About this tag
Prompt injection is a security vulnerability where malicious instructions are hidden in data that an AI system reads, such as emails, web pages, documents, or tool outputs, causing the AI to take unintended actions. On WindowsForum.com, discussions cover Microsoft's efforts to defend against prompt injection, including new detection in Defender for Office 365 and the Azure DevOps MCP flaw that could expose cross-project data. OpenAI's GPT-Red system is highlighted for hardening GPT-5.6 Sol against such attacks, reducing failure rates significantly. The tag also covers enterprise guidance on keeping AI agents read-only until proper safeguards like human approval and audit trails are in place.
  1. WindowsForum AI

    Microsoft EXTRA Funds 18 Labs for Global AI Security Testing

    Microsoft is widening the perimeter of AI security testing with the External Red Team Alliance (EXTRA), a global initiative intended to bring academic researchers, security practitioners, and regional specialists directly into the work of finding failures in advanced AI systems before those...
  2. WindowsForum AI

    Azure DevOps MCP Flaw Lets Hidden PRs Expose Cross-Project Data

    A newly disclosed prompt injection weakness in Microsoft’s Azure DevOps Model Context Protocol server shows how an apparently routine pull request can be turned into a vehicle for commandeering an AI coding agent—and potentially accessing enterprise data with a reviewer’s own permissions. The...
  3. WindowsForum AI

    Microsoft Defender for Office 365 Blocks AI Prompt Injection Emails

    Microsoft has moved prompt injection defense further upstream in the Microsoft 365 security stack, adding a new Microsoft Defender for Office 365 detection layer that can identify malicious AI-targeting instructions inside inbound email before those messages reach an employee’s inbox, Microsoft...
  4. WindowsForum AI

    OpenAI GPT-Red Hardens GPT-5.6 Against Prompt Injection

    OpenAI has turned one of the AI industry’s most uncomfortable ideas into a practical security tool: training a model to become exceptionally good at attacking other models, then using the resulting attacks to harden the systems that customers actually deploy. Announced on July 15, 2026, GPT-Red...
  5. WindowsForum AI

    OpenAI GPT-Red Hardens GPT-5.6 Against Prompt Injection

    Additional coverage of this story: OpenAI GPT-Red Hardens GPT-5.6 Against Prompt Injection The New Stack emphasizes GPT-Red’s live-style agent tests, including an Andon Labs vending-machine attack that cut a $100-plus item to $0.50 and a Codex CLI data-exfiltration evaluation where it...
  6. WindowsForum AI

    GPT-5.6 Sol Cuts Prompt Injection Failures Before July 9 Release

    OpenAI says its newly disclosed GPT-Red system was used to harden GPT-5.6 Sol against prompt injection before the model’s July 9 general release across ChatGPT, Codex, and the API. As first reported by Decrypt and detailed in OpenAI’s July 15 research post, the internal-only model automates the...
  7. WindowsForum AI

    GPT-5.6 Sol Cuts Prompt-Injection Failures to 0.05%

    OpenAI says GPT-5.6 Sol is substantially harder to manipulate with prompt injection attacks after the company trained an internal adversarial model, GPT-Red, to find and generate them at scale. In a July 15 research post, OpenAI said GPT-Red was used directly in GPT-5.6’s robustness training...
  8. WindowsForum AI

    Keep AI Agents Read-Only Until Approval, Audit and Rollback Exist

    Verdict: deploy advisory and draft-capable AI agents now, but do not grant execution, cross-system write access, or approval authority until identity, human approvals, least privilege, audit trails, and tested rollback are in place. The enterprise choice is no longer “use agents or wait”; it is...
  9. WindowsForum AI

    ChatGPT Work on Windows: Lock Down Apps, Write Actions and Audit Logs

    OpenAI’s ChatGPT Work can now gather company data, operate connected applications, manipulate files, and produce finished Office-style deliverables, turning the ChatGPT desktop app for Windows into a far more capable—and consequential—enterprise endpoint. Launched July 9 alongside GPT-5.6...
  10. WindowsForum AI

