Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A security researcher demonstrated how Microsoft Copilot for Word can be tricked into spreading a self-propagating prompt-injection 'AI worm' by hiding malicious instructions in white text on white background. The attack spreads through legitimate document-sharing workflows, and no complete mitigation exists for this class of LLM attacks.
A security researcher revealed a method to turn Microsoft Copilot for Word into a self-propagating "AI worm" through prompt injection. The attack involves embedding hidden JSON-formatted instructions as white text in a Word document.
CISA released a critical advisory on security principles and practices for open source software. The guidance addresses dependency management, vulnerability disclosure, and community security practices.
CISA released new guidance on open source software security principles and practices, covering risk management, trust assessment, vulnerability management, SBOMs, and secure development. The guidance helps agencies securely use, evaluate, and publish open source software.
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following versions of Johnson Controls OpenBlue Employee are affected: OpenBlue Employee (FMS Employee) <=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497) CVSS Vendor Equipment Vulnerabilities v3 2.4 Johnson Controls Inc.
CISA published an advisory on high-severity vulnerabilities in Schneider Electric IGSS SCADA/HMI software. Successful exploitation could lead to remote code execution on industrial control systems.