logo

Microsoft and ServiceNow's exploitable agents reveal a growing - and preventable - AI security crisis

ID: 58cd6a2d-5e21-5046-afea-a2ece69f0a54

STIX ID: report--58cd6a2d-5e21-5046-afea-a2ece69f0a54

Feed Name: ZDNet Security

Threat Score
70/100

Date Published: 2026-02-04

Date Updated: 2026-04-26

...
...

This article describes critical security risks in agentic AI: AppOmni disclosed 'BodySnatcher', a ServiceNow vulnerability where an attacker with only an email could impersonate an admin and execute agents to create privileged backdoors (ServiceNow issued a patch), and researchers flagged Microsoft Copilot Studio's 'Connected Agents' feature (enabled by default) as allowing lateral agent-to-agent access that can expose privileged capabilities; the piece emphasizes the need for least-privilege defaults, monitoring of agent interactions, and vendor/customer mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.