If you have noticed that copy and paste suddenly stopped working in Microsoft Excel, you are not alone.
Microsoft's latest Patch Tuesday update (KB5002914) has introduced a bug that silently disables the paste function across Excel 2016, 2019, 2021, and 2024.
When users attempt to paste content, the operation simply fails without displaying an error message or alert: the source stays selected, and the target cell remains blank.
Microsoft has officially acknowledged the issue and confirmed that a fix is currently in the works. Until an update rolls out, there is no official workaround available.
#Microsoft #Excel #TechNews #CyberSecurity #PatchTuesday #ITSupport
https://www.itpro.com/security/microsoft-patch-tuesday-inadvertently-takes-down-copy-and-paste-in-excel-and-theres-no-way-to-fix-it-yet
Remote
Pedram
@psoheil@c.im
mastodon 4.7.29 Followers
11 Following
4 Posts
Joined November 06, 2022
LinkedIn Profile:
Open post
One small change can make a big difference in software supply chain security.
PyPI has introduced a new safeguard that rejects uploads of new files to package releases older than 14 days. This helps prevent attackers who compromise a maintainer’s account or publishing pipeline from silently adding malicious files to a long-trusted package version months after it was released.
While this doesn’t eliminate all supply chain threats, it significantly reduces the risk of “package poisoning” attacks against pinned dependencies and encourages immutable releases, a security best practice every ecosystem should strive for.
Security isn’t about a single silver bullet, it’s about layering defenses that make attacks increasingly difficult.
Could we see similar protections become the standard across other package registries like npm, NuGet, and RubyGems?
https://cybersecuritynews.com/pypi-14-day-release-lock/amp/
#CyberSecurity #AppSec #SupplyChainSecurity #PyPI #Python #DevSecOps #SoftwareSecurity #OpenSource #SecureByDesign #SoftwareSupplyChain #Infosec
8
1
6
0
Open post
Laravel Scalpel: A New Way to Detect Filesystem Intrusions in Laravel
Laravel applications can be compromised in ways that traditional code and dependency scanners may not catch. Laravel Scalpel takes a different approach by looking for evidence that a deployed application has already been modified or compromised.
It can detect:
• Rogue PHP files and suspicious extensions
• Obfuscated PHP and common backdoor patterns
• Malicious .htaccess and .user.ini changes
• Unexpected .env files and configuration issues
• Added, modified, or deleted files using SHA-256 baselines
• Changes that can be integrated into CI/CD security checks
It also supports JSON, SARIF, and GitHub Actions output, making it interesting for teams that want to incorporate filesystem integrity checks into their deployment pipelines.
One important limitation: Scalpel runs with the same permissions as the Laravel application, so it should be treated as a detection tool rather than a complete security or containment solution.
For Laravel teams, this is an interesting additional layer for detecting signs of post-deployment compromise.
#Laravel #PHP #Cybersecurity #ApplicationSecurity #DevSecOps #WebSecurity #SoftwareDevelopment #CI_CD
https://laravel-news.com/laravel-scalpel
0
0
0
0
Open post
Akamai security researchers have uncovered an interesting attack technique they call “Bring Your Own EDR.”
The research demonstrates how a trusted, privileged EDR component can potentially become an attacker’s tool against the system it was designed to protect.
In a SentinelOne case study, researchers found that exposed interfaces could be abused by an administrator to bypass Windows Protected Process Light protections and interact with highly protected processes. By chaining multiple techniques, they demonstrated how legitimate security software could potentially be turned into a powerful attack mechanism.
The bigger lesson is important: security software itself is part of the attack surface.
EDR solutions operate with extremely high privileges, which makes vulnerabilities, exposed interfaces, weak trust assumptions, and insecure management mechanisms particularly significant. Organizations should consider not only whether their security tools detect threats, but also how well those tools protect themselves from abuse.
“Bring Your Own EDR” is an interesting evolution of the traditional BYOVD concept and another reminder that trusted software should never automatically be treated as inherently trustworthy.
#Cybersecurity #EDR #EndpointSecurity #ThreatResearch #ZeroTrust #WindowsSecurity #SecurityResearch #InformationSecurity
https://www.akamai.com/blog/security-research/bring-your-own-edr-turn-commercial-edr-trojan-horse
0
0
0
0

