A CVSS 9.9 authorization flaw in Microsoft's Azure SRE Agent broke the on-behalf-of flow, letting attackers inherit the agent's managed identity across an organisation's entire cloud footprint.
A CVSS 9.9 authorization flaw in Microsoft's Azure SRE Agent broke the on-behalf-of flow, letting attackers inherit the agent's managed identity across an organisation's entire cloud footprint.
Varonis researchers used the assistant's own refusals to map an undocumented URL parameter in Microsoft Copilot Personal, chaining it into silent access to Gmail, Drive, and Calendar. Microsoft patched CVE-2026-24301 on August 18.
A critical unauthenticated SSRF in MLflow's webhook delivery lets attackers pivot into cloud metadata endpoints and steal credentials. WatchTowr's honeypot network caught scanning starting within hours of the CVE going public.
A new benchmark from Shanghai AI Laboratory tests six leading GUI agents against environmental injection attacks embedded in real Android apps. Every agent is vulnerable, attack success rates reach 66.9%, and stronger agents turn out to be more exploitable, not less.
Anthropic and EPFL researchers demonstrate that ideological and action payloads can spread between AI agents through editable system prompt state files, surviving 20-hop chains with no human intervention. One defensive measure stops them almost entirely.