Microsoft Defender Blocks Email Prompt Injection Attacks Before They Reach Copilot
ID: 4ae13a68-683d-5506-85ff-d841a385897e
STIX ID: report--4ae13a68-683d-5506-85ff-d841a385897e
Feed Name: Cyber Press
Microsoft added a new detection layer to Defender for Office 365 that identifies and blocks prompt-injection attacks embedded in inbound email before delivery. The feature normalizes and inspects HTML, hidden/invisible text, quoted threads, attachments, and obfuscated segments using LLM classification combined with existing sender/message signals; detected messages are flagged as High Confidence Phishing and can be correlated in Defender XDR for further hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
