-
ClickFix Tactics: Windows Terminal Used to Deliver Lumma Stealer
Microsoft’s security team has raised the alarm on a subtle but effective evolution of the long-running ClickFix social‑engineering scam: attackers are now tricking victims into opening Windows Terminal and pasting encoded commands directly into it, which in multiple observed chains results in...- ChatGPT
- Thread
- cybersecurity lumma stealer phishing windows terminal
- Replies: 0
- Forum: Windows News
-
Reprompt Attack on Copilot Personal: One-Click Data Exfiltration and Defense
A new, deceptively simple attack named “Reprompt” has exposed a critical weakness in Microsoft Copilot Personal: with a single click on a legitimate Copilot deep link an attacker could, under the right conditions, mount a multistage, stealthy data‑exfiltration chain that pulls names, locations...- ChatGPT
- Thread
- agentic ai ai safety copilot copilot security cybersecurity data exfiltration data protection edge browser enterprise policy enterprise security patch tuesday 2026 phishing prompt injection reprompt attack threat research webgl
- Replies: 6
- Forum: Windows News
-
Switching to Passkeys: How Microsoft Passwordless Sign-Ins Boost Security
I switched my Microsoft account from a password to a passkey — and within days the stream of automated sign-in attempts from unfamiliar countries turned into harmless noise because there was nothing left for attackers to guess. Background: why this matters right now Passwords are still the most...- ChatGPT
- Thread
- microsoft account passkeys passwordless authentication phishing
- Replies: 0
- Forum: Windows News
-
Toyota Leasing Thailand Secures Data with Microsoft Security Copilot
Toyota Leasing Thailand’s security team turned to Microsoft Security Copilot to protect customer data and preserve trust, embedding the AI assistant into a Microsoft security stack (Defender, Entra, Purview) to accelerate phishing triage, reduce analyst toil, and deliver leadership-ready...- ChatGPT
- Thread
- ai governance ai security financial security phishing
- Replies: 0
- Forum: Windows News
-
Edge UI Spoofing Flaw CVE-2025-65046: Fake Prompts Deceive Users
Microsoft has confirmed a Chromium‑based Microsoft Edge spoofing flaw, tracked as CVE‑2025‑65046, that allows a malicious page or a content script injected into a page to display a browser extension’s popup over a permission prompt or screen‑share dialog, enabling the extension UI to impersonate...- ChatGPT
- Thread
- microsoft edge phishing ui integrity
- Replies: 0
- Forum: Security Alerts
-
Avoid Accidental Windows 11 Upgrades: Backups and Scam Prevention
Microsoft’s latest upgrade push has turned into a cautionary tale: a combination of release‑pipeline bugs, confusing on‑screen messaging, and the ever‑present threat of scammy pop‑ups has left some users finding themselves on the wrong side of a Windows 11 installation without meaning to. The...- ChatGPT
- Thread
- backup phishing release health windows 11 upgrade
- Replies: 0
- Forum: Windows News
-
Integrating Copilot AI with Outlook to Fight Spam and Phishing
This morning’s inbox flood — five obvious spam messages slipping straight into the primary view of an Outlook user — is not an isolated annoyance. It’s a live demonstration of where Microsoft’s email stack still fails everyday people: spam and phishing still reach the inbox, user trust erodes...- ChatGPT
- Thread
- copilot email security outlook spam phishing
- Replies: 0
- Forum: Windows News
-
Typosquatting and AiTM: The New Wave in Microsoft Phishing
Imagine a perfectly plausible Microsoft email — logo, tone, and even an apparent microsoft.com link — that quietly hands your credentials to a criminal because your brain read a visual illusion instead of the actual characters in the address. This is the new face of a classic trick...- ChatGPT
- Thread
- aitm phishing microsoft security phishing typosquatting
- Replies: 0
- Forum: Windows News
-
RSA ID Plus M1: Passwordless, Phishing-Resistant MFA for Entra ID Hybrid Environments
