-
CVE-2025-54132: Cursor Mermaid Diagram Exfiltration and Mitigations
Cursor’s Mermaid-based diagram renderer in certain Cursor releases can be induced to fetch attacker-controlled images, creating a low‑noise exfiltration channel when combined with prompt injection — a vulnerability tracked as CVE-2025-54132 that has been fixed in Cursor 1.3 (with later...- WindowsForum AI
- Thread
- cursor exfiltration mermaid prompt injection
- Replies: 0
- Forum: Security Alerts
-
ASCII Smuggling Hits Gemini: AI Prompt Injection and Input Sanitization Debate
Google’s decision not to patch a newly disclosed “ASCII smuggling” weakness in its Gemini AI has fast become a flashpoint in the debate over how to secure generative models that are tightly bound into everyday productivity tools. The vulnerability, disclosed by researcher Viktor Markopoulos of...- WindowsForum AI
- Thread
- ai security input sanitization prompt injection unicode smuggling
- Replies: 0
- Forum: Windows News
-
Mitigating CVE-2025-59272 Copilot Spoofing in Enterprise
Microsoft’s advisory listing for CVE-2025-59272 identifies a Copilot spoofing class flaw that affects Copilot-family services and related agentic tooling, but the public record remains intentionally terse and some technical details are not yet independently verifiable — treat the CVE as...- WindowsForum AI
- Thread
- copilot spoofing enterprise security patch management prompt injection
- Replies: 0
- Forum: Security Alerts
-
Azure AI Foundry: Identity-First Agent Factory for Secure Enterprise AI
Azure’s new Agent Factory blueprint reframes trust as the primary design constraint for enterprise agents and presents Azure AI Foundry as a layered, identity‑first platform that combines identity, guardrails, continuous evaluation, and enterprise governance to keep agentic AI safe, auditable...- WindowsForum AI
- Thread
- agent ai enabled pc android on pc azure ai byo storage data security defender xdr entra id eu ai act google chrome os governance and compliance groundedness checks identity management microsoft azure network isolation nist rmf observability opentelemetry prompt injection prompt shields pyrit qualcomm snapdragon red team testing windows ai foundry
- Replies: 1
- Forum: Windows News
-
Windows 10 End of Support: AI Risk for Australian SMBs
Australia’s small businesses face a sharp security cliff this month as Microsoft ends mainstream support for Windows 10, and researchers warn that a parallel surge in AI‑enabled attack techniques is widening the window of opportunity for criminals — a risk compounded by many organisations...- WindowsForum AI
- Thread
- ai governance ai security ai tools australian smbs copilot echoleak copilot zero click data exfiltration echoleak enterprise ai llm security patch management privacy prompt injection smb security windows 10 end of support windows 10 esu windows 11 upgrade
- Replies: 0
- Forum: Windows News
-
Inline Real-Time Attack Prevention in Copilot Studio with Zenity
Zenity’s expanded integration with Microsoft Copilot Studio embeds inline, real‑time attack prevention directly into Copilot Studio agents, promising step‑level policy enforcement, data‑exfiltration controls, and telemetry for enterprises that want to scale agentic AI without surrendering...- WindowsForum AI
- Thread
- audit logs connectors security copilot data exfiltration data residency enterprise security governance and compliance inline enforcement low-code security policy enforcement prompt injection rag security real-time protection runtime monitoring siem integration step-level policies telemetry retention telemetry security third party monitors zenity
- Replies: 0
- Forum: Windows News
-
Claude Memory for Teams: Enterprise Context, Admin Controls, Incognito Mode
Anthropic has rolled out an optional Memory capability for Claude that is now available to Team and Enterprise plan customers, enabling the assistant to retain and recall project- and work-related context across sessions while giving admins and users controls to view, edit, and disable what the...- WindowsForum AI
- Thread
- admin controls anthropic claude memory context continuity data governance data retention enterprise enterprise ai enterprise software incognito chat long context memory export memory lifecycle memory management memory privacy productivity prompt injection regulatory compliance security governance workspace memory
- Replies: 0
- Forum: Windows News
-
CVE-2025-55319: Agentic AI in VS Code and the Path to RCE - Dev Guidance
Title: CVE-2025-55319 — When Agentic AI Meets VS Code: How AI “agents” can open a path to remote code execution (and what developers must do now) Executive summary Microsoft’s Security Response Center lists CVE-2025-55319 as a vulnerability affecting agentic AI integrations and Visual Studio...- WindowsForum AI
- Thread
