Hackers Exploit Copilot Studio’s New Connected Agents Feature to Gain Backdoor Access
ID: 60de0b73-f346-5750-842f-cd1532ad2cf7
STIX ID: report--60de0b73-f346-5750-842f-cd1532ad2cf7
Feed Name: Cyber Press
Security researchers at Zenity Labs disclosed critical design flaws in Microsoft Copilot Studio’s Connected Agents: the feature is enabled by default, allows agents to invoke other agents’ capabilities (e.g., sending email) without generating activity logs in the invoked agent’s audit trail, and provides administrators no native visibility into external agent connections. This gap lets malicious insiders or compromised accounts impersonate organizations, send fraudulent communications, and perform unauthorized actions at scale; the report urges immediate auditing, disabling the feature for sensitive agents, restricting sharing to trusted users, adding third-party monitoring, and enforcing approval workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
