Microsoft 365 Copilot is a technology platform tracked across 19 threat clusters and 28 intelligence report mentions on ThreatCluster. First observed November 20, 2025; most recent activity July 15, 2026.
OrcaRouter Security Research released its AI Threat Report 2026, identifying prompt injection as the leading risk to large language model (LLM) applications, with a 340% increase in such attacks year-over-year. The…
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…
On July 15, 2026, Microsoft released security patches to address multiple critical vulnerabilities across its software products. The vulnerabilities include Remote Code Execution and Elevation of Privilege issues…
A newly disclosed vulnerability in Microsoft 365 Copilot Enterprise, named SearchLeak (CVE-2026-42824), allows attackers to exfiltrate sensitive data with a single click on a crafted link. Discovered by Varonis Threat…
Recent research highlights significant vulnerabilities in agentic AI systems, which can misclassify adversarial inputs as trusted instructions across six architectural layers. These vulnerabilities stem from trust…
On May 7, 2026, Microsoft disclosed and remediated three critical information disclosure vulnerabilities in Microsoft 365 Copilot and Copilot Chat, tracked as CVE-2026-26129, CVE-2026-26164, and CVE-2026-33111. These…
In 2025, over 90 organizations fell victim to prompt injection attacks, exploiting vulnerabilities in large language models (LLMs). CrowdStrike's 2026 Global Threat Report indicates that AI-enabled cyberattacks surged…
Stellantis and Microsoft have announced a five-year collaboration to enhance digital capabilities, focusing on AI and cybersecurity. The partnership aims to co-develop over 100 initiatives that will integrate AI-driven…
Gartner analyst Dennis Xu has humorously suggested banning the use of Microsoft’s Copilot AI on Friday afternoons, citing concerns that users may neglect to verify its potentially offensive outputs during that time.…
Microsoft confirmed a bug in its Copilot AI that allowed unauthorized summarization of customers' confidential emails from late January 2026. The issue affected Microsoft 365 users, bypassing data loss prevention…