ThreatCluster
  • Feed
  • Dashboard
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Article

Microsoft patched a critical vulnerability in its NLWeb AI search tool – but there's no CVE (yet)

Threat Score:
88
IT Pro Security
4 hours ago

Overview

Limited Content Available

We were unable to pull all insights from this article. Clustering, as well as Threat and Business intelligence may be limited.

Researchers found an unauthenticated path traversal bug in the tool debuted at Microsoft Build in May...

Continue Reading on Original Site

Related Articles

5 articles
1

SonicWall says recent attack wave involved previously disclosed flaw, not zero-day

Cybersecurity Dive • 3 hours ago

The company said it had linked recent hacks to customers’ use of legacy credentials when migrating from Gen 6 to Gen 7 firewalls.

Score
91
Read more
2

Business Associate Data Breaches Affect Florida Healthcare Providers

Hipaajournal • 4 hours ago

PhyNet Dermatology, a business associate of Premier Dermatology Partners, has identified unauthorized access to an email account containing patient information. […]

Score
88
Read more
3
SonicWall finds no SSLVPN zero-day, links ransomware attacks to 2024 flaw

SonicWall finds no SSLVPN zero-day, links ransomware attacks to 2024 flaw

BleepingComputer • 2 hours ago

SonicWall finds no SSLVPN zero-day, links ransomware attacks to 2024 flaw Bill Toulas August 7, 2025 11:27 AM 0 SonicWall says that recent Akira ransomware attacks exploiting Gen 7 firewalls with SSLVPN enabled are exploiting an older vulnerability rather than a zero-day flaw. The company says that the attackers are targeting CVE-2024-40766, an unauthorized access flaw fixed in August 2024. "We now have high confidence that the recent SSLVPN activity is not connected to a zero-day vulnerability,

Score
87
Read more
4

Google Confirms Salesforce Data Breach by ShinyHunters via Vishing Scam

Hackread • 3 hours ago

Google confirms a data breach by ShinyHunters hackers, who used a vishing scam to access a Salesforce database with small business customer info.

Score
87
Read more
5

Google Among Victims in Ongoing Salesforce Data Theft Campaign

Infosecurity Magazine • 5 hours ago

Google confirms it was among the victims of an ongoing data theft campaign targeting Salesforce instances, where publicly available business names and details were retrieved by the threat actor

Score
86
Read more

Save to Folder

Choose a folder to save this article:

Article Intelligence

Key entities and indicators for this article

VULNERABILITIES
Path Traversal
COMPANIES
Microsoft
ARTICLE INFORMATION
Article #9603
Published 4 hours ago
IT Pro Security

We use cookies

We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.

Cookie Settings

Essential Cookies

Required for the website to function. Cannot be disabled.

  • Session management and authentication
  • Security and fraud prevention
  • Cookie consent preferences

Analytics Cookies

Help us understand how visitors interact with our website.

  • Plausible Analytics - Privacy-focused usage statistics
  • PostHog - Product analytics and feature tracking
  • Page views and user journey analysis

Performance Cookies

Help us monitor and improve website performance.

  • Page load time monitoring
  • Error tracking and debugging
  • Performance optimisation

Marketing Cookies

Used to track visitors across websites for marketing purposes.

  • Conversion tracking
  • Remarketing campaigns
  • Social media integration