Related Threat Clusters
-
OrcaRouter AI Threat Report 2026 Highlights Rising Prompt Injection Risks
OrcaRouter Security Research released its AI Threat Report 2026, identifying prompt injection as the leading risk to large language model (LLM) applications, with a 340% increase in such attacks year-over-year. The…
3 articles · Updated June 22, 2026 -
Microsoft and Salesforce Address AI Agent Data Exfiltration Vulnerabilities
Microsoft and Salesforce have patched serious prompt injection vulnerabilities in their AI platforms, Copilot Studio and Agentforce, respectively. Capsule Security identified these flaws, allowing attackers to…
6 articles · Updated April 15, 2026 -
Critical SearchLeak Vulnerability in Microsoft 365 Copilot Exposes Sensitive Data
A newly disclosed vulnerability in Microsoft 365 Copilot Enterprise, named SearchLeak (CVE-2026-42824), allows attackers to exfiltrate sensitive data with a single click on a crafted link. Discovered by Varonis Threat…
34 articles · Updated June 15, 2026 -
Attackers Use Indirect Prompt Injection to Manipulate AI Systems
In 2025, attackers exploited AI systems by embedding malicious commands in emails and documents, a technique known as indirect prompt injection. This method targets AI tools that process digital communications,…
2 articles · Updated July 30, 2026 -
Emerging Threats in Agentic AI Systems: Trust Inversion and Attack Patterns
Recent research highlights significant vulnerabilities in agentic AI systems, which can misclassify adversarial inputs as trusted instructions across six architectural layers. These vulnerabilities stem from trust…
2 articles · Updated May 18, 2026 -
AI Exploitation Threats Prompt Emergency Meeting Among U.S. Financial Leaders
VectorCertain LLC has validated its SecureAgent platform, achieving 100% detection and prevention of autonomous multi-step AI exploitation attempts and unsanctioned AI agent scope expansion. The validation involved…
3 articles · Updated April 14, 2026 -
Prompt Injection Attacks Surge, Targeting AI Systems in 2025
In 2025, over 90 organizations fell victim to prompt injection attacks, exploiting vulnerabilities in large language models (LLMs). CrowdStrike's 2026 Global Threat Report indicates that AI-enabled cyberattacks surged…
11 articles · Updated June 28, 2026 -
Google Patches GeminiJack Zero-Click Exploit in Gemini Enterprise
Google has addressed a zero-click vulnerability in Gemini Enterprise and Vertex AI, identified as 'GeminiJack.' Discovered by Noma Labs in June 2025, this exploit could have allowed attackers to steal sensitive…
4 articles · Updated December 10, 2025
Recent Intelligence Reports
- Proven LLM Security Best Practices That Stand Between Your AI and an Attack — Bignewsnetwork · July 30, 2026
- Prompt injection is exploiting enterprise AI's biggest design flaws by targeting agents, RAG ... — Venturebeat · June 28, 2026
- OrcaRouter Releases AI Threat Report 2026 and Makes Its Security Controls Free Amid ... — Bignewsnetwork · June 23, 2026
- OrcaRouter Releases AI Threat Report 2026 and Makes Its Security Controls Free Amid ... — Irishsun · June 22, 2026
- OrcaRouter Releases AI Threat Report 2026 and Makes Its Security Controls Free Amid Rise in Prompt-Injection Attacks — Aninews.In · June 22, 2026
- A single click on a Microsoft link could have drained your inbox. Here's how SearchLeak worked. — Thenextweb · June 15, 2026
- Common Agentic Attack Patterns: 6 Layers Explained — Augmentcode · May 18, 2026
- Microsoft patched a Copilot Studio prompt injection. The data exfiltrated anyway. — Venturebeat · April 15, 2026