
Atlassian Rovo One-Click Flaw Exposes Jira, Confluence Data
Varonis and PromptArmor disclosed prompt-injection flaws in Atlassian Rovo that can exfiltrate Jira, Confluence, and SharePoint data from enterprise tenants.

Varonis and PromptArmor disclosed prompt-injection flaws in Atlassian Rovo that can exfiltrate Jira, Confluence, and SharePoint data from enterprise tenants.

PortSwigger researcher Gareth Heyes showed email-borne CSS attacks that capture passwords and steal tokens in Outlook, Gmail, Yahoo, and other

Head Mare hacktivists exploited TrueConf servers and replaced client installers with backdoored versions carrying PhantomCore and PhantomGraph backdoors.

Researcher James Arnott disclosed severe flaws in the Connective eID extension exposing PINs, enabling forged signatures, and allowing drive-by code

Yeeth Security flagged malicious Solidity Pro VS Code extensions that steal crypto wallets, API keys, and developer credentials, exfiltrating them

OpenAI paused internal work on its Astra model after an evaluation found cyber capabilities that may reach a Critical rating

Arctic Wolf documented an AitM phishing campaign hijacking Microsoft 365 accounts to collect payroll and finance emails across North America

BIT’s SharePoint intrusion compromised credentials for about 200 Swiss federal accounts, likely via Microsoft flaws fixed in the July Patch

Google Threat Intelligence ties hedge fund vishing attacks to UNC6671 (BlackFile), an extortion group rebranding across Redact, Pink, Helix, and

Unlimited Technology Systems disclosed an October 2025 data theft affecting 3.8 million people, exposing Social Security numbers, diagnoses, and ID
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.