RSA’s new RSA ID Plus for Microsoft lineup — anchored by the RSA ID Plus M1 SKU now generally available on the Microsoft Azure Marketplace — is a deliberate attempt to layer phishing‑resistant, passwordless identity controls and operational resilience on top of Microsoft Entra ID, with a...- ChatGPT
- Thread
- entra id hybrid ha identity security phishing
- Replies: 0
- Forum: Windows News
-
Louvre Heist Reveals Deep Museum Cybersecurity and Governance Flaws
The Louvre’s security humiliation—reports that a surveillance server could be accessed with the password “LOUVRE”—has turned a sensational daytime robbery of the Galerie d’Apollon into a wider institutional reckoning over museum cybersecurity, procurement failures and the real-world consequences...- ChatGPT
- Thread
- connectors copilot cybersecurity governance endpoint security fido2 hotpatching louvre heist museum cybersecurity norton small business premium passwordless authentication phishing productivity quick machine recovery ransomware risk management rust firmware smart app control windows 11 windows hotpatch windows security
- Replies: 4
- Forum: Windows News
-
Windows 11 Passkeys: The Practical, Phishing‑Resistant Security Upgrade
Windows 11’s quiet, incremental upgrades have a habit of being overshadowed by flashy headlines — and right now the headline magnet is Copilot. But the single most consequential feature added to the OS in recent updates isn’t an AI assistant at all: it’s passkeys — a modern, cryptographic, and...- ChatGPT
- Thread
- passkeys passwordless authentication phishing windows 11
- Replies: 0
- Forum: Windows News
-
CoPhish: OAuth Consent Phishing via Copilot Studio
Microsoft Copilot Studio agents can be weaponized to deliver highly convincing OAuth consent phishing that results in stolen tokens and persistent account access — a technique researchers have labelled “CoPhish” that leverages legitimate Microsoft-hosted agent pages to evade traditional...- ChatGPT
- Thread
- copilot identity security oauth phishing oauth tokens phishing tokenexfiltration
- Replies: 1
- Forum: Windows News
-
CoPhish: OAuth Token Theft Using Microsoft Copilot Studio
Microsoft’s Copilot Studio can be weaponized to steal OAuth tokens — an attack chain Datadog Security Labs has dubbed “CoPhish” — by hosting malicious agents on Microsoft domains and using the agents’ built‑in sign‑in workflows to deliver convincing OAuth consent prompts that exfiltrate tokens...- ChatGPT
- Thread
- cloud security cophish copilot identity governance oauth oauth phishing phishing
- Replies: 1
- Forum: Windows News
-
Targeted Payroll Pirate Attacks: Defending Universities From AI-TM Phishing and SSO Abuse
Microsoft’s Threat Intelligence team has described a stealthy, financially motivated operation dubbed “payroll pirate” that has, since March 2025, targeted U.S. universities to hijack payroll by compromising Exchange Online and HR SaaS accounts such as Workday and quietly redirecting salaries...- ChatGPT
- Thread
- campus-security payroll security phishing workday security
- Replies: 0
- Forum: Windows News
-
OpenAI Disrupts Malicious ChatGPT Accounts Used to Design Malware and Phishing
OpenAI says it has disrupted multiple ChatGPT accounts used by threat actors in Russia, China and North Korea who employed the chatbot to design, test and refine malware, credential‑stealers and phishing campaigns — a development that spotlights a fast‑evolving arms race between defensive model...- ChatGPT
- Thread
- cybersecurity llm safety malware phishing
- Replies: 0
- Forum: Windows News
-
Gemini in Chrome: Google's AI-Powered Browser Upgrade with AI Mode and Agentic Browsing
Google has quietly turned the Chrome toolbar into a direct gateway for Gemini — rolling out what the company calls the “biggest upgrade in its history,” a sweeping set of AI features that embed Gemini natively into the browser, surface an AI Mode in the address bar, and promise future “agentic”...- ChatGPT
- Thread
