Related Threat Clusters
-
Microsoft and Salesforce Address AI Agent Data Exfiltration Vulnerabilities
Microsoft and Salesforce have patched serious prompt injection vulnerabilities in their AI platforms, Copilot Studio and Agentforce, respectively. Capsule Security identified these flaws, allowing attackers to…
6 articles · Updated April 15, 2026 -
New GitHub Exploit Allows AI Coding Agents to Execute Malicious Payloads
Researchers from Mozilla's 0DIN have demonstrated a new attack vector that allows AI coding agents, specifically Anthropic's Claude Code, to execute malicious payloads from seemingly benign GitHub repositories. The…
67 articles · Updated June 28, 2026 -
Hackers Exploit Vulnerabilities in Copilot Studio's Connected Agents Feature
Security researchers at Zenity Labs have identified critical design flaws in Microsoft’s Copilot Studio, specifically in the newly introduced Connected Agents feature. These vulnerabilities enable attackers to…
3 articles · Updated December 30, 2025 -
Tenable Reveals Security Flaw in Microsoft Copilot AI Leading to Fraud Risks
Tenable's research shows that Microsoft Copilot Studio's no-code AI agents can be exploited through prompt injection attacks, resulting in data leakage and financial fraud. This vulnerability affects organizations using…
3 articles · Updated December 11, 2025 -
AI Agents Vulnerable to Data Leakage via Malicious Link Previews
AI agents can be manipulated by attackers to generate URLs that leak sensitive data through link previews in messaging apps. This vulnerability was identified by AI security firm PromptArmor, highlighting the risks…
4 articles · Updated February 11, 2026
Recent Intelligence Reports
- BeyondTrust Phantom Labs™ Research Hub — www.beyondtrust.com · August 5, 2026
- Microsoft patched a Copilot Studio prompt injection. The data exfiltrated anyway. — Venturebeat · April 15, 2026
- Copilot and Agentforce fall to form — Csoonline · April 15, 2026
- AI agents can spill secrets via malicious link previews — Theregister · February 11, 2026
- AI agents spill secrets just by previewing malicious links — Theregister · February 10, 2026
- Hackers Exploit Copilot Studio's New Connected Agents Feature to Gain Backdoor Access — Cyberpress · December 30, 2025
- Hackers Exploit Copilot Studio’s New Connected Agents Feature to Gain Backdoor Access — Cybersecuritynews · December 30, 2025
- Hackers Abuse Copilot Studio’s New Connected Agents Feature to Plant Backdoors — Gbhackers · December 30, 2025