{"data":[{"id":"aeb9ede6-f72e-4564-b5ca-e6ee74371831","title":"Microsoft is giving Copilot more control over Windows and your files","headline":null,"summary":"At a Windows and Surface event, Microsoft showed an upgraded Copilot that can access local files on a PC and take actions across the operating system. The feature is part of what Microsoft calls \"Hybrid Intelligence,\" in which apps rely on a mix of local and cloud AI models. A stage demo had Jacob Andreou, Microsoft's EVP of Copilot, asking the Autopilot tool to help file taxes.","sourceUrl":"https://www.theverge.com/tech/1007113/microsoft-windows-copilot-ai-control-search-hybrid-intelligence","publishedAt":"2026-10-07T18:01:20.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["industry","privacy"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Microsoft Copilot","Windows","Autopilot"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-07T18:01:20.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"a0284e6f-a81b-4c76-b496-a8f73a283e97","title":"Encrypted instructions trick Copilot CLI into spilling developer secrets","headline":null,"summary":"Adversa AI researchers described Cryptographic Context Injection (CCI), a technique that hides malicious instructions inside encrypted content so GitHub Copilot CLI treats them as trusted context. In a demonstration, Copilot read a \".env.prod\" file and sent its contents to an attacker-controlled endpoint in 28 seconds without confirmation. The attack requires autopilot mode and a model willing to execute the decrypted instructions, and GitHub declined to treat it as a vulnerability.","sourceUrl":"https://www.csoonline.com/article/4231763/encrypted-instructions-trick-copilot-cli-to-spill-dev-secrets.html","publishedAt":"2026-10-07T11:47:48.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security","safety"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["GitHub Copilot CLI","Copilot","mai-code-1.1-flash","GPT-5.6"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source. GitHub said it may make the functionality stricter in the future but had nothing to announce. Adversa advises defenders to look for suspicious sequences of actions around an encrypted payload: untrusted web content entering the agent, code executing, local files being read, and an unrelated outbound connection following.","attackType":["prompt_injection","data_extraction"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-07T11:47:48.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"870e5777-95bb-416e-8630-2cc83619a9b5","title":"GitHub Copilot CLI vulnerability: Cryptographic Context Injection steals developer secrets","headline":null,"summary":"GitHub Copilot CLI can be made to read a developer's local files and send them to an attacker from a single web page. The attack, Cryptographic Context Injection (CCI), hides instructions as ciphertext that the agent decrypts in its own shell and trusts as its own, and the researchers say one attacker-controlled URL fetched in autopilot mode was enough to exfiltrate a .env.prod file in 28 seconds.","sourceUrl":"https://adversa.ai/blog/cryptographic-context-injection-github-copilot/","publishedAt":"2026-10-06T12:50:00.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["GitHub Copilot CLI","GitHub Copilot","Cryptographic Context Injection"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["prompt_injection","data_extraction"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-10-06T12:50:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"fb1325a6-b0a8-48a9-bd5c-de2a78c9e9a3","title":"From SELECT to SYSADMIN with SQL Copilot (CVE-2026-65669)","headline":null,"summary":"A researcher presented at BlueHat Asia 2026 in Singapore on Microsoft's Copilot in SQL Server Management Studio (SSMS). The talk covered CVE-2026-65669, a SQL Server Elevation of Privilege Vulnerability that Microsoft rated critical.","sourceUrl":"https://embracethered.com/blog/posts/2026/from-select-to-sysadmin-sql-copilot-bluehat-asia/","publishedAt":"2026-09-30T21:00:40.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Microsoft Copilot in SSMS","SQL Server Management Studio"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"So, make sure your installations are up-to-date.","attackType":["other"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-30T21:00:40.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"plugin","llmSpecific":true,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null},{"id":"c883f948-a2f3-4896-a3a7-4fbaa8c9167a","title":"Microsoft thinks its new Copilot ‘super app’ will be as influential as Office","headline":null,"summary":"Microsoft is officially unveiling a redesigned Copilot app that bundles chat, coding, and agent capabilities into a single interface. The app has three tabs, Home, Code, and Autopilot, with Home combining Copilot Chat and Cowork. Microsoft is also renaming Scout, the AI personal assistant it unveiled at Build, as Autopilot.","sourceUrl":"https://www.theverge.com/news/1000532/microsoft-copilot-super-app-chat-coding-autopilot","publishedAt":"2026-09-25T12:00:00.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Microsoft Copilot","Copilot Chat","Cowork","Scout","Autopilot"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-25T12:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":null,"llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null},{"id":"97c2e41b-66b2-4241-8dc7-98b6456af9f9","title":"​​​​​​​​What’s new in Microsoft Security: September 2026​​","headline":null,"summary":"Microsoft's September 2026 security update, published as a news item, describes new features across Microsoft Defender, Microsoft Security Copilot, Microsoft Purview and Microsoft Entra. Updates include AI-generated email detonation summaries, network-layer blocking of sensitive data sent to unsanctioned AI tools, expanded auto-labeling for large environments, and eDiscovery and archiving changes for Copilot-created content.","sourceUrl":"https://www.microsoft.com/en-us/security/blog/2026/09/24/whats-new-in-microsoft-security-september-2026/","publishedAt":"2026-09-24T16:00:00.