💻 Technology 6d ago · louiswcolumbus@gmail.com (Louis Columbus)

Microsoft patched a Copilot Studio prompt injection. The data exfiltrated anyway.

VentureBeat
VentureBeat tech
View Channel →
Microsoft patched a Copilot Studio prompt injection. The data exfiltrated anyway.
Source ↗ 👁 0 💬 0
Microsoft assigned CVE-2026-21520, a CVSS 7.5 indirect prompt injection vulnerability, to Copilot Studio. Capsule Security discovered the flaw, coordinated disclosure with Microsoft, and the patch was deployed on January 15. Public disclosure went live on Wednesday.That CVE matters less for what it fixes and more for what it signals. Capsule’s research calls Microsoft’s decision to assign a CVE to a prompt injection vulnerability in an agentic platform “highly unusual.” Microsoft previously assi

Comments (0)

Sign in to join the discussion

More Like This

📰
I saw Framework's new 'MacBook Pro for Linux users' and it may entice Windows fans, too
Latest news · 9h ago
The ‘Texas Chainsaw Massacre’ Reboot Snags an Exciting Director
Gizmodo · 9h ago
📰
I'm putting Motorola above Samsung when it comes to flip phones - and won't think twice
Latest news · 9h ago
ChatGPT Images 2.0 is here, and it’s way more than an upgrade
Digital Trends · 10h ago
SpaceX and Cursor strike partnership that might end in a $60 billion acquisition
Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics · 10h ago
OpenAI launches ChatGPT Images 2.0, Codex Labs developer training service
SiliconANGLE · 10h ago