The rapid integration of artificial intelligence into security operations and consumer products has introduced significant new risks, as organizations and vendors rush to deploy AI-driven features without adequate security controls. In security operations centers (SOCs), many teams are experimenting with AI and machine learning tools, but a lack of operational integration and oversight has led to inconsistent results and potential vulnerabilities. The 2025 SANS SOC Survey found that a large portion of SOCs use AI tools informally or without customization, resulting in unreliable outputs and unclear validation processes. When AI is applied to well-defined tasks with rigorous review, it can enhance detection engineering, process repeatability, and staff efficiency, but careless implementation can create new attack surfaces.
Meanwhile, the introduction of advanced AI features in consumer and enterprise platforms has already been exploited by threat actors. Microsoft’s Copilot Studio "Connected Agents" feature, designed for AI-to-AI integration, has been abused by attackers to gain backdoor access to business systems, enabling large-scale phishing and impersonation attacks without leaving audit trails. Additionally, the proliferation of agentic AI browsers and chatbots has exposed users to prompt injection attacks and sophisticated scams, including fake interfaces and misconfigured AI-powered devices. These incidents underscore the urgent need for deliberate, security-focused integration of AI technologies, as well as robust monitoring and validation mechanisms to prevent exploitation by malicious actors.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Security reporting disclosed that attackers were already abusing Copilot Studio's default-enabled Connected Agents feature to access other agents' knowledge and tools within the same environment. The issue was framed as a significant security exposure that could enable large-scale phishing, impersonation, and brand damage until mitigations or product changes are made.
Zenity Labs showed proof-of-concept attacks in which a malicious agent connected to a privileged Copilot Studio agent and gained the ability to send emails from official company domains. The research highlighted that poor visibility and missing audit logging could let phishing or impersonation activity occur without detection.
At Build 2025, Microsoft introduced the Connected Agents feature for Copilot Studio, enabling AI agents to connect to and share functionality with other agents in the same environment. The feature was described as enabled by default on new agents, creating broad inter-agent access unless restricted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecybersecuritynews.com
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.