logo

Copilot's No-Code AI Agents Liable to Leak Company Data

ID: d43cb9d0-4b70-59ee-b9c3-733f15ae69d3

STIX ID: report--d43cb9d0-4b70-59ee-b9c3-733f15ae69d3

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-12-11

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Tenable researchers showed that Microsoft Copilot Studio AI agents are easily susceptible to prompt injection, enabling disclosure of sensitive customer data and unauthorized actions (such as editing bookings to cost $0); the report warns this is a systemic risk across agent platforms, exacerbated by unmonitored "shadow AI," and urges centralized visibility, permission controls, and continuous monitoring to mitigate exposures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.