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Microsoft Defender","Microsoft Security Copilot","Microsoft Purview","Microsoft Entra Global Secure Access","Microsoft 365 Copilot","Microsoft Loop","Copilot Pages","Copilot Notebooks"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-24T16:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null},{"id":"880833ce-47b1-450f-add1-7554f43c65f1","title":"Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk","headline":null,"summary":"Z.ai disabled several features of its ZCode coding assistant after a default setting was found sending users' local code repositories to Alibaba Cloud servers in China without consent. An independent blogger, Ferstar, reported that the client packaged full workspaces, including .git history and global app configs, and uploaded them to Aliyun OSS. The company removed the feature from its latest release and said it had deleted the associated cloud storage.","sourceUrl":"https://www.csoonline.com/article/4225037/z-ai-disables-coding-assistant-feature-after-flaw-exposed-enterprise-code-upload-risk-2.html","publishedAt":"2026-09-22T14:56:08.000Z","severity":"medium","cvssSeverity":null,"cvssScore":null,"labels":["security","privacy"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Z.ai","ZCode","Alibaba Cloud"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Z.ai disabled the repository upload mechanism, deleted the associated cloud storage infrastructure, and implemented changes in the ZCode v3.14.0 client. It also removed the Repo Wiki entry point and the associated generation workflow, and asked CAICT and NSFOCUS to conduct security assessments.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-22T14:56:08.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"9cbf40c3-8110-4b62-9891-43006fe24914","title":"CVE-2026-85887: Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose…","headline":"M365 Copilot incorrect permission assignment allows information disclosure","summary":"CVE-2026-85887 is an incorrect permission assignment for a critical resource in M365 Copilot. An authorized attacker can exploit it over a network to disclose information.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85887","publishedAt":"2026-09-18T00:17:47.920Z","severity":"high","cvssSeverity":"high","cvssScore":"7.7","labels":["security","privacy"],"issueType":"vulnerability","cveId":"CVE-2026-85887","cweIds":["CWE-732"],"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["M365 Copilot"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["data_extraction"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.0084,"epssCheckedAt":"2026-10-10T06:42:02.840Z","kevDateAdded":null,"advisoryAliases":["GHSA-g3r4-5f4w-4vh4"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-18T00:17:47.920Z","capecIds":["CAPEC-1"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"e6c22579-cb4d-4737-b696-50a29f425123","title":"CVE-2026-85885: Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an…","headline":"M365 Copilot command injection allows privilege elevation over a network","summary":"CVE-2026-85885 is an improper neutralization of special elements used in a command ('command injection') flaw in M365 Copilot. An authorized attacker can exploit it over a network to elevate privileges.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85885","publishedAt":"2026-09-17T23:18:53.080Z","severity":"critical","cvssSeverity":"critical","cvssScore":"9.9","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-85885","cweIds":["CWE-77"],"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["M365 Copilot"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.0072,"epssCheckedAt":"2026-10-10T02:58:12.571Z","kevDateAdded":null,"advisoryAliases":["GHSA-jjmx-rwxc-vwh4"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-17T23:18:53.080Z","capecIds":["CAPEC-88"],"crossRefCount":1,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"plugin","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"d773e2c3-310a-4ca2-be55-5f2fbee69b2f","title":"CVE-2026-78501: Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business…","headline":null,"summary":"CVE-2026-78501 is an improper neutralization of special elements used in a command ('command injection') flaw in Microsoft 365 Copilot's Business Chat. An unauthorized attacker can exploit it over a network to disclose information.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78501","publishedAt":"2026-09-17T23:18:45.770Z","severity":"high","cvssSeverity":"high","cvssScore":"7.4","labels":["security","privacy"],"issueType":"vulnerability","cveId":"CVE-2026-78501","cweIds":["CWE-77","CWE-923"],"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Microsoft 365 Copilot","Business Chat"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00477,"epssCheckedAt":"2026-10-10T02:57:39.298Z","kevDateAdded":null,"advisoryAliases":["GHSA-hjj2-64g6-jw5p"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-17T23:18:45.770Z","capecIds":["CAPEC-88"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0051"]},{"id":"c9cf2dd6-a9a2-4a04-a02a-d1d8077d23db","title":"CVE-2026-55946: Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an…","headline":"Microsoft Copilot command injection allows unauthorized information disclosure","summary":"CVE-2026-55946 is an improper neutralization of special elements used in a command ('command injection') flaw in Microsoft Copilot. An unauthorized attacker can exploit it over a network to disclose information.