Connect with us

Hi, what are you looking for?

Top Stories

Microsoft Blocks Unauthorized Scripts in Entra ID, ASUS Patches Critical AiCloud Vulnerability

Microsoft will block unauthorized scripts in Entra ID by late 2026 to combat XSS attacks, enhancing security during user logins while ASUS patches critical AiCloud vulnerabilities.

Microsoft is set to enhance security for its Entra ID platform by blocking unauthorized script injections during user logins, with the update scheduled for late 2026. This initiative, part of the company’s Secure Future Initiative, will implement a stricter Content Security Policy for sign-ins at login.microsoftonline.com, permitting scripts solely from trusted Microsoft domains. The move aims to mitigate risks associated with cross-site scripting (XSS) attacks and prevent unauthorized code from executing during the authentication process. Importantly, this update will not affect external identity sign-ins. Microsoft has advised organizations to proactively test their sign-in flows and refrain from using browser extensions that inject scripts, recommending alternatives that do not alter the Entra login experience.

In parallel, a bipartisan legislative effort known as the AI Fraud Deterrence Act has been introduced by Representatives Ted Lieu (D-Calif.) and Neal Dunn (R-Md.). This bill seeks to impose harsher criminal penalties for fraudulent activities facilitated by artificial intelligence tools, such as convincing fake audio, video, or text communications. Under the proposed legislation, the fines for mail, wire, and bank fraud, as well as for money laundering, could reach between $1 million and $2 million. Moreover, utilizing AI in fraudulent impersonations of government officials may incur a maximum fine of $1 million and a prison sentence of up to three years. The lawmakers emphasized the need for stringent measures as AI technology increasingly aids scammers.

ASUS has responded to cybersecurity threats by rolling out firmware updates that address nine vulnerabilities within its AiCloud feature, which allows routers to function as personal cloud servers. Notably, one critical vulnerability, assigned a CVSS score of 9.2, pertains to an authentication bypass that can be triggered inadvertently through Samba functionality. This discovery raises concerns about the potential for unauthorized access to sensitive functions. The company’s advisory underscores the importance of updating affected devices to mitigate security risks.

In another notable development, OpenAI has severed ties with Mixpanel following a data breach that compromised the personal information of API users, affecting approximately 35,000 individuals. Mixpanel reported the breach to OpenAI on November 25, with the exposed data including names, email addresses, locations, system details, and account IDs. While regular ChatGPT users were not impacted, OpenAI has initiated a comprehensive security review of all its vendors and is actively notifying those affected. The company has stated that there is no evidence indicating that the breach extends beyond Mixpanel’s environment, reaffirming its commitment to transparency and robust security measures.

The cybersecurity landscape remains cautious as three London councils—Royal Borough of Kensington and Chelsea, Westminster City Council, and the Borough of Hammersmith and Fulham—have been affected by an incident involving their shared IT services. Although details are still emerging, the incident has prompted these authorities to take precautionary measures by shutting down certain IT systems. It is currently premature to attribute the incident to a specific threat actor or to confirm data compromise.

Dartmouth College has also experienced a significant data breach linked to a campaign involving Oracle E-Business Suite, impacting over 35,000 individuals across multiple states. The breach reportedly occurred between August 9 and August 12, with unauthorized access resulting in the theft of sensitive information, including Social Security numbers and financial account data. College officials have commenced an investigation to assess the full extent of the breach.

Meanwhile, Microsoft is investigating a service outage affecting its Exchange Online platform, which has been blocking user access to Outlook mailboxes. Reports indicate that the outage began on Tuesday and has primarily impacted users in the Asia Pacific and North America regions attempting to connect via the classic Outlook desktop client. Microsoft has yet to disclose the number of users affected, but the disruption has caused server connection and login issues for many.

Further complicating matters for Windows users, Microsoft has issued a warning regarding recent changes to FIDO2 security keys. Following updates released since the September 2025 preview update, users may now be prompted to enter a PIN when signing in. This adjustment is in accordance with WebAuthn specifications, which dictate the handling of user verification requests for various authentication methods. Users are advised that they might need to create a PIN, even if it was not previously required during their initial device registration.

As the cybersecurity landscape evolves, organizations are reminded of the importance of staying vigilant against emerging threats and ensuring robust security protocols are in place.

See also
Staff
Written By

The AiPressa Staff team brings you comprehensive coverage of the artificial intelligence industry, including breaking news, research developments, business trends, and policy updates. Our mission is to keep you informed about the rapidly evolving world of AI technology.

You May Also Like

AI Cybersecurity

Anthropic's Claude Mythos Preview can autonomously exploit software vulnerabilities, alarming leaders like U.S. Treasury Secretary Scott Bessent and raising cyber risk concerns.

AI Cybersecurity

New analysis warns that Anthropic's Mythos AI tool could empower cyberattacks on small businesses, making them vulnerable to exploitation by advanced AI threats.

AI Technology

Durabook unveils the R10 rugged tablet with Intel's Core Ultra 200V processor and AI capabilities, designed for 8.5 hours of reliable outdoor performance.

Top Stories

Microsoft acquires 30,000 Nvidia GPU slots in Norway and 3,200 acres in Wyoming, enhancing Azure's AI infrastructure amid rising demand.

AI Generative

Microsoft launches MAI-Image-2, ranking third on Arena.ai with advanced photorealism and text generation, but faces significant usage limitations.

Top Stories

Hyperscalers like Microsoft and Amazon are facing a $650B AI hardware spend dilemma as rapid obsolescence threatens profitability and market positions.

AI Education

Khan Academy, ETS, and TED launch the Khan TED Institute, aiming to redefine higher education with tuition under $10,000 and skills aligned with top...

AI Generative

Microsoft Research finds self-distillation reduces large language model accuracy by 40% on unseen tasks, raising concerns over adaptability in diverse contexts.

© 2025 AIPressa · Part of Buzzora Media · All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site. Some images used on this website are generated with artificial intelligence and are illustrative in nature. They may not accurately represent the products, people, or events described in the articles.