option
Home
Flash News
Content
PatrickGonzález
PatrickGonzález
May 26, 2026

A security report reveals a severe vulnerability in Microsoft 365s Copilot Cowork AI agent Attackers can use indirect prompt injection via documents or templates to manipulate the AI The compromised agent can secretly exfiltrate authenticated download links for sensitive files from OneDrive or SharePoint sending them to attackers via Teams The automated scheduled task feature amplifies the risk making detection and prevention difficult

A security report reveals a severe vulnerability in Microsoft 365s Copilot Cowork AI agent Attackers can use indirect prompt injection via documents or templates to manipulate the AI The compromised agent can secretly exfiltrate authenticated download links for sensitive files from OneDrive or SharePoint sending them to attackers via Teams The automated scheduled task feature amplifies the risk making detection and prevention difficult
Comments (0)
0/300
OR