Prompt Injection
The latest Prompt Injection coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2025-55319: How Agentic AI in Visual Studio Code Can Enable Remote Code Execution
A newly listed vulnerability in Microsoft’s Security Response Center, CVE-2025-55319, pulls back the curtain on a dangerous new class of attacks: prompt injections that weaponize agentic AI...
Zenity Embeds Inline Attack Prevention in Microsoft Copilot Studio Agents
On May 22, 2025, Zenity unfurled an expanded integration with Microsoft Copilot Studio that embeds native, inline security controls directly into the execution path of enterprise AI agents. The move...
Copilot Studio Now Intercepts Agent Actions for Real-Time Security Vetoes
Microsoft has shifted the security model for its Copilot Studio from passive guardrails to active, inline enforcement. Organizations can now route an AI agent’s planned actions—including prompts,...
Zenity's Real-Time Agent Security Hits Azure Marketplace Preview for Copilot Studio
Microsoft Copilot Studio agents now have a dedicated inline security layer that can block prompt injections, data exfiltration, and secrets misuse mid-execution, following Zenity’s expanded...
Copilot Studio Now Lets Security Teams Block Agent Actions in Under One Second
Microsoft has handed enterprise defenders a powerful new capability: the ability to inspect and veto every planned action of an autonomous AI agent before execution, all within a single second....
Copilot Studio's New Runtime Security Lets Enterprises Veto AI Agent Actions Instantly
Microsoft is giving enterprise security teams a new way to block dangerous AI agent actions in near real time. A public preview feature in Copilot Studio, announced March 2025, lets organizations...
Microsoft Copilot’s EchoLeak Flaw Proves GenAI Must Embrace Zero Trust — Or Risk Catastrophic Data Leaks
A zero-click prompt injection flaw in Microsoft 365 Copilot, discovered in January by security researchers at Aim Labs, allowed attackers to trick the AI assistant into silently exfiltrating...
Claude Lands in Chrome as an AI Agent, Igniting Browser War and Privacy Firestorm
Anthropic has slipped its Claude AI assistant directly into Google Chrome, turning the world’s most popular browser into a launchpad for AI agents—and instantly raising the stakes for...
Ireckonu CEO: Hotels Pasting Guest Data into Public AI Chatbots Risk GDPR Fines and Broken Trust
Hotel staff are casually copying guest names, preferences, and booking histories into public generative AI tools like ChatGPT, and the practice is creating a ticking privacy time bomb. That’s the...
Claude for Chrome Pilot Exposes Residual Prompt Injection Risks for Enterprise AI Browsing
Anthropic has quietly launched a research preview of a Chrome extension that lets its Claude AI assistant operate web browsers—clicking buttons, filling forms, and navigating multi-step...
Chrome’s AI Security Line: Hallucinations Are Feedback, Prompt Injection Is a Breach
Google quietly revised Chrome’s public security FAQ last week, inserting a new “AI Features” section that finally tells bug hunters and enterprises exactly how the browser team will triage...
Microsoft’s 1.3 Billion Agent Projection Sparks Urgent Security Overhaul with Entra Agent ID and MCP Governance
Microsoft expects more than 1.3 billion AI agents to be operating across enterprises by 2028—a staggering scale that demands a fundamental rethink of identity, access, and runtime security. The...