Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The U.S. Federal Trade Commission (FTC), alongside Utah and California, has filed a lawsuit against telehealth provider Hims & Hers, alleging the company shared consumers’ sensitive health data with third-party advertising platforms like Meta and Snap despite promising robust privacy protections. Hims & Hers, a digital health platform offering online consultations, prescription medications, and personal care products, is also accused of deceptive billing practices, including charging users before consultations and making subscription cancellations unnecessarily difficult.
The FTC, along with Utah and California, sued Hims & Hers for allegedly sharing sensitive health data with ad platforms and using deceptive billing and subscription practices that made cancellation difficult. The lawsuit highlights privacy and security concerns in telehealth.
A critical vulnerability in Microsoft's Azure Cosmos DB, dubbed CosmosEscape by researchers at Wiz, could have allowed attackers to gain full read and write access to any customer database. The flaw, discovered in November 2025 and patched by July 2026, stemmed from a sandbox escape in the Gremlin query engine, enabling attackers to execute arbitrary code and retrieve a platform-wide master key.
A now-patched vulnerability in Azure Cosmos DB could have allowed an attacker to escape the service's Gremlin query sandbox and gain full read and write access to databases across customer tenants, according to Wiz. The exploit chain, dubbed CosmosEscape, began with a crafted Gremlin query against a database controlled by the attacker, then achieved code execution on a multi-tenant gateway that exposed a platform-wide signing secret.
A vulnerability in Azure Cosmos DB's Gremlin query sandbox could allow an attacker to obtain a platform-wide key and access any database across tenants. Microsoft patched the issue within 48 hours and completed the fix across all regions, with no evidence of customer impact.
A security researcher has demonstrated how Microsoft Copilot for Word can be tricked into spreading a self‑propagating.