Microsoft ends desktop detour for sensitivity labels in Office web apps

2026-04-15T02:51:47Z6235306f1ee0782859ffb720b18b64c977305709676e785e3e6ba28aa4f4bb52
CPS securityFBI takedownVeraW3LLai securityanthropicbasic-fitbooking.comclarotyclaude mythosdata breachdatavisordavmailencrypted client hellofraud preventionmicrosoft officeoffice web appsoligoopenssl 4.0phishingpost-quantumregex vulnerabilityruntime exploit blockingsensitivity labelsxDome

What happened

A collection of security news: Microsoft added user-defined sensitivity label permissions to Office for the web, aligning browser apps with desktop capabilities; OpenSSL 4.0.0 was released removing legacy protocol support and adding Encrypted Client Hello and post-quantum features (with breaking API changes); the UK AISI found Anthropic’s Claude Mythos has improved offensive capabilities but cannot reliably perform autonomous attacks on hardened networks; the FBI and Indonesian authorities dismantled the W3LL phishing kit sold for about $500; DavMail 6.6.0 fixes a regex-related security alert;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
6235306f1ee0782859ffb720b18b64c977305709676e785e3e6ba28aa4f4bb52
Enrichment time
2026-04-15T02:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.