Affected Technology

Microsoft incidents

Microsoft AI and Copilot security developments

Matching incidents

31

Technology type

Vendor

Low severity STABLE

CVE-2024-50050 Insecure Deserialization Vulnerability affecting Llama Stack

Llama Stack prior to revision 7a8aa775e5a267cf8660d83140011a0b7f91e005 used pickle as a serialization format for socket communication, potentially allowing for remote code execution. The issue can allow unauthenticated attackers to invoke exposed MCP bridge tooling and execute commands in the affected container.

MetaMicrosoftNvidiaLlama StackTensorRT-LLMvLLM
News STABLE

Malicious AI Assistant Extensions Harvest LLM Chat Histories

Malicious Chromium-based browser extensions are impersonating legitimate AI tools to harvest sensitive LLM chat histories and browsing data, impacting over 900,000 installs and 20,000 enterprise tenants. These extensions exfiltrate proprietary code, internal workflows, and confidential data to threat actor-controlled infrastructure, leading to widespread information leakage.

MicrosoftOpenAIChatGPTTrojan:JS/ChatGPTStealerData LeakageChat Histories
1 source: microsoft.com Updated 5mo ago
Low severity STABLE

Microsoft Data Exposure

A reported vulnerability in Microsoft 365 Copilot could lead to the exposure of sensitive email content through its AI summarization feature. This flaw poses a risk of unauthorized data disclosure, potentially compromising user privacy within the Microsoft 365 ecosystem.

MicrosoftData LeakageAI SummarizationCopilot Vulnerability ExposesSensitive Emails
1 source: cyberpress.org Updated 6mo ago
News STABLE

Researcher Uncovers 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks

Security researcher Ari Marzouk disclosed "IDEsaster," a collection of over 30 vulnerabilities, with 24 assigned CVEs, affecting various AI-powered Integrated Development Environments (IDEs) like GitHub Copilot and Cursor. These flaws enable attackers to chain prompt injection techniques with legitimate IDE features and auto-approved AI agent tool calls to achieve sensitive data exfiltration and remote code execution (RCE).

1 source: thehackernews.com Updated 8mo ago
News STABLE

Microsoft Flags AI-Driven Phishing: LLM

Threat actors are employing Large Language Models (LLMs) to create sophisticated phishing campaigns, leveraging LLM-generated code to obfuscate malicious payloads within Scalable Vector Graphics (SVG) files. These meticulously crafted SVG files bypass email security by disguising embedded JavaScript with business terminology, ultimately redirecting victims to fake login pages for credential harvesting.

MicrosoftCredential ExposureCrafted SVG FilesDriven PhishingMicrosoft Flags AIOutsmart Email Security
1 source: thehackernews.com Updated 10mo ago
Low severity STABLE

Critical flaw in Microsoft Copilot could have allowed zero-click attack

A critical zero-click vulnerability, dubbed "EchoLeak" and identified as CVE-2025-32711, was discovered in Microsoft Copilot. This flaw leveraged an "LLM scope violation" to allow remote attackers to exfiltrate sensitive data from Microsoft 365 services without any user interaction.

News STABLE

Microsoft 365 Copilot: New Zero

Researchers have uncovered "EchoLeak," a critical zero-click vulnerability in Microsoft 365 Copilot that exploits design flaws inherent to Retrieval Augmented Generation (RAG) applications. This flaw, leveraging an "LLM Scope Violation" technique, allows for the automatic exfiltration of sensitive corporate data from the LLM's context without requiring user interaction.

Amazon AWSMicrosoftAllows Corporate DataClick AI VulnerabilityCopilotNew Zero
Low severity STABLE

Microsoft Copilot Security Incident

A critical "EchoLeak" zero-click vulnerability in Microsoft 365 Copilot allowed attackers to remotely exfiltrate sensitive internal data by sending emails containing hidden instructions. This flaw represents an LLM scope violation where the AI agent was tricked into accessing information beyond its intended permissions without user interaction.

1 source: fortune.com Updated 1y ago
Low severity NEW

Microsoft Copilot Security Vulnerability

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced

Amazon AWSMicrosoftMicrosoft CopilotAppsData From ConnectedMicrosoft Copilot Personal
Low severity NEW

Data Breaches Hit 471M Victims: 2026 Report Breakdown - tech

The Identity Theft Resource Center reported 471.2 million data breach victims in H1 2026, a 58% increase over 2025, driven by surging malicious insiders and AI-scaled phishing attacks. This escalation is facilitated by exploits like the ShieldBreak Microsoft Defender zero-day (CVE-2026-69414) and supply-chain compromises, exemplified by the Trezor customer data exposure via ShipMonk.

Low severity STABLE

AI Security Vulnerability

Microsoft launched Project Perception, an AI security platform leveraging multi-agent systems and specialized models like MAI-Cyber-1-Flash for automated vulnerability discovery and threat investigation. This platform orchestrates red, blue, and green AI agents to identify weaknesses, detect exploitation, and implement remediation actions, aiming to harden systems and reduce operational costs.

