< Back to all clusters
[TECHNOLOGY] · Netherlands · 2 sources

Microsoft patches critical Exchange and Copilot flaws as new crypto‑wallet malware emerges

Microsoft Threat Intelligence announced the discovery of new malware hidden in two npm packages that targets cryptocurrency investors and developers. The code installs a Remote Access Trojan that can capture keystrokes, screenshots and search for crypto wallets, private keys and passwords. Data exfiltration is routed through the AI platform Hugging Face to evade detection. Microsoft also identified a related cryptojacking campaign that hijacks GPUs of gamers and hardware enthusiasts.

In a separate security bulletin, Microsoft said it had patched four critical vulnerabilities – two in Exchange Online (CVE‑2026‑48579) and two in its M365 Copilot and Copilot Chat for Edge (CVE‑2026‑42824, CVE‑2026‑45497, CVE‑2026‑47644). The flaws could allow data theft, command injection and remote code execution. No evidence of exploitation was reported and updates were applied automatically, requiring no action from users.