Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Microsoft Adds Prompt Injection Protection to Defender for Office 365

Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats. As organizations increasingly adopt AI assistants like Microsoft 365 Copilot to summarize, triage, and respond to…

New TrickBot Malware Variant Uses DNS Tunneling for Command-and-Control

A new TrickBot malware variant that significantly evolves its command-and-control (C2) communication by leveraging DNS tunneling, replacing the traditional HTTP-based mechanisms observed in earlier campaigns. The discovery highlights a continued shift among financially motivated threat actors toward stealthier communication channels…

Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases

Meta has addressed a critical vulnerability involving broken access control that exposed sensitive customer support data across multiple services. This issue highlighted systemic weaknesses in authorization within their shared backend infrastructure. The flaw, categorized as an Insecure Direct Object Reference…