logo

Hackers Exploit Copilot Studio’s New Connected Agents Feature to Gain Backdoor Access

ID: 60de0b73-f346-5750-842f-cd1532ad2cf7

STIX ID: report--60de0b73-f346-5750-842f-cd1532ad2cf7

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-12-30

Date Updated: 2026-04-19

Author: AnuPriya

...
...

Security researchers at Zenity Labs disclosed critical design flaws in Microsoft Copilot Studio’s Connected Agents: the feature is enabled by default, allows agents to invoke other agents’ capabilities (e.g., sending email) without generating activity logs in the invoked agent’s audit trail, and provides administrators no native visibility into external agent connections. This gap lets malicious insiders or compromised accounts impersonate organizations, send fraudulent communications, and perform unauthorized actions at scale; the report urges immediate auditing, disabling the feature for sensitive agents, restricting sharing to trusted users, adding third-party monitoring, and enforcing approval workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.