Theme:
Light Dark Auto
GeneralPoliticsBusinessEconomyTechnologyEnvironmentScienceSportsHealthEducationEntertainmentLifestyleGeneralNationWorld
TECHNOLOGY

Microsoft’s plan to fix the web with AI has already hit an embarrassing security flaw

A critical vulnerability allowing remote access to sensitive files, including API keys, has been discovered in Microsoft's new NLWeb protocol. Researchers Aonan Guan and Lei Wang reported the flaw in May, with Microsoft patching it in July but not issuing a CVE. The vulnerability, a classic path traversal flaw, is easily exploited via a malformed URL. While Microsoft claims the impacted code isn't used in their products, NLWeb users need to update their builds to remain secure. The incident highlights concerns about Microsoft's balance between rapid AI feature deployment and robust security practices.

Prepared by Jonathan Pierce and reviewed by editorial team.

Related News

Comments

JQJO App
Get JQJO App
Read news faster on our app
GET