Microsoft Says Bug Causes Copilot to Summarize Confidential Emails

Microsoft 365 Copilot bug since January causes AI to incorrectly summarize confidential emails, bypassing DLP policies. A code error allows emails marked with confidentiality labels to be processed, prompting Microsoft to initiate a fix. As of mid-February, they continue monitoring the situation but have not disclosed the full impact or timeline for resolution.

https://www.bleepingcomputer.com/news/microsoft/microsoft-says-bug-causes-copilot-to-summarize-confidential-emails/

Flaws in Popular VSCode Extensions Expose Developers to Attacks

Flaws in popular VSCode extensions allow attackers to steal files and execute code. Vulnerabilities affect extensions like Code Runner and Markdown Preview Enhanced, with over 128 million total downloads. Discovered by Ox Security, the issues pose risks such as data exfiltration and system takeover. Developers are advised against using untrusted configurations and to only install reputable extensions.

https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/

Huntr

Huntr is the first bug bounty platform focused on AI/ML, allowing security researchers to report vulnerabilities in open-source AI/ML apps, libraries, and model formats. It features over 240 programs with bounties up to $1500. Users can join and engage via Discord to contribute to the security of AI/ML projects.

https://huntr.com/

CyberheistNews Vol 16 #07 Uncovering the Sophisticated Phishing Campaign Bypassing M365 MFA

Phishing campaign bypassing M365 MFA detected, compromising accounts by exploiting OAuth 2.0 flows. Attackers trick users into authenticating on legitimate Microsoft domains, stealing access tokens for persistent access to data. Key sectors targeted include tech, manufacturing, and finance. Immediate mitigation requires auditing OAuth apps and reviewing email logs. Additionally, there’s discussion on automation in incident response, AI-driven email security, and the evolution of romance scams using deepfake technology. New voice phishing kits enable real-time control over attacks, raising concerns over email security gaps in organizations.

https://blog.knowbe4.com/cyberheistnews-vol-16-07-uncovering-the-sophisticated-phishing-campaign-bypassing-m365-mfa

UK.gov Launches Cyber ‘lockdown’ Campaign as 80% of Orgs Hit

UK government launches cyber lockdown campaign urging businesses to enhance digital defenses, as report shows 82% of organizations experienced cyber incidents. Only 30% adhere to Cyber Essentials standards. Campaign aims to raise awareness among SMEs about the risks and importance of basic cybersecurity measures. Free resources offered to assist businesses in improving security practices.

https://www.theregister.com/2026/02/17/govt_launches_cyber_lockdown_push/

Manipulating AI Memory for Profit: The Rise of AI Recommendation Poisoning

AI Recommendation Poisoning exploits AI memory to influence recommendations by embedding hidden instructions in prompts. Companies use malicious URLs in “Summarize with AI” buttons, instructing AIs to remember them favorably, leading to biased outputs. The trend poses risks as poisoned AIs provide slanted advice on critical topics, affecting users' decisions without their awareness. Microsoft has begun implementing protections against these attacks, but research indicates widespread attempts across various industries to manipulate AI assistants.

https://www.microsoft.com/en-us/security/blog/2026/02/10/ai-recommendation-poisoning/

Chinese Hackers Exploiting Dell Zero-day Flaw Since Mid-2024

Chinese hackers have been exploiting a critical Dell security flaw, identified as CVE-2026-22769, in their RecoverPoint for Virtual Machines since mid-2024. The UNC6201 group uses hardcoded credentials for unauthorized access, deploying sophisticated malware like Grimbolt to infiltrate VMware networks. To mitigate these attacks, Dell advises affected customers to apply recommended remediations.

https://www.bleepingcomputer.com/news/security/chinese-hackers-exploiting-dell-zero-day-flaw-since-mid-2024/

What Your Bluetooth Devices Reveal About You

Bluetooth devices leak personal data. The author built Bluehood, a scanner to analyze Bluetooth presence patterns and understand data exposure risks. Key points include the unintended information leaked by always-on Bluetooth devices, lack of control over Bluetooth settings in many devices, and potential privacy tools needing Bluetooth for functionality. Bluehood passively monitors devices, creating heatmaps and identifying patterns. The main takeaway: users need to be aware of their Bluetooth habits to make informed privacy decisions.

https://blog.dmcc.io/journal/2026-bluetooth-privacy-bluehood/

Password Managers Don’t Protect Secrets if Pwned

Research exposes vulnerabilities in popular password managers (Bitwarden, LastPass, Dashlane) claiming zero-knowledge encryption, enabling potential password exposure if servers are compromised. Bitwarden was most affected, with 12 attack methods detailed; LastPass and Dashlane followed with 7 and 6 respectively. The study urges enhanced security practices and clear communications from providers regarding risks and protections. Vendors acknowledged flaws and are addressing them, but similar vulnerabilities may apply to others in the industry.

https://www.theregister.com/2026/02/16/password_managers/

Eurail Says Stolen Traveler Data Now up for Sale on Dark Web

Eurail's stolen customer data is for sale on the dark web after a breach revealed sensitive records, including names and bank details. The company is investigating the extent of the breach and has notified data protection authorities. Affected customers should be alert for phishing attempts and update their passwords.

https://www.bleepingcomputer.com/news/security/eurail-says-stolen-traveler-data-now-up-for-sale-on-dark-web/

Are Hackers Trying to Utilize Gemini AI’s Capabilities for Malicious Purposes?

Hackers are attempting to exploit Gemini AI for cyberattacks, as highlighted in a Google Threat Intelligence report. While direct cloning hasn’t succeeded, state-sponsored groups are using AI tools for sophisticated hacks. The private sector is also interested in Gemini’s proprietary technology for development, raising concerns about intellectual property theft. Despite growing reliance on AI, Americans remain distrustful, fearing privacy violations and data exploitation.

https://www.pandasecurity.com/en/mediacenter/are-hackers-trying-to-utilize-gemini-ais-capabilities-for-malicious-purposes/

Infostealer Malware Found Stealing OpenClaw Secrets for First Time

Infostealer malware has been detected stealing sensitive data from OpenClaw, an AI assistant framework, marking a new trend in targeting personal AI configurations. The stolen files include API keys and login information, with a potential full compromise of victims' digital identities. Hudson Rock identified the malware as having similarities to the Vidar infostealer. As OpenClaw gains traction, its configuration files, containing sensitive authentication secrets, are increasingly being targeted by cybercriminals.

https://www.bleepingcomputer.com/news/security/infostealer-malware-found-stealing-openclaw-secrets-for-first-time/

Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging

Microsoft revealed a new ClickFix attack utilizing nslookup for malware staging. Attackers trick users into running DNS lookups to retrieve malicious payloads, circumventing security measures by having victims infect their own machines. This technique has evolved into various forms and leverages DNS traffic as a stealthy method of signaling to malicious infrastructure. The attack can lead to further malware deployment, including remote access trojans and information stealers, particularly targeting both Windows and macOS users amidst rising incidents of cryptocurrency theft.

https://thehackernews.com/2026/02/microsoft-discloses-dns-based-clickfix.html

Scroll to Top