buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
U.S. CISA adds #Microsoft #SharePoint and #Zimbra flaws to its Known Exploited Vulnerabilities catalog
https://securityaffairs.com/189628/security/u-s-cisa-adds-microsoft-sharepoint-and-zimbra-flaws-to-its-known-exploited-vulnerabilities-catalog.html
#securityaffairs #hacking
#CheckPoint Research has published its Untold Stories of 2025, a compilation covering multiple notable campaigns that occurred during 2025. These include exploitation of #Microsoft #SharePoint (“ToolShell”), and adversary-in-the-middle #phishing used to bypass MFA, as well as state-linked operations attributed to groups such as Camaro Dragon and COLDRIVER. The report also highlights evolving command-and-control techniques observed across Europe and Central Asia.
https://research.checkpoint.com/2026/2025-the-untold-stories-of-check-point-research/
I was surprised to learn that Microsoft 365 can recommend files to me from someone else in the organization, by default. This is part of their "Item Insight" feature [1]. The description of this service goes to great lengths to explain how it respects the document access rights and won't be leaking documents.
While that's all good in theory, in many instances people do not use Sharepoint permissions right, and everyone in the organization has access to the documents unintended. I can see how this could amplify impact of such misconfiguration, in specific making some too widely shared document visible to much wider audience.
Also, this all relies on the machine learning to do correct decision in the first place. I prefer to keep such control to myself and this I disabled this feature.
You can disable the "Item Insight" from https://myaccount.microsoft.com/settingsandprivacy/privacy
1) https://learn.microsoft.com/en-us/graph/item-insights-overview
🚨 CRITICAL: CVE-2025-59245 in Microsoft SharePoint Online allows remote privilege escalation via deserialization of untrusted data. No patch yet—restrict access & monitor activity! Full details: https://radar.offseq.com/threat/cve-2025-59245-cwe-502-deserialization-of-untruste-ba16b807 #OffSeq #SharePoint #CloudSecurity #Vuln