Home Cyber Security News Hackers Exploit Copilot Studio’s New Connected Agents Feature to Gain Backdoor Access

Hackers Exploit Copilot Studio’s New Connected Agents Feature to Gain Backdoor Access

0
Hackers Exploit Copilot Studio’s New Connected Agents Feature to Gain Backdoor Access

Microsoft’s latest AI innovation has become a security liability. The tech giant introduced Connected Agents at Build 2025, a feature in Copilot Studio that enables AI agents to communicate and share functionality across environments.

Security researchers at Zenity Labs have now exposed critical design flaws that allow attackers to impersonate organizations and execute unauthorized actions without detection.

How Connected Agents Work

Connected Agents operates through a simple toggle switch that exposes agent capabilities, tools, knowledge, and topics to other agents within the same environment.

This design eliminates code duplication, similar to reusing functions in traditional programming. For instance, an agent configured to send emails can be invoked by multiple other agents without duplicating the same functionality.

The convenience comes at a severe security cost. The feature is enabled by default for all agents, creating immediate exposure.

Administrators have no visibility into which external agents are connected to their systems via Copilot Studio’s native interface.

Most concerning, invocations of connected agents generate no activity logs in the invoked agent’s audit trail, rendering unauthorized connections invisible to security teams.

Consider a customer support agent configured to send emails from a company’s official address.

Because Connected Agents activate automatically, any other agent in the environment, including those created by malicious insiders or compromised accounts, can invoke this email capability.

An attacker with tenant access can deploy a rogue agent that connects to the legitimate support agent and begins sending fraudulent communications.

The potential for impersonation is limitless: phishing campaigns targeting employees and customers, the spread of misinformation that damages brand reputation, or spam that triggers domain blocklisting.

If the compromised agent is publicly accessible, unauthenticated internet users could exploit the email-sending functionality, thereby exponentially amplifying the threat surface.

Microsoft’s logging architecture compounds the vulnerability. Activity tabs display no records when connected agents invoke other agents. Defenders cannot detect abuse through native Copilot Studio monitoring capabilities.

According to Zenity Labs, only third-party solutions, such as their own platform, provide visibility, but most organizations lack such specialized tools.

Organizations should audit their Copilot Studio environments immediately for connected agents. Disable the feature for sensitive agents handling critical operations like financial transactions, email communications, or data access.

Restrict agent sharing to trusted internal users exclusively. Implement third-party monitoring solutions to track inter-agent communication.

Establish approval workflows before agents execute privileged operations requiring credentials.

Connected Agents demonstrates how AI orchestration innovation can inadvertently create security backdoors without proper architectural safeguards.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyber Press as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here