Tag: office
-
Microsoft fixes broken Excel copy and paste for all Office users
Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-broken-excel-copy-and-paste-for-all-office-users/
-
Home Office challenged on ‘farcical’ secrecy over Apple ‘backdoor’ order
UK government argues that national security would be damaged if it departs from ‘neither confirm nor deny policy’ on Apple ‘backdoor’ notice First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650612/Home-Office-challenged-on-farcical-secrecy-over-Apple-backdoor-order
-
FBI Seizes NightmareStresser DDoSHire Domains Used in Hundreds of Thousands of Attacks
The FBI has seized internet domains linked to NightmareStresser, a long-standing distributed denial-of-service (DDoS)-for-hire platform allegedly used to launch hundreds of thousands of attacks or attempted attacks worldwide since 2022. The U.S. Attorney’s Office for the District of Alaska announced the action, which targets the infrastructure that allowed paying customers to overwhelm victims’ networks and…
-
New York Seizes a Dozen Celebrity Deepfake Websites
In the biggest-ever legal action against harmful deepfake websites, the Manhattan District Attorney’s Office has seized 12 sites that collectively targeted around 1,200 victims. First seen on wired.com Jump to article: www.wired.com/story/new-york-seizes-a-dozen-celebrity-deepfake-websites/
-
Cybersecurity Leaders to Watch in London: Securing Britain’s Business Capital
London hosts the head offices of insurers, payment providers, publishers, industrial groups, and consumer brands, each operating under a regulatory environment shaped by GDPR, NIS2, FCA supervision, and the UK’s evolving cyber resilience legislation. The security leaders below have built… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cybersecurity-leaders-to-watch-in-london-securing-britains-business-capital/
-
Microsoft Excel KB5002914 update breaks copy and paste for some users
Microsoft Excel users report that this week’s KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-excel-kb5002914-update-breaks-copy-and-paste-for-some-users/
-
Nutzerbeschwerden: Kopierfunktion in Excel nach Office-Update kaputt
Im Netz häufen sich Beschwerden von Nutzern, die in Excel nicht mehr kopieren können. Ursache scheint ein Bug im neuen Microsoft-Office-Update zu sein. First seen on golem.de Jump to article: www.golem.de/news/nutzerbeschwerden-kopierfunktion-in-excel-nach-office-update-kaputt-2609-212865.html
-
Microsoft Fixes 974 CVEs in Record Patch Tuesday Release
Microsoft fixed a record 974 CVEs for September’s Patch Tuesday, including two actively exploited Windows flaws. Most of the vulnerabilities addressed in the September release affect Windows, but the update also covers Office, SQL Server, Exchange Server, SharePoint Server, Azure and developer tools. Microsoft urged customers to apply the updates quickly and specifically called out..…
-
San Francisco Orders Meta to Stop ‘Allowing’ AI Child Abuse Ads
The City Attorney’s Office has asked Meta to explain how the harmful ads repeatedly ran on Facebook and Instagram. The company claims the ads are not under the city’s jurisdiction. First seen on wired.com Jump to article: www.wired.com/story/san-francisco-orders-meta-to-stop-allowing-ai-child-abuse-ads/
-
Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365
Switzerland’s Federal Chancellery is advancing a sovereign digital workplace initiative following a feasibility study that demonstrated how open-source collaboration and office software can effectively support essential workflows within the federal administration. This initiative, announced to the Federal Council on September 2, aims to establish an open-source workplace platform that will operate alongside Microsoft 365 without…
-
Microsoft Finds ASCII Smuggling Repurposed for Phishing Campaign
Attackers have adapted a technique popularized in AI prompt injection research for a high-volume phishing campaign, using invisible Unicode characters to evade email filtering, Microsoft researchers reported Thursday. The finding came from Microsoft Defender for Office 365 prompt injection protection research. A hunting signature built to detect ASCII smuggling in email recorded a surge beginning..…
-
Kentucky Appellate Court Data Caught in Multi-State Cyber Data Breach
The Kentucky Administrative Office of the Courts (AOC) has confirmed that Kentucky Appellate Court data was compromised in a cybersecurity breach traced to a third-party vendor. West Publishing Corporation, operating as Thomson Reuters Court Management Solutions (Thomson Reuters CMS), informed the AOC that the incident originated within file systems tied to its C-Track case management…
-
CrowdStrike Falcon Zero-Day Lets Attackers Escalate Privileges on Windows Systems
A recently released proof-of-concept, named FalconFlank, claims to reveal a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor on Windows. CrowdStrike is actively investigating these claims and has advised customers to turn off the Microsoft Office File Suspicious Macro Removal policy while the assessment is ongoing. CrowdStrike Falcon Zero-Day The project was published on…
-
Breach Roundup: FBI Probes Sale of 153 Million Driver’s Licenses
Also, Dropbox Accounts Breached, BGP Hijack Compromises Virtualizor Servers. This week: a massive breach of U.S. driver’s licenses, Dropbox accounts breached, a BGP hijack, Artifactory flaw, Russian national indicted, Aesto health breach, a new U.S. Coast Guard cybersecurity policy office, Morocco denied a security breach and a Brazilian illicit marketplace. First seen on govinfosecurity.com Jump…
-
Breach Roundup: FBI Probes Sale of 153 Million Driver’s Licenses
