From runtime risk to real‑time defense: Securing AI agents
ID: f73d5933-eafe-550c-9df1-25c8ff0d76e2
STIX ID: report--f73d5933-eafe-550c-9df1-25c8ff0d76e2
Feed Name: Microsoft Security
Date Published: 2026-01-23
Date Updated: 2026-04-28
Author: Microsoft Defender Security Research Team
This report analyzes security risks introduced by Microsoft Copilot Studio agents, demonstrating how natural-language inputs can be abused to manipulate agent planning and invoke privileged tools, potentially leading to unauthorized actions or data exfiltration. It presents three scenarios—malicious instruction injection in event-triggered workflows, prompt injection via shared documents causing email exfiltration, and capability reconnaissance against public chatbots—and explains how Microsoft Defender’s webhook-based runtime checks inspect planned tool invocations and block unsafe actions to provide runtime protection without changing agent logic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