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55946","publishedAt":"2026-09-17T23:17:46.687Z","severity":"medium","cvssSeverity":"medium","cvssScore":"6.1","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-55946","cweIds":["CWE-77"],"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Microsoft Copilot"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.0039,"epssCheckedAt":"2026-10-10T02:57:07.563Z","kevDateAdded":null,"advisoryAliases":["GHSA-rq75-5hf2-vppm"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-17T23:17:46.687Z","capecIds":["CAPEC-88"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"238f9e41-5ae0-4c20-bcfe-7d85a5dd244a","title":"Microsoft says Copilot buttons still missing in classic Outlook","headline":null,"summary":"Microsoft is still investigating a known issue that makes the Copilot and Copilot Chat buttons disappear in classic Outlook for some Windows users with a Copilot Chat (Basic) license or a paid M365 Copilot (Premium) account. Microsoft says the problem occurs after upgrading classic Outlook for Windows to build 20026.20182 and higher, because Outlook cannot locate the MAPI property PR_PROFILE_USER_SMTP_EMAIL_ADDRESS_W within the null profile section. Copilot remains available through Outlook on the web and the Microsoft 365 Copilot standalone app or web experience.","sourceUrl":"https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-workaround-for-missing-outlook-copilot-buttons/","publishedAt":"2026-09-16T12:16:32.000Z","severity":"low","cvssSeverity":null,"cvssScore":null,"labels":["industry","security"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Microsoft Copilot","Copilot Chat","Microsoft 365 Copilot","Outlook"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Temporary workaround: in classic Outlook, select File, then Options, go to Advanced, and check \"Show Apps in Outlook\" under \"Outlook panes.\" Affected users can also create a new Outlook profile or use the new Outlook email client or Outlook Web Access (OWA), which Microsoft says are not affected.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-16T12:16:32.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["availability"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null},{"id":"2673d9a6-0e85-4765-b32c-1e42e392aaf7","title":"Update your firewall rules: Teams and Copilot are changing address","headline":null,"summary":"Microsoft is changing the destination addresses of M365 and Teams web users to copilot.cloud.microsoft and teams.cloud.microsoft, announced in MessageCenter posts MC1465764 and MC1462915. Redirects should be completed by early October, and limited Teams exceptions are possible until Dec. 31, 2026.","sourceUrl":"https://www.csoonline.com/article/4221275/update-your-firewall-rules-teams-and-copilot-are-changing-address.html","publishedAt":"2026-09-11T17:00:20.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Microsoft 365 Copilot","Microsoft Teams","M365"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Microsoft advises customers to review configurations on client devices, proxies, firewalls, secure web gateways, or other enterprise network controls to confirm users can connect to the new addresses. Companies blocking the new Copilot address to keep employees off personal Microsoft accounts can use Microsoft's TenantRestrictions control instead. Companies that cannot meet the deadline should contact their account representative.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-11T17:00:20.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null},{"id":"6ac0430b-28a5-4203-a665-1725fe98def2","title":"CVE-2026-81381: Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to…","headline":"GitHub Copilot and Visual Studio Code credential exposure over network","summary":"CVE-2026-81381 describes insufficiently protected credentials in GitHub Copilot and Visual Studio Code. An unauthorized attacker can exploit this over a network to disclose information.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81381","publishedAt":"2026-09-08T18:20:54.470Z","severity":"medium","cvssSeverity":"medium","cvssScore":"6.5","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-81381","cweIds":["CWE-522"],"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["GitHub Copilot","Visual Studio Code"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00874,"epssCheckedAt":"2026-10-10T06:41:59.205Z","kevDateAdded":null,"advisoryAliases":["GHSA-8qwj-prhm-6mp3"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-08T18:20:54.470Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"ad2d3a09-6fe2-4cf6-970e-51add964e1a6","title":"CVE-2026-81380: Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio…","headline":null,"summary":"CVE-2026-81380 is a command injection flaw (CWE-77 style wording: improper neutralization of special elements used in a command) affecting GitHub Copilot and Visual Studio Code. An unauthorized attacker can exploit it over a network to disclose information.