p2p (2)

31181446893?profile=RESIZE_400xA novel Microsoft Copilot attack that researchers named "SearchLeak" would have enabled an attacker to silently exfiltrate user files, including emails, meeting notes, OneDrive files, SharePoint documents, and other business files the user has access to.  Recently, Varonis Threat Labs detailed the three-stage vulnerability, which works as a relatively unknown subset of indirect prompt-injection attacks called parameter-to-prompt injection (P2P), which needs to be on defender radar screens.[1]

Ho

31166451096?profile=RESIZE_400xFortiGuard Labs recently identified persistent P2Pinfect presences within Google Kubernetes Engine (GKE) clusters at several client companies, with one compromise spanning six months.  The compromises originated from exposed Redis instances, which allowed the botnet to gain an initial foothold.  The botnet's beaconing was repeatedly flagged in FortiCNAPP's Composite Alerts, underscoring how a single misconfiguration can enable long-term compromise in cloud environments.  The IOCs observed across