Also, Dropbox Accounts Breached, BGP Hijack Compromises Virtualizor Servers. This week: a massive breach of U.S. driver’s licenses, Dropbox accounts breached, a BGP hijack, Artifactory flaw, Russian national indicted, Aesto health breach, a new U.S. Coast Guard cybersecurity policy office, Morocco denied a security breach and a Brazilian illicit marketplace. First seen on govinfosecurity.com Jump…
-
Breach Roundup: FBI Probes Sale of 153 Million Driver’s Licenses
Also, Dropbox Accounts Breached, BGP Hijack Compromises Virtualizor Servers. This week: a massive breach of U.S. driver’s licenses, Dropbox accounts breached, a BGP hijack, Artifactory flaw, Russian national indicted, Aesto health breach, a new U.S. Coast Guard cybersecurity policy office, Morocco denied a security breach and a Brazilian illicit marketplace. First seen on govinfosecurity.com Jump…
-
Breach Roundup: FBI Probes Sale of 153 Million Driver’s Licenses
Also, Dropbox Accounts Breached, BGP Hijack Compromises Virtualizor Servers. This week: a massive breach of U.S. driver’s licenses, Dropbox accounts breached, a BGP hijack, Artifactory flaw, Russian national indicted, Aesto health breach, a new U.S. Coast Guard cybersecurity policy office, Morocco denied a security breach and a Brazilian illicit marketplace. First seen on govinfosecurity.com Jump…
-
Microsoft-365-Security-Assessment Warum ein Audit mehr als den Secure-Score prüfen muss
In vielen Unternehmen ist Microsoft-365 längst keine Office-Suite mehr, sondern die zentrale Plattform für Identitäten, E-Mail, Zusammenarbeit, Geräteverwaltung und geschäftskritische Daten. Diese Konzentration macht den Arbeitsalltag effizient. Sie sorgt aber auch dafür, dass eine einzelne Fehlkonfiguration weitreichende Folgen haben kann: Ein zu großzügiger Gastzugriff, eine dauerhaft privilegierte Rolle oder eine unkontrollierte Anwendung reicht unter Umständen…
-
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon.”FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor,” the researcher said in a GitHub README file, adding First seen on…
-
New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password
A newly identified phishing-as-a-service kit is being used to hijack Microsoft 365 accounts by stealing victims’ active login sessions rather than their passwords, according to new research from cybersecurity firm Huntress, a technique that allows attackers to walk straight past multi-factor authentication (MFA) without ever needing to guess, crack, or bypass it. The kit, dubbed “Knight…
-
Hackers Abuse Legitimate IT Management Tool to Sneak Into Business Networks
Cybersecurity researchers at Huntress have uncovered a phishing campaign that abuses Faronics Deploy, a legitimate endpoint management platform used by businesses, schools, and government offices to remotely install software and run scripts across their networks. According to the security firm, threat actors sent victims phishing emails disguised as invoices, tax documents, financial records, and event…
-
Hackers Abuse Legitimate IT Management Tool to Sneak Into Business Networks
Cybersecurity researchers at Huntress have uncovered a phishing campaign that abuses Faronics Deploy, a legitimate endpoint management platform used by businesses, schools, and government offices to remotely install software and run scripts across their networks. According to the security firm, threat actors sent victims phishing emails disguised as invoices, tax documents, financial records, and event…
-
Microsoft Defender flags legitimate Google search links as malicious
Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-defender-flags-legitimate-google-search-links-as-malicious/
-
Microsoft Defender flags legitimate Google search links as malicious
Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-defender-flags-legitimate-google-search-links-as-malicious/
-
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, the U.S. Attorney’s…
-
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
Tags: authentication, cisa, cve, cybersecurity, exploit, flaw, healthcare, infrastructure, kev, office, remote-code-execution, software, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)addedthe following vulnerabilities to itsKnown Exploited Vulnerabilities (KEV) catalog: PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578,…
-
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
The six-month program will be overseen by the Office of the National Cyber Director and Texas Cyber Command to “find out what works.” First seen on cyberscoop.com Jump to article: cyberscoop.com/watershed-250-texas-water-cybersecurity-pilot/
-
AI Doesn’t Mean the End of Mathematics”, at Least Not Yet
This essay was written with Kasra Rafi, and originally appeared in The Guardian. Earlier this month, about 40 top mathematicians gathered at OpenAI’s offices to discuss the future of their profession. The meeting was off-the-record, but if recent articles by mathematicians are any guide, it was mostly pretty glum. People fear for their jobs, their…
-
US Lawmakers Urge Probe of Trump Cyber Workforce Cuts
House Lawmakers Ask Watchdog to Assess Staffing Losses at US Cyber Agency. House Democrats are asking the Government Accountability Office to examine how staffing reductions and cuts at the Cybersecurity and Infrastructure Security Agency have affected the agency’s ability to defend federal networks and critical infrastructure. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/us-lawmakers-urge-probe-trump-cyber-workforce-cuts-a-32653
-
Enterprise Network Security Solution
A traditional corporate network may once have consisted primarily of office computers, servers, switches, routers, and a centralized data center. Today, organizations operate across cloud platforms, remote offices, SaaS applications, mobile devices, IoT systems, endpoints, APIs, data centers, and operational technology environments. Employees can access business resources from almost anywhere. Applications may be distributed across…

