22 Sep, 2026

Microsoft fixes broken Excel copy and paste for all Office users

Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. The bug was confirmed following a wave of customer reports on Reddit and the Microsoft Q&A forums that this month’s updates (including the KB5002914 security update) break copy-and-paste, autofill, and formula dragging in Excel. “In […]

2 mins read

Microsoft reminds admins to migrate Entra ID users to passkeys

Microsoft has reminded administrators to migrate Entra ID users to phishing-resistant methods, such as passkeys, to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. Admins also have alternatives, including QR code authentication, FIDO2 security keys, and other Entra ID-supported authentication methods. Before this date, organizations should ensure all users use […]

2 mins read

Microsoft: September updates break File History backup feature

Microsoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the September 2026 security updates. File History (introduced in Windows 8 and replaced by Windows Backup, which backs up data to OneDrive) automatically saves copies that let users recover accidentally deleted or damaged files using an older version […]

2 mins read

Malicious npm packages evade install-script defenses at runtime

An ongoing npm malware campaign involving the ‘indexed-btree’ package shows how threat actors bypass supply chain defenses by hiding malicious code in a package’s normal runtime behavior rather than in installation scripts. The package, spotted by Checkmarx researchers, attempts to impersonate the legitimate ‘sorted-btree’ library and has already amassed 2 million weekly downloads. The campaign may […]

3 mins read

Researchers escape OpenAI Codex sandbox to run commands on host

Security researchers found two ways out of the OpenAI Codex sandbox, one of them capable of running commands on a developer’s machine from Codex’s most locked-down mode, with no approval prompt and nothing shown on screen. Both flaws were reported to OpenAI on August 12 and fixed within eight days, according to Oren Yomtov of […]

5 mins read

BragJack attacks hijack AI browser agents through malicious extensions

Security researcher Gal Weizman of Forever Security has disclosed a new attack technique that can hijack the AI assistants built into popular browsers using a single malicious browser extension. Dubbed BragJack, the proof-of-concept was demonstrated against five Chromium-based browsers or browser assistants: Google Chrome’s Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic’s Claude […]

5 mins read

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. The figures came from a joint advisory by Japanese, US, Australian, and German authorities that collectively traced the […]

3 mins read

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload […]

5 mins read

Viral AI actress’ hotline face-scans every caller, watches their mood

Last night, in a clip viewed more than eight million times, AI actress Tilly Norwood glitched mid-interview and unexpectedly began speaking Chinese on the Piers Morgan Uncensored show. Norwood has been the subject of much controversy and mainstream commentary for starring in an upcoming AI-generated film, Misaligned. Her creators run a “Talking Tilly” service that lets anyone video-call […]

5 mins read

Gyazo server flaw exploited to steal 23.6 million user records

The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. Gyazo is a cloud-based screenshot and screen-recording tool operated by Helpfeel that automatically uploads user screen captures to the cloud and gives them a shareable link to share on chats, […]

3 mins read