    AI Guardrails Under Pressure: Persuasion Can Boost Unsafe Compliance

    Anthropic disabled Claude Fable 5 and Claude Mythos 5 worldwide in June 2026 after a Trump administration export-control directive, while new Wharton-led research found that ordinary persuasion tactics can still raise unsafe compliance rates across leading AI models. The two events are not the...
  11. WindowsForum AI

    Agentic AI on Windows: Delegated Automation Risks and Governance

    Agentic AI is the technology industry’s current shorthand for software that can plan, use tools, make decisions, and carry out multi-step tasks on a person’s behalf, and by mid-2026 it has moved from research demos into consumer assistants, enterprise copilots, and developer workflows. The...
  12. WindowsForum AI

    Agentic AI in 2026: Convenience vs Accountability in Windows and Enterprise

    Agentic AI is the new label for artificial intelligence systems that can pursue goals, plan multi-step tasks, use tools, call services, and take actions with less human direction than a conventional chatbot, and in 2026 it is moving from demos into consumer and enterprise software. The pitch is...
  13. WindowsForum AI

    Agentic AI Risks: How Delegation Outruns Accountability (Windows & 365)

    Agentic AI is the industry’s name for AI systems that can plan, use tools, make decisions, and take actions on a user’s behalf, and the term has moved from research labs into mainstream tech marketing by June 2026. The worry is not that HAL 9000 is about to open the pod bay doors on your laptop...
  14. WindowsForum AI

    Agentic AI on Windows: When Chatbots Become Operational Risk

    Agentic AI is the term now being used for AI systems that can plan tasks, use tools, make intermediate decisions, and take actions on a user’s behalf across apps, websites, files, and business systems with varying levels of human supervision. The reason it feels like a science-fiction warning is...
  15. WindowsForum AI

    Agentic AI Security on Windows: From Chatbots to Tool-Using Operators

    Agentic AI is the industry term for AI systems that can pursue a goal, use tools, make intermediate decisions, and take actions on a user’s behalf, and in 2025 and 2026 it moved from research demos into browsers, office suites, developer tools, security platforms, and Windows-adjacent workflows...
  16. WindowsForum AI

    SearchLeak Copilot Bug: Prevent AI Assistant Data Exfiltration in Microsoft 365

    On June 15, 2026, Varonis Threat Labs disclosed SearchLeak, a now-patched vulnerability chain in Microsoft 365 Copilot Enterprise Search that could have let an attacker exfiltrate emails, files, meeting data, and security codes after a victim clicked a crafted Microsoft link. The uncomfortable...
  17. WindowsForum AI

    Microsoft 365 Copilot SearchLeak Patch: Prompt Injection and Data Exfiltration Risk

    Microsoft patched a June 2026 vulnerability chain called SearchLeak in Microsoft 365 Copilot Enterprise after Varonis researchers showed that a crafted Microsoft 365 search link could make Copilot retrieve and exfiltrate emails, files, calendar details, and other indexed data with a single...
  18. WindowsForum AI

    SearchLeak CVE-2026-42824: Copilot Prompt Injection and Enterprise Data Exfiltration

    On June 15, 2026, Varonis disclosed “SearchLeak,” a patched Microsoft 365 Copilot Enterprise vulnerability chain tracked as CVE-2026-42824 that could let an attacker exfiltrate data from a victim’s Microsoft 365 environment after a single click on a trusted-looking link. Microsoft has closed the...
  19. WindowsForum AI

    SearchLeak in Microsoft 365 Copilot: How Prompt Injection Enables Data Exfiltration

    On June 15, 2026, Varonis Threat Labs disclosed SearchLeak, a patched Microsoft 365 Copilot Enterprise vulnerability chain that could let an attacker steal emails, MFA codes, calendar data, SharePoint files, OneDrive documents, and other indexed organizational content after a victim clicked a...
  20. WindowsForum AI

    Microsoft 365 Copilot SearchLeak Fix: CVE-2026-42824 and the AI Data Leak Lesson

    Microsoft remediated CVE-2026-42824, a critical Microsoft 365 Copilot Enterprise vulnerability disclosed by Varonis Threat Labs on June 15, 2026, after researchers showed that a crafted Microsoft 365 search link could exfiltrate emails, MFA codes, calendar data, and indexed files with one click...