1 source: linkedin.com Updated 23d ago
Low severity STABLE

Microsoft Security Incident

Microsoft has developed a new multi-model agentic security system designed for AI-driven defense at high speeds. This advanced system has successfully surpassed leading industry benchmarks, demonstrating superior performance in security capabilities.

MicrosoftDefense
1 source: microsoft.com Updated 3mo ago
Low severity STABLE

Microsoft Prompt Injection Vulnerability

Microsoft security researchers have identified "AI Recommendation Poisoning," an attack exploiting specially crafted URLs or embedded prompts to inject persistent, biasing instructions into AI assistant memory. This technique, categorized under MITRE ATLAS® AML.T0080, can compromise AI objectivity, leading to subtly manipulated recommendations in critical domains like finance, health, and security.

MicrosoftPrompt InjectionAI Recommendation PoisoningManipulating AI
1 source: microsoft.com Updated 6mo ago
Low severity STABLE

Microsoft Prompt Injection Vulnerability

The article details "GRP-Obliteration," a novel technique leveraging Group Relative Policy Optimization (GRPO) to dismantle the safety alignment of Large Language Models and diffusion models. This method exploits a training feedback loop, where a judge model reinforces harmful prompt responses, leading to broad unalignment across various safety categories even with a single, mild adversarial prompt.

1 source: microsoft.com Updated 6mo ago
Low severity STABLE

Microsoft Copilot Prompt Injection Vulnerability

Researchers unveiled a "Reprompt" attack method enabling single-click data exfiltration from Microsoft Copilot by exploiting the "q" URL parameter for indirect prompt injection. This attack bypasses enterprise security controls and guardrails, facilitating continuous, hidden data exfiltration via attacker-controlled servers without further user interaction.

MicrosoftMicrosoft CopilotPrompt InjectionAttack Allowing SingleClick Data ExfiltrationFrom Microsoft Copilot
1 source: thehackernews.com Updated 7mo ago
Low severity STABLE

Microsoft Copilot Prompt Injection Vulnerability

AI agents created using Microsoft Copilot Studio are vulnerable to prompt injection, allowing attackers to bypass internal security mandates. This exploit facilitates the unauthorized exfiltration of sensitive corporate data and enables malicious modification of information, posing a significant risk to organizations.

1 source: darkreading.com Updated 8mo ago
Low severity STABLE

Microsoft Security Incident

The "Whisper Leak" is a novel side-channel attack targeting remote language models, allowing passive adversaries to infer sensitive conversation topics from encrypted network traffic. This is achieved by analyzing packet sizes and inter-arrival times of streaming LLM responses, which enables trained classifiers to reliably identify specific prompt topics, posing a significant privacy risk.

MicrosoftAI Chat TopicsAttack That IdentifiesEncrypted TrafficMicrosoft UncoversWhisper Leak
1 source: thehackernews.com Updated 9mo ago
Low severity STABLE

Microsoft Security Incident

The "Whisper Leak" is a novel side-channel attack that infers language model conversation topics by analyzing network packet sizes and timings, even when communications are protected by end-to-end TLS encryption. This allows attackers observing network traffic to deduce sensitive information about user prompts, posing significant privacy risks to users and enterprises.

MicrosoftWhisper Leak
1 source: microsoft.com Updated 9mo ago
Low severity STABLE

AI Prompt Injection Vulnerability

Security researchers demonstrated a prompt injection attack against an AI agent built on Microsoft Copilot Studio, enabling it to reveal private knowledge and complete Salesforce CRM records without human verification. Although Microsoft patched the specific vulnerability, Zenity warns that thousands of public-facing AI agents remain susceptible to similar "agent aijacking" attacks.

1 source: cxtoday.com Updated 1y ago
Low severity STABLE

AI Prompt Injection Vulnerability

Zenity Labs research details how widely deployed AI agents are highly susceptible to "hijacking attacks" via methods such as email-based prompt injection and zero-click risks. These vulnerabilities enable data exfiltration, manipulation of critical workflows, user impersonation, and long-term access, impacting major platforms like OpenAI ChatGPT, Microsoft Copilot, Salesforce Einstein, and Google Gemini.

Low severity STABLE

AI Security Vulnerability

The "EchoLeak" vulnerability in Microsoft 365 Copilot allows attackers to embed hidden commands within regular emails, triggering the AI agent to access and expose sensitive files like emails and spreadsheets without user action. This "zero-click" attack highlights a structural vulnerability in AI tools, enabling silent data exfiltration and making breach source identification extremely difficult.

1 source: zscaler.com Updated 1y ago
Low severity STABLE

Microsoft Prompt Injection Vulnerability

Prompt injection attacks are identified as the top threat to generative AI, enabling adversaries to manipulate Large Language Models (LLMs) to bypass safety measures, exfiltrate sensitive data, or perform unintended actions, including jailbreaks. Microsoft addresses this by introducing Azure Prompt Shields within Azure AI Content Safety, providing real-time defense against direct and indirect prompt injection attacks through advanced machine learning and contextual awareness.

MicrosoftPrompt InjectionAzure AI ContentAzure Prompt ShieldsEnhance AISafety

Back to intelligence feed