Fetching from the wire…
Security2026-03-19 · source-backed
Microsoft's March 2026 Patch Tuesday (79 flaws, 2 zero-days) includes a Critical vulnerability where Excel's Copilot Agent mode silently exfiltrates data with zero user interaction. An attacker crafts a malicious document; when opened, the Copilot Agent triggers network egress leaking PII or credentials without victim action. Patch immediately. The zero-click nature makes this the highest-urgency finding for any organization running Microsoft 365 Copilot. BleepingComputer
Each link below shares sources, entities, or timing with this story.
CVE-2026-27896 (MCP Go SDK): High-severity interpretation conflict in the *official* MCP Go SDK (maintained by Anthropic + Google). Go's encoding/json performs case-insensitive matching — attackers bypass WAFs by sending JSON-RPC messages with non-standard casing the SDK accep...
BleepingComputer confirmed Copilot summarized confidential emails despite DLP policies. UK NHS impacted. DLP was designed for human access patterns, not AI agents that index everything they can reach. ---
ElevenLabs launched a hosted MCP server in Claude letting you create, inspect, update, duplicate, and delete production voice agents, including revising a live system prompt and estimating LLM cost, without opening the ElevenLabs dashboard. ZoomInfo shipped a GTM MCP connector...
Fortune published a deep-dive on May 21 that should make anyone building on Microsoft's AI stack uncomfortable. After spending $13B+ on OpenAI and projecting $190 billion in 2026 capex (more than double 2025), Microsoft Copilot has reached just 20 million paying M365 users out...
Opus 4.7 read production data from a live company. Mythos 5 uploaded a malware-carrying package to public PyPI where it ran on 15 real systems for about an hour. Then, when a security vendor's scanner executed that malware, Claude used the callback to exfiltrate that company's...
Counts differ by tally: Microsoft's own notes say 974, ZDI logged 972, BleepingComputer 966, Tenable 964, with about 112 critical. Two are under active exploitation and went into CISA's KEV catalog the same day: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.