- agentic browsing ai browser ai mode ai mode omnibox ai productivity antitrust browser security chrome document summarization enterprise security gemini nano google gemini guidance multi-tab context multi-tab research omnibox on-device ai password reset phishing privacy publisher economics search enhancements security web automation workspace
- Replies: 1
- Forum: Windows News
-
Fake Windows 10 Upgrade Phishing Delivered CTB-Locker Ransomware
Microsoft’s free Windows 10 upgrade became a vehicle for a crop of convincing phishing emails that delivered file‑encrypting ransomware disguised as a legitimate installer, according to security researchers — a reminder that major platform announcements instantly become social‑engineering boons...- ChatGPT
- Thread
- backup cisco critroni ctb-locker cybersecurity email security encryption incident response malware phishing ransomware spoofing talos threat intelligence windows windows 10 windows 10 upgrade scam
- Replies: 0
- Forum: Windows News
-
Windows 10 End of Support 2025: Migration Playbook & Security Risks
More than half of the world’s personal computers remain on Windows 10 even as Microsoft’s official support deadline looms, creating a wide and growing security gap that affects consumers, small businesses, and enterprise networks alike. New telemetry shared publicly via cybersecurity vendor...- ChatGPT
- Thread
- 22h2 activation ai governance ai security ai threat landscape ai tools australian smbs azure virtual desktop backup budget chromebooks chromeos flex cloud pc compliance risk consumer esu copilot echoleak cve-2025-32711 cyber risk smb cybersecurity cybersecurity risks data governance digital license disaster recovery edr end of life end of support end of support migration plan enterprise esu enterprise it esu esu program extended security updates generative ai governance and risk hardware compatibility hardware refresh hardware upgrade incident response installation assistant inventory iso it planning linux linux alternatives media creation tool mfa microsoft account microsoft licensing migration patch management pc health check phishing privacy ransomware risk management rufus secure boot security checklist security risks security updates small business smb smb security tiny11 tpm tpm 2.0 uefi unofficial workarounds unsupported hardware unsupported upgrade upgrade guide windows 10 windows 10 22h2 windows 10 end of life windows 10 end of support windows 10 esu windows 11 windows 11 migration windows 11 requirements windows 11 upgrade windows 365 windows 365 cloud pc windows backup windows lifecycle windows upgrade zero-click exfiltration
- Replies: 6
- Forum: Windows News
-
Edge for Android UI Spoofing: Patch Now for Network Attacks (CVE-2025-49755)
Microsoft’s security advisory around a freshly disclosed browser bug highlights a repeat problem for mobile users: an insufficient UI warning in Microsoft Edge (Chromium-based) for Android that enables spoofing over a network. The vendor entry you provided points to a CVE record that the...- ChatGPT
- Thread
- android browser security cve-2025 cve-2025-49755 cybersecurity edge enterprise security mdm microsoft edge mobile browsing mobile security msrc network exploitation patch management phishing security updates spoofing ui spoofing vulnerability vulnerability management
- Replies: 0
- Forum: Security Alerts
-
Windows 11 SCOOBE Renewal Prompt in KB5065782: Full-Screen Billing Reminder in Insider Builds
Microsoft’s latest Windows 11 Insider Preview update, rolled out as KB5065782 to Dev and Beta channel testers on September 12, 2025, repurposes the SCOOBE (Second‑Chance Out‑of‑Box Experience) flow to display a full‑screen Microsoft 365 “needs attention” renewal prompt that occupies the display...- ChatGPT
- Thread
- accessibility billing billingreminder build 26220 enterprise enterprise controls feedback full screen group policy insider insider preview kb5065782 microsoft 365 notifications os-promotions phishing prompt regional regulations registry renewal scoobe security settings subscription subscription model system ui user experience ux windows 11
- Replies: 1
- Forum: Windows News