INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Microsoft and Salesforce Patch AI Agent Data Leak Vulnerabilities
| 2026-04-15 12:00 DATA BREACH VULNERABILITY DISCLOSURE ATTACK ON AI SYSTEMS
Executive Summary
AI-generated
On April 15, 2026, a configuration-specific issue was discovered in Salesforce's AI Agentforce and Microsoft Copilot systems, allowing for prompt injection attacks that enabled the exfiltration of sensitive data. The identified entity behind this incident is not specified, but it appears to be related to Capsule Security, which published research on the vulnerabilities. This vulnerability affects customers using these services, with no specific number provided in the source. According to Capsule's report, an attacker could insert malicious instructions into a public-facing customer relationship management (CRM) form or SharePoint form input, triggering the AI agent's behavior and returning sensitive data to an attacker-controlled email. The current status is that Salesforce has addressed the prompt injection vulnerabilities, but customers are advised to activate human-in-the-loop requirements as a configuration setting to prevent data leaking.
Technical Mitigations AI-generated
• Patch Salesforce Agentforce to address the "PipeLeak" vulnerability (CVE-2026-21520) by configuring lead form inputs as untrusted data.
• Configure Microsoft Copilot to use human-in-the-loop requirements for all email actions, and set custom action configurations with HITL oversight to prevent unintentional data transfers/actions.
• Implement a robust validation mechanism on customer-facing forms to detect malicious prompts before they are processed by the AI agent.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Intelligence Sources
Dark Reading
2026-04-15
Microsoft, Salesforce Patch AI Agent Data Leak Flaws
Dark Reading