The Cybersecurity and Infrastructure Security Agency (CISA) has added a new SharePoint zero-day, CVE-2026-32201, to its Known Exploited Vulnerabilities list, confirming active exploitation and ...
Microsoft assigned CVE-2026-21520, a CVSS 7.5 indirect prompt injection vulnerability, to Copilot Studio. Capsule Security discovered the flaw, coordinated disclosure with Microsoft, and the patch was ...
In 2026, Microsoft is embedding Copilot deeper into OneDrive and Power Automate, enabling natural-language workflow creation and intelligent file management. These updates, along with advances in ...