HomeSecurityHackers exploit Copilot Studio's new Connected Agents feature

Hackers are exploiting Copilot Studio's new Connected Agents feature

recently announced Connected Agents in Copilot Studio , unveiled at Build 2025, creates a serious security hole. Attackers are already exploiting it to gain unauthorized access to critical business systems.

See also: LG installed Copilot on its TVs, but you can delete it

Connected Agents

Connected Agents enables AI-to-AI communication and collaboration, allowing agents to share functions and reuse logic across different environments. While designed to increase efficiency—similar to converting repetitive code into shared functions—it can open dangerous attack paths when misconfigured or used maliciously.

By default, Connected Agents is enabled on all new agents in Copilot Studio. When enabled, it exposes an agent's knowledge, tools, and topics to all other agents within the same environment.

The main problem is that there is no built-in visibility into which agents are connected to yours, creating a "blind spot" in security monitoring.

According to Zenity Labs, attackers are exploiting this vulnerability by creating malicious agents that are associated with legitimate, high-privileged agents, particularly those with the ability to send email or access sensitive business data. In proof-of-concept, the attackers were able to compromise support agents that were configured to send email from official corporate domains, enabling large-scale phishing and impersonation attacks.

An insider threat or compromised account can create a “backdoor” agent that connects to a legitimate agent and enables email sending capabilities without leaving a trace in the activity logs.

See also: Microsoft Copilot's holiday ad is full of empty promises

Hackers are exploiting Copilot Studio's new Connected Agents feature

Activating Connected Agents does not produce any messages in the targeted agent's activity tab, bypassing standard audit mechanisms.

This way, the attacker can send emails impersonating your company to thousands of recipients and destroy your reputation through misinformation. It can also cause domain blocking due to spam, while everything appears to come from your own infrastructure.

Zenity Labs recommends that organizations perform direct testing on agents in production.

  • Disable Connected Agents on all agents that contain unverified tools or sensitive knowledge sources before publishing.
  • Implement authentication in tools so that sensitive actions require explicit user credentials and not just owner permissions.
  • For business-critical agents, disable Connected Agents completely. Review all knowledge sources and publishing channels, ensuring that current and future users of the environment have legitimate access to every available feature.

Zenity Labs also suggests that Microsoft set this feature to be disabled by default, shifting the responsibility to developers to enable the feature if they wish, rather than requiring security after release.

See also: ChatGPT and Copilot are moving away from WhatsApp

Microsoft recall

Until full fixes are in place, any agent with Connected Agents enabled should be considered publicly accessible for security reasons.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS