Prompt Injection
The latest Prompt Injection coverage — news, analysis, and updates from the WindowsNews.AI desk.
Agentic AI Browsers 2025: Security Risks & Protection Strategies
The rapid evolution of agentic AI browsers in 2025 represents both the most significant technological breakthrough and the most concerning security challenge of the year. These intelligent browsing...
CVE-2025-62222: Critical Command Injection Vulnerability in VS Code Copilot Chat
Microsoft has issued a high-severity security advisory for CVE-2025-62222, a critical command injection vulnerability affecting the Visual Studio Code Copilot Chat extension that could allow remote...
CVE-2025-62214: Visual Studio AI Prompt Bug Enables Code Execution
Microsoft has issued a critical security advisory for Visual Studio developers, warning of CVE-2025-62214, a sophisticated AI prompt injection vulnerability that could lead to remote code execution....
GitHub Agent HQ: Securing AI Agents Against Enterprise Security Threats
The rapid proliferation of AI agents across enterprise environments has created unprecedented security challenges that demand immediate attention. GitHub's recent launch of Agent HQ, coupled with a...
Microsoft 365 Copilot Security Flaw: Mermaid Diagrams Enable Data Exfiltration
A sophisticated security vulnerability in Microsoft 365 Copilot has been uncovered, where seemingly innocent Mermaid diagrams can be weaponized to extract sensitive organizational data through...
ChatGPT Atlas: OpenAI's AI Browser Revolution and Security Risks
OpenAI's ChatGPT Atlas represents a fundamental reimagining of what a web browser can be, transforming it from a passive viewing tool into an active, intelligent assistant that can perform tasks,...
CVE-2025-54132: Cursor Mermaid Diagram Security Vulnerability Analysis
A critical security vulnerability designated as CVE-2025-54132 has been identified in Cursor's Mermaid-based diagram renderer, exposing users to potential data exfiltration attacks through...
ASCII Smuggling in Gemini AI Sparks Security Debate Over Prompt Injection
Google's controversial decision not to patch a newly discovered "ASCII smuggling" vulnerability in its Gemini AI has ignited a fierce debate about how to properly secure generative AI models...
CVE-2025-59272: Microsoft Copilot Spoofing Vulnerability Threatens Enterprise Security
Microsoft has disclosed a significant security vulnerability affecting its Copilot AI services and related agentic tooling, designated as CVE-2025-59272. This spoofing-class flaw represents one of...
Microsoft Previews Mandatory Unique IDs for Every Azure AI Agent to End Shadow AI
Microsoft has published a detailed blueprint for locking down autonomous AI agents in the enterprise, anchored by a forthcoming capability that will require every agent to carry a unique identity...
Zenity Embeds Real-Time Attack Prevention Inside Microsoft Copilot Studio Agents
Microsoft Copilot Studio now supports a runtime monitoring API that enables third-party security platforms to inspect and block agent actions in real time, and Zenity has moved quickly to deliver...
Anthropic Adds Project-Scoped Memory to Claude, Gives IT Teams Admin Controls and Incognito Mode
Anthropic today rolled out a long-awaited Memory capability for its Claude assistant, giving Team and Enterprise plan customers the ability to retain and recall project-specific context across chat...