Microsoft reported a critical vulnerability (CVE-2025-21415) in Azure AI Face Service that allowed attackers to bypass authentication via spoofing, leading to privilege escalation. The issue, classified as critical with a CVSS score of 9.9, has been fully mitigated, requiring no customer action. Microsoft emphasizes its commitment to transparency and encourages users to adopt security best practices.
Researchers Flag Crypto-Stealing Malware in Google and Apple Apps
Cybersecurity researchers have discovered a cross-platform malware campaign named “SparkCat” that targets cryptocurrency wallet recovery phrases through malicious mobile apps. Cybersecurity researchers at Kaspersky first