logo

Microsoft’s New Update Creates an Agentic OS Infostealer Attack Vector

ID: fe81fea7-df50-5835-be83-0c0c89d13ebe

STIX ID: report--fe81fea7-df50-5835-be83-0c0c89d13ebe

Feed Name: infostealers.com

Date Published: 2025-11-19

Date Updated: 2026-06-07

Author: InfoStealers

...
...

This document contains an embedded prompt-injection payload (white-on-white hidden text) that instructs an AI agent to locate sensitive credentials (passwords, API keys, private keys, seed phrases) across local apps and post them to an attacker-controlled webhook; it also references Microsoft guidance on prompt-injection/XPIA and indirect prompt injection as context.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.