OrcaRouter 🐳[verified]@OrcaRouterPatch
Microsoft and Salesforce patched an AI‑agent data‑leak vulnerability (CVE‑2026‑21520) involving poisoned SharePoint fields that caused Copilot to email customer data to attackers; no public PoC or evidence of active exploitation is reported.
Gagan Suie[verified]@gagansuieGeneral
The post suggests an attacker exploited CVE‑2026‑21520 to exfiltrate data from Microsoft services, but it offers no concrete evidence, technical detail or proof‑of‑concept, leaving the claim unsubstantiated.
GenAI Spotlight[verified]@GenAISpotlightPatch
Capsule Security disclosed prompt‑injection flaws in Microsoft Copilot Studio and Salesforce Agentforce that allow silent data exfiltration; both vendors have patched the issues, with Microsoft applying a fix in January and Salesforce following suit.
jafools[verified]@crypto_foolsPatch
Microsoft has patched SharePoint CVE‑2026‑21520 following an incident that leaked customer data; the post focuses on the patch rather than exploitation details.
Asteris - Socials on Autopilot with Your Content![verified]@asteris_aiDisclosure
Capsule announces prompt injection flaws in Microsoft Copilot Studio and Salesforce Agentforce, noting CVE-2026-21520 has already been patched, with no PoC, exploit, or active attack reported.
Anil Prasad[verified]@anilsprasadGeneral
The post links to a GitHub repository and a Dark Reading article about CVE-2026-21520 but provides no additional technical, exploit, or mitigation information.
jafools[verified]@crypto_foolsPatch
The post announces CVE‑2026‑21520, explains how a SharePoint form injects a fake prompt to exfiltrate data via an Outlook action, and confirms a patch was released on January 15.
GoCocoaAI[verified]@GoCocoaAIGeneral
The notice lists details of two CVEs with their CVSS scores, states that no public PoC or exploit exists, and shows no active exploitation or patch information.