Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
2026-08-18T19:23:59Z•c294eff3e7702b002b408519c23a619837dc2d6d709e1eec4d71637566cee470
CVE-2026-15748CVE-2026-19478CVE-2026-58231CVE-2026-59310CVE-2026-65400active-exploitationai-securitybotnetbrowser-securityc2cloud-securitycredential-theftdata-exfiltrationgitlabidentity-and-access-managementindustrial-control-systemsmacosphishingprompt-injectionransomwareremote-code-executionrootkitsap-commerce-cloudsession-hijackingsupply-chain-securitytyposquattingvmware-vcenterwordpresszero-day
What happened
The feed reports widespread active exploitation and emerging threats, including critical vulnerabilities in GitLab, Forminator, VMware vCenter, SAP Commerce Cloud, Apple macOS Screen Sharing, Ray, MLflow, and FUXA. Other coverage includes AI-agent prompt propagation, cloud and SaaS credential theft, SharePoint/Teams-based implants, supply-chain typosquatting, ransomware-related fraud, botnets, rootkits, phishing, and session hijacking. Multiple issues involve unauthenticated remote code execution, credential or secret theft, destructive project modification, and exploitation in the wild.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- c294eff3e7702b002b408519c23a619837dc2d6d709e1eec4d71637566cee470
- Enrichment time
- 2026-08-18T19:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.