Microsoft now lets admins uninstall Copilot on enterprise devices

2026-04-24T13:23:33Zbf521ffb5b9e8530759d2a986c52e31d024a9ae5395a5c7452b38f2a8677a64d
CVE-2025-29635aptbitwardenbluehammerbotnetbreeze-cachecheckmarxcisad-linkdata-breachfile-uploadgopherwhisperiotkicskybermicrosoft-defendermirainpmpost-quantumproxy-networksransomwaresupply-chaintrigonawordpresszero-day

What happened

This feed reports multiple high-impact security events: active exploitation of a critical Breeze Cache WordPress file-upload flaw; a malicious @bitwarden/cli npm package that stole developer credentials; a Checkmarx KICS supply-chain compromise (malicious Docker images and extensions); Trigona and Kyber ransomware activity (Kyber experimenting with post‑quantum Kyber1024); and a Mirai campaign exploiting CVE-2025-29635 in EoL D‑Link DIR‑823X routers. CISA ordered federal patching for a Microsoft Defender privilege‑escalation zero‑day dubbed “BlueHammer,” and a new GopherWhisper state‑linked A

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
bf521ffb5b9e8530759d2a986c52e31d024a9ae5395a5c7452b38f2a8677a64d
Enrichment time
2026-04-24T13:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft now lets admins uninstall Copilot on enterprise devices · Baitaphish