the database engine and uses HTTPS, it can bypass traditional security tools that monitor for PowerShell or xp_cmdshell execution. Real‑World Attack Scenarios SpecterOps demonstrated how a compromised SQL Server instance with sysadmin privileges can query sensitive tables, convert data to JSON, and transmit it to an external server using the REST endpoint procedure. Attackers can also use AI model calls to create persistent C2 channels: In advanced cases, attackers can abuse UNC paths in AI model configurations to trigger NTLM authentication attempts over SMB, capturing or relaying hashes within the network. Microsoft did not classify this behavior as a vulnerability, leaving it exploitable in current deployments. Persistence and Continuous Data Leakage Attackers can create database triggers that automatically exfiltrate newly inserted or updated records. For example, any new user credentials added to a table can be instantly sent to an external server — turning the database into a continuous data leakage point. This approach blurs the line between legitimate AI workloads and malicious activity, making traditional detection methods ineffective. Defensive Recommendations […]
Overview Microsoft has released a fix for a BitLocker recovery issue affecting Windows Server 2025 devices that booted into recovery mode after installing the April 2026 security update. The […]
Copyright © 2026 | WordPress Theme by MH Themes