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81380","publishedAt":"2026-09-08T18:20:54.330Z","severity":"medium","cvssSeverity":"medium","cvssScore":"5.3","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-81380","cweIds":["CWE-77"],"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["GitHub Copilot","Visual Studio Code"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00619,"epssCheckedAt":"2026-10-10T02:56:03.326Z","kevDateAdded":null,"advisoryAliases":["GHSA-r64m-65x5-h3wx"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-08T18:20:54.330Z","capecIds":["CAPEC-88"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"093f7932-33dc-4928-840c-1c3c8ee0c9a4","title":"Microsoft says virtually nobody was grabbing NYT articles through its chatbot","headline":null,"summary":"Microsoft says in new legal filings that its Copilot rarely reproduces even full sentences from news articles and books, let alone substantive chunks that could substitute for the originals. The company is contesting copyright claims from publishers including The New York Times and book authors, and it provided 8.2 million Copilot chat logs to an expert hired by the news publishers during discovery.","sourceUrl":"https://www.theverge.com/policy/990267/microsoft-openai-new-york-times-authors-lawsuit","publishedAt":"2026-09-04T16:05:57.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["policy","industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Microsoft","OpenAI"],"affectedVendorsRaw":["Microsoft Copilot"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-04T16:05:57.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":null,"llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"1476520d-0c49-41e8-814d-77ebffbdddbe","title":"CVE-2026-80098: Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate…","headline":"Copilot Studio improper signature verification allows privilege elevation","summary":"CVE-2026-80098 is an improper verification of cryptographic signature flaw in Copilot Studio. An unauthorized attacker can exploit it over a network to elevate privileges.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80098","publishedAt":"2026-09-03T23:17:20.350Z","severity":"critical","cvssSeverity":"critical","cvssScore":"9.3","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-80098","cweIds":["CWE-347"],"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Copilot Studio"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00488,"epssCheckedAt":"2026-10-10T03:00:37.498Z","kevDateAdded":null,"advisoryAliases":["GHSA-r9hf-26xj-x88v"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-09-03T23:17:20.350Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"595cfa72-246a-4a15-95b3-3581ecedfc31","title":"CVE-2026-58616: Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft…","headline":"Copilot Chat (Microsoft Edge) race condition allows info disclosure","summary":"CVE-2026-58616 is a race condition (CWE-362, improper synchronization of a shared resource) in Copilot Chat in Microsoft Edge. An authorized attacker can exploit it over a network to disclose information.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-58616","publishedAt":"2026-08-28T20:18:44.927Z","severity":"medium","cvssSeverity":"medium","cvssScore":"4.4","labels":["security","privacy"],"issueType":"vulnerability","cveId":"CVE-2026-58616","cweIds":["CWE-362"],"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Copilot Chat","Microsoft Edge"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"low","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00295,"epssCheckedAt":"2026-10-10T06:41:57.681Z","kevDateAdded":null,"advisoryAliases":["GHSA-c7hh-86mm-w7m5"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-08-28T20:18:44.927Z","capecIds":["CAPEC-26","CAPEC-29"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null},{"id":"dc0ac6b5-87a0-477d-a026-1a505cffb14e","title":"CVE-2026-69855: Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information…","headline":"Microsoft Copilot in Azure SSRF allows information disclosure","summary":"CVE-2026-69855 is a server-side request forgery (SSRF) flaw in Microsoft Copilot in Azure, classified as CWE-918. An authorized attacker can exploit it over a network to disclose information. The source gives no CVSS score, as NVD has not yet provided an assessment.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-69855","publishedAt":"2026-08-20T22:18:01.003Z","severity":"high","cvssSeverity":"high","cvssScore":"7.7","labels":["security"],"issueType":"vulnerability","cveId":"CVE-2026-69855","cweIds":["CWE-918"],"affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Microsoft Copilot in Azure"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["other"],"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.0084,"epssCheckedAt":"2026-10-10T02:57:56.487Z","kevDateAdded":null,"advisoryAliases":["GHSA-6g7w-gggp-m44g"],"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-08-20T22:18:01.003Z","capecIds":["CAPEC-664"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"2340a524-ae8e-471c-88b1-fc72db383e06","title":"Slack is launching collaborative vibe coding channels","headline":null,"summary":"Slack is introducing dedicated Slack Code channels where teams can vibe code together with AI agents rather than switching between tools. The launch includes open, project-specific code channels with dedicated user tabs, plus features to compare code changes and preview HTML output before shipping.","sourceUrl":"https://www.theverge.com/tech/982628/slack-code-vibe-coding-channels-launch","publishedAt":"2026-08-20T12:00:00.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Anthropic"],"affectedVendorsRaw":["Slack Code","Claude","Devin","Cognition"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-08-20T12:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":null,"llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}],"meta":{"total":160,"limit":20,"offset":0}}