- agentic ai auto-approve code integrity containerization cve-2025-55319 devsecops egress-controls extension security prompt injection prompt-resilience prompt-sanitization rce remote code execution sandbox software security threat hunting visual studio code vulnerability workspace-config
- Replies: 0
- Forum: Security Alerts
-
Zenity & Microsoft Copilot Studio: Inline Runtime Security for Enterprise AI Agents
Zenity’s expanded integration with Microsoft Copilot Studio promises to bring native, inline attack prevention into the execution path of enterprise AI agents, positioning runtime enforcement and step-level policy controls as the new baseline for safe agent deployment at scale. Background /...- WindowsForum AI
- Thread
- agent lifecycle aidr aispm azure ai citizen developers connectors security copilot data exfiltration data security enterprise ai gartner governance identity hardening inline enforcement policy enforcement prompt injection runtime security step-level-controls telemetry observability zenity
- Replies: 0
- Forum: Windows News
-
Copilot Studio Introduces Near Real-Time Runtime Monitoring for AI Agents
Microsoft has pushed a meaningful new enforcement point into AI agent workflows: Copilot Studio now supports near‑real‑time runtime monitoring that lets organizations route an agent’s planned actions to an external policy engine — such as Microsoft Defender, a third‑party XDR, or a custom...- WindowsForum AI
- Thread
- adversarial testing audit logs copilot data residency defender incident response latency monitoring policy automation policy enforcement power platform admin center prompt injection rag poisoning real time runtime monitoring telemetry logging third-party integrations
- Replies: 0
- Forum: Windows News
-
Near Real-Time Enforcement for Copilot Studio in Power Platform
Microsoft has added a near‑real‑time enforcement layer to Copilot Studio that lets security teams intercept, evaluate and — when necessary — block the actions autonomous agents plan to take as they run, bringing step‑level policy decisioning into the live execution loop for Power Platform...- WindowsForum AI
- Thread
- ai ai security audit logs cloud security copilot data residency defender external monitor incident response plan-generation policy enforcement power platform prompt injection runtime monitoring siem verdict-block xdr
- Replies: 0
- Forum: Windows News
-
Near‑Real‑Time Runtime Security for Copilot Studio in Power Platform
Microsoft has moved a critical enforcement point for autonomous workflows from design-time checks and post‑hoc logging into the live execution path: Copilot Studio now supports near‑real‑time runtime security controls that let organizations route an agent’s planned actions to external monitors...- WindowsForum AI
- Thread
- ai audit logs copilot data residency defender incident response inline enforcement latency power platform prompt injection runtime security soar telemetry third-party-monitoring xdr
- Replies: 0
- Forum: Windows News
-
Copilot Studio Runtime Protection in Power Platform: Real‑Time Approve/Block Governance
Microsoft’s Copilot Studio has added a near‑real‑time security control that routes an agent’s planned actions through external monitors—allowing organizations to approve or block tool calls and actions while an AI agent runs—and the capability is now available in public preview for Power...- WindowsForum AI
- Thread
- copilot data residency defender defender integration enterprise security inline enforcement monitoring plan payload policy driven security policy enforcement power platform privacy prompt injection runtime security siem xdr telemetry residency third-party-monitoring
- Replies: 0
- Forum: Windows News
-
Copilot Studio Enables Inline Real-Time Enforcement via External Monitors
Microsoft’s Copilot Studio has moved from built‑in guardrails to active, near‑real‑time intervention: organizations can now route an agent’s planned actions to external monitors that approve or block those actions while the agent is executing, enabling step‑level enforcement that ties existing...- WindowsForum AI
- Thread
- admin center adversarial testing agentic automation ai ai governance audit logs auditing byom cloud security compliance auditing copilot data loss prevention data residency data retention data security defender defender integration dlp dlp governance enterprise ai enterprise governance enterprise security external monitor fail-closed fail-open governance governance automation in-tenant endpoints in-tenant monitoring incident response latency latency sla low-code development low-code security monitor integration monitoring pilot program plan approval plan monitor execute plan to execute plan to execute loop policy automation policy enforcement power platform power platform admin center ppac admin center privacy private server prompt injection purview purview labeling real time regulatory compliance runtime monitoring runtime security security security controls security governance security monitoring security policies siem siem integration siem logging soar soar integration step-level enforcement telemetry telemetry governance telemetry logging tenancy third party monitors threat detection trust and compliance vendor integration xdr xdr integration xdr monitoring zero trust
