Back to News
SourceDecrypt

Microsoft Fixes 'Perfect 10' Exploit That Could Have Let Hackers Run Code Remotely

The Entra ID flaw earned the highest possible severity score, but Microsoft says it patched the bug before publishing the CVE and found no evidence it was ever exploited.
Disclaimer: The views above are the author's only and do not represent 711BTC. Nothing here constitutes investment advice.

Related

09-09 23:02

Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider

The hardware wallet maker said a fake security alert claimed a hardware flaw could expose users’ recovery phrases.

08-27 21:36

Bitcoin Privacy Wallet Sparrow Issues Update After AI Flags Fixes

Developer Craig Raw said an AI-assisted review produced most of the fixes in version 2.5.4, though none appeared likely to put users’ funds at risk.

07-03 13:42Important

Gnosis Pay Security Incident Recap: Vulnerability stemmed from a flaw in signature verification logic; fix completed.

According to Foresight News , Gnosis Pay released a post-incident report on June 1st, disclosing that the root cause of the vulnerability was a flaw in the ERC-1271 signature verification logic within the Zodiac module: the system only reads the contract's return result and does not check whether the call was actually executed successfully. Attackers exploited this flaw to deploy a contract that intentionally failed but still returned a "valid" status, forged authorization, and then withdrew funds from accounts not owned by them. This vulnerability was introduced with Zodiac code version 3.4.0 in October 2023 and was patched on June 5th. The report shows that attackers withdrew approximately $1.5 million from 5,281 wallets, including approximately $641,000 in GNO, approximately $453,000 in EURE, and approximately $399,000 in USDC.e; another approximately $300,000 is locked in inaccessible accounts, and the team is exploring recovery methods. Gnosis Pay stated that it will expand its security team, introduce external audits, broaden the scope of smart contract audits, and has completed a complete product rebuild (v2) to improve its security response capabilities.

07-01 08:52Important

Anthropic responded to the Claude Code accusation of containing hidden code to detect Chinese users: It is true, and a complete rollback will be implemented tomorrow.

According to Foresight News , Thariq Shihipar, a member of the Claude Code team, responded to the issue of Anthropic embedding hidden code in Claude Code targeting Chinese users, stating that the mechanism was an "experimental" measure launched by the team in March 2026 to prevent unauthorized account resale and prevent model distillation attacks. The team has since deployed stronger mitigation measures and originally planned to take the experiment offline; the relevant PRs have been merged and will be fully rolled back in the new version released on July 2, 2026.

09-14 19:07

Microsoft Unveils 'Humanist AI' Code of Conduct, Asks the Public to Poke Holes in It

Mustafa Suleyman's AI unit wants feedback for six weeks before the document guides model training in 2027.

09-14 11:38

EU cyber rules put crypto wallet makers on 24-hour reporting clock

Crypto wallet providers must submit an early vulnerability report within 24 hours and a full notification within 72 hours of exploits, or risk administrative fines of as much as $17.3 million.