Sand Security Research disclosed a critical cross-tenant vulnerability in Writer's agent preview feature that let attackers steal session tokens and take over enterprise accounts with a single malicious link.
Sand Security Research disclosed a critical cross-tenant vulnerability in Writer's agent preview feature that let attackers steal session tokens and take over enterprise accounts with a single malicious link.
Varonis Threat Labs chained three bugs in Microsoft 365 Copilot Enterprise Search to build a one-click exfiltration path that pulls emails, files, and live MFA codes without any OAuth prompt or user consent beyond clicking a Microsoft-domain URL.
The NSA AISC's May 2026 CIS on MCP security: authentication gaps, tool poisoning via unsigned dynamic discovery, session-identity binding failures, and compensating controls.
RAG pipelines introduce document poisoning, indirect prompt injection via retrieved content, and semantic access control gaps that most security teams have not assessed.