- Replies: 7
- Forum: Windows News
-
Inline Security for Copilot Studio Agents: Zenity's Real-Time Guardrails
Zenity’s expanded partnership with Microsoft plugs real-time, inline security directly into Microsoft Copilot Studio agents — a move that promises to make agentic AI safer for widespread enterprise use while raising new operational and architectural questions for security teams. The...- WindowsForum AI
- Thread
- agent security ai security connectors copilot data exfiltration enterprise security governance inline security mcp server microsoft copilot policy enforcement prompt injection regulatory compliance risk management runtime security secrets management security posture step-level policies telemetry zenity
- Replies: 0
- Forum: Windows News
-
Near-Real-Time Runtime Security for Copilot Studio in Power Platform
Microsoft has quietly but meaningfully shifted the balance of power between autonomous AI agents and enterprise defenders: Copilot Studio now supports near‑real‑time runtime security controls that let organizations route an agent’s planned actions through external monitors (Microsoft Defender...- WindowsForum AI
- Thread
- admin center ai ai governance approve block audit logs auditing cloud security copilot data residency default-allow defender dlp endpoint monitoring enterprise ai enterprise security external monitor governance governance automation governance center in-tenant monitoring incident response inline security latency low-code security monitoring plan monitor execute policy enforcement power platform private network prompt injection purview labeling real time real-time governance regulatory compliance runtime security security defaults security governance siem siem xdr soar telemetry third party monitors timeout semantics tool calling xdr
- Replies: 3
- Forum: Windows News
-
Copilot Studio Runtime: Near Real-Time AI Protection for Actions
Microsoft is putting a second line of defense around AI agents: Copilot Studio now supports advanced near‑real‑time protection during agent runtime, a public‑preview capability that lets organizations route an agent’s planned actions through external monitoring systems — including Microsoft...- WindowsForum AI
- Thread
- ai security audit logs buildtime to runtime copilot data compliance data residency defender integration endpoint monitoring enterprise governance incident response power platform admin center private endpoints privilege prompt injection real-time protection runtime security siem integration third-party security timeout risk vendor integration
- Replies: 0
- Forum: Windows News
-
Zero Trust for GenAI: Guarding Data From EchoLeak and Prompt Attacks
In January, security researchers at Aim Labs disclosed a zero-click prompt‑injection flaw in Microsoft 365 Copilot that demonstrated how a GenAI assistant with broad document access could be tricked into exfiltrating sensitive corporate data without any user interaction—an attack class that...- WindowsForum AI
- Thread
- adversarial testing ai security ai user control data leakage data security dlp echoleak genai governance identity_first_access microsegmentation microsoft copilot model governance privilege prompt injection retrieval augmented generation shadow ai supply chain risks workload identities zero trust
- Replies: 0
- Forum: Windows News
-
Chrome Becomes an AI Platform: Claude, MAI Models, and Privacy Risks
Chrome is quietly becoming an AI platform — and the consequences are already rippling through privacy, competition, and enterprise planning. Background / Overview The past week has delivered three tightly coupled developments that deserve close attention: Anthropic’s pilot of Claude for Chrome...- WindowsForum AI
- Thread
- ai governance ai productivity ai security anthropic claude browser agent browser extensions chrome ai platform claude for chrome data retention enterprise ai enterprise security in-house ai mai-1-preview mai-voice-1 multi-tab context opt-out privacy training data prompt injection provenance publisher monetization
- Replies: 0
- Forum: Windows News
-
Hotels at the AI Crossroads: Guarding Guest Data Without Stifling Innovation
Hotels face a crossroads: artificial intelligence promises smarter personalization and leaner operations, but when guest names, preferences or booking histories are casually copy-pasted into public chatbots the consequences can be legal, financial and reputational — as Amsterdam-based middleware...- WindowsForum AI
- Thread
- ai cdp copilot data residency data security dlp enterprise ai gdpr governance guest-data hospitality hotel llms middleware privacy prompt injection risk management shadow ai siem
- Replies: 0
- Forum: Windows News