Varonis researchers used the assistant's own refusals to map an undocumented URL parameter in Microsoft Copilot Personal, chaining it into silent access to Gmail, Drive, and Calendar. Microsoft patched CVE-2026-24301 on August 18.
Varonis researchers used the assistant's own refusals to map an undocumented URL parameter in Microsoft Copilot Personal, chaining it into silent access to Gmail, Drive, and Calendar. Microsoft patched CVE-2026-24301 on August 18.
Varonis disclosed at DEF CON 34 that Atlassian Rovo's URL parameter pre-fills the AI agent with attacker-controlled prompts, enabling a one-click attack that directs Rovo's ResearchAgent to exfiltrate Jira, Confluence, Slack, and M365 data to an attacker URL.
xAI's Grok Build CLI 0.2.93 uploaded entire Git repositories including commit history and unredacted credentials to a Google Cloud Storage bucket by default. Here's what was exposed and what xAI's server-side fix left unanswered.
Straiker's STAR Labs ran over 1,700 adversarial scenarios against production AI coding and productivity agents. The headline finding: 36% of successful coding agent attacks reach remote code execution on the developer's machine, putting source code and cloud credentials at direct risk.
Noma Security's GitLost research shows that a public GitHub issue can trick GitHub Agentic Workflows into exfiltrating private repository contents. The attack requires no credentials — just a crafted issue on any public repo the agent can see.
Research confirms that text embeddings stored in vector databases are not safely anonymised. Inversion attacks can reconstruct source text with high fidelity from embeddings alone, including those produced by commercial APIs.
Johann Rehberger's DEF CON Singapore research demonstrates how indirect prompt injection chains into Microsoft Copilot's memory feature to plant a persistent backdoor — one that survives across every future session, not just the compromised one.
Varonis Threat Labs chained three bugs in Microsoft 365 Copilot Enterprise Search to build a one-click exfiltration path that pulls emails, files, and live MFA codes without any OAuth prompt or user consent beyond clicking a Microsoft-domain URL.
A UK law firm's misconfigured AI document assistant was exploited to systematically extract privileged client communications and M&A due diligence files over six weeks.