First reported microsoft.com
News · latest
First reported paloaltonetworks.com
Potential denial of wallet abusing AI services • Cortex XSIAM Analytics Alert Reference by data source • Palo Alto Networks documentation portal
A Palo Alto Networks Cortex XSIAM analytics alert reference page documents a detection named 'Potential denial of wallet abusing AI services,' which flags abuse of cloud AI services (via AWS Audit Log data) to drive up costs in a denial-of-wallet style attack. The page is a product documentation entry describing the built-in detection rather than a technical write-up of the attack mechanism. Details →First reported microsoft.com
Prompt injection protection in Microsoft Defender for Office 365 - Microsoft Defender for Office 365 | Microsoft Learn
Microsoft documentation describes prompt injection protection built into Microsoft Defender for Office 365, which detects attacker-authored instructions embedded in inbound email (body, subject, quoted replies, attachments, or hidden markup) before that content reaches a user or an AI assistant such as Microsoft 365 Copilot. The feature explains indirect prompt injection techniques including direct instructions to the model and hidden/invisible text (white-on-white fonts, zero-size text, HTML/CSS tricks) and detects them as part of existing mail-flow inspection. Details →First reported google.com
Securing agentic AI: What's new in VPC Service Controls | Google Cloud Blog
Google Cloud announces new VPC Service Controls capabilities aimed at securing agentic AI workloads, including treating agents as first-class IAM identities in ingress/egress rules, conditional access based on MCP attributes (mcp.toolName, mcp.method, mcp.tool.isReadOnly), and native integration blocking public access to the Gemini Enterprise Agent Platform. Details →First reported · updated · 2 reports talosintelligence.com
ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Cisco Talos documents ARToken, a phishing-as-a-service affiliate panel sharing infrastructure with the EvilTokens platform, that abuses Microsoft's OAuth device authorization grant to steal tokens and bypass MFA. The AI element is an AI-augmented BEC pipeline chaining Groq-hosted Llama models for financial exposure scoring and GPT-4o-mini for email translation, plus AI-powered personalized lures, to automate fraud against compromised Microsoft 365 mailboxes. Details →First reported theregister.com
Microsoft builds a bouncer to keep bots out of Teams meetings
The Register reports that Microsoft is rolling out bot-detection technology for Teams meetings that uses behavioral and infrastructure signals to distinguish bots from humans, requiring a human in the lobby to deliberately admit a bot. The move responds to unwanted bots—including third-party transcription and meeting-assistant bots—automatically joining meetings that may involve sensitive or NDA-covered discussions, and will add an ISV registration path for known bots while retiring CAPTCHAs. Details →First reported techcrunch.com
OpenAI unveils Lockdown Mode to protect sensitive data from prompt injection attacks
TechCrunch reports OpenAI introduced a 'Lockdown Mode' designed to reduce the likelihood that sensitive data is shared via prompt injection attacks against ChatGPT. The article notes ChatGPT could still be vulnerable even with the feature enabled. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector