Related Threat Clusters
-
OrcaRouter AI Threat Report 2026 Highlights Rising Prompt Injection Risks
OrcaRouter Security Research released its AI Threat Report 2026, identifying prompt injection as the leading risk to large language model (LLM) applications, with a 340% increase in such attacks year-over-year. The…
3 articles · Updated June 22, 2026 -
Self-Propagating AI Worm Discovered in Microsoft Word Copilot
A critical vulnerability in Microsoft Copilot for Word allows hidden malicious prompts in documents to alter generated content and spread to new files. Disclosed by researcher Håkon Måløy, this issue, termed 'Context…
6 articles · Updated July 30, 2026 -
New Cryptographic Context Injection Attack Targets AI Coding Agents
A novel attack technique named Cryptographic Context Injection has been identified, allowing attackers to inject malicious instructions into AI models like Grok and Gemini. This method involves shipping encrypted…
11 articles · Updated August 20, 2026 -
Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…
57 articles · Updated June 9, 2026 -
Microsoft July 2026 Security Patches Address Critical Vulnerabilities
On July 15, 2026, Microsoft released security patches to address multiple critical vulnerabilities across its software products. The vulnerabilities include Remote Code Execution and Elevation of Privilege issues…
2 articles · Updated July 15, 2026 -
Critical SearchLeak Vulnerability in Microsoft 365 Copilot Exposes Sensitive Data
A newly disclosed vulnerability in Microsoft 365 Copilot Enterprise, named SearchLeak (CVE-2026-42824), allows attackers to exfiltrate sensitive data with a single click on a crafted link. Discovered by Varonis Threat…
34 articles · Updated June 15, 2026 -
Attackers Use Indirect Prompt Injection to Manipulate AI Systems
In 2025, attackers exploited AI systems by embedding malicious commands in emails and documents, a technique known as indirect prompt injection. This method targets AI tools that process digital communications,…
2 articles · Updated July 30, 2026 -
Emerging Threats in Agentic AI Systems: Trust Inversion and Attack Patterns
Recent research highlights significant vulnerabilities in agentic AI systems, which can misclassify adversarial inputs as trusted instructions across six architectural layers. These vulnerabilities stem from trust…
2 articles · Updated May 18, 2026 -
Microsoft 365 Copilot Vulnerabilities Expose Sensitive Information
On May 7, 2026, Microsoft disclosed and remediated three critical information disclosure vulnerabilities in Microsoft 365 Copilot and Copilot Chat, tracked as CVE-2026-26129, CVE-2026-26164, and CVE-2026-33111. These…
3 articles · Updated May 9, 2026 -
Prompt Injection Attacks Surge, Targeting AI Systems in 2025
In 2025, over 90 organizations fell victim to prompt injection attacks, exploiting vulnerabilities in large language models (LLMs). CrowdStrike's 2026 Global Threat Report indicates that AI-enabled cyberattacks surged…
11 articles · Updated June 28, 2026
Recent Intelligence Reports
- Reprompt — www.varonis.com · September 7, 2026
- Prompt injection protection: Detecting and blocking malicious AI instructions — Acronis · September 7, 2026
- New attack bypasses AI guardrails by encrypting malicious prompts — Feeds.Feedburner · August 21, 2026
- Microsoft 365 Copilot Word worm survives model updates — Feeds.4Sysops · July 30, 2026
- Proven LLM Security Best Practices That Stand Between Your AI and an Attack — Bignewsnetwork · July 30, 2026
- July 2026 Monthly Patch — Csa.Sg · July 15, 2026
- July 2026 Monthly Patch — Csa.Sg · July 15, 2026
- Prompt injection is exploiting enterprise AI's biggest design flaws by targeting agents, RAG ... — Venturebeat · June 28, 2026