Microsoft Copilot Studio and Salesforce Agentforce Hit by Prompt Injection Flaws
Microsoft recently patched a critical indirect prompt injection vulnerability (CVE-2026-21520) in Copilot Studio, discovered by Capsule Security. Despite the patch, data exfiltration occurred because the system treated malicious LLM-generated requests ... Read More