Microsoft Copilot for Word Vulnerability Allows Hidden Prompt Injection and Propagation
Security researcher Håkon Måløy disclosed a prompt injection vulnerability in Microsoft 365 Copilot for Word that allows hidden instructions in a document…
Security researcher Håkon Måløy disclosed a prompt injection vulnerability in Microsoft 365 Copilot for Word that allows hidden instructions in a document…
A new class of attack called Agent Data Injection (ADI) has been disclosed by researchers from Seoul National University, the University of…
A new attack named MemGhost demonstrates how a single email can inject persistent false memories into AI personal assistants, manipulating their future…
Microsoft has issued a warning about a new attack vector targeting AI agents that use the Model Context Protocol (MCP). Attackers can…
A critical vulnerability in Microsoft 365 Copilot Enterprise Search, dubbed SearchLeak, could have allowed attackers to exfiltrate emails, files, and MFA codes…
A critical command injection vulnerability in Microsoft 365 Copilot Enterprise Search, discovered by Varonis Threat Labs, allows one-click data exfiltration. Microsoft assigned…
EchoLeak is a prompt injection vulnerability in Microsoft 365 Copilot disclosed by Aim Security in June 2025. An attacker could craft an…
An AI-powered assistant integrated into Microsoft 365 apps, including Word, that can draft, edit, and summarize content based on user prompts and…