Microsoft, Salesforce Patch AI Agent Data Leak Flaws
2026-04-15T14:51:48Z•ce4e2c1f39e4da4119339d09a0809cdb8c04e9c9b574d3818bb1c0dc5af0d694
active-exploitationadobe-acrobatai-securityanthropic-mythosapt41byovdcloud-credentials-theftcredential-harvestingcve-2026-35616data-leakedr-killerfortinetgrafanaot-icsphi-breachprompt-injectionransomwarereact2shellsupply-chain-attackzero-day
What happened
This Dark Reading roundup highlights a surge of high-impact vulnerabilities and active campaigns across AI agents, cloud environments, endpoint products and OT. Notable patches include prompt-injection fixes for Salesforce Agentforce and Microsoft Copilot that could have leaked sensitive data; a large Microsoft update dominated by elevation-of-privilege bugs (including two zero-days); an emergency Fortinet FortiClient fix (CVE-2026-35616); and an actively exploited Adobe Acrobat/Reader zero-day used via malicious PDFs. Threat activity includes APT41 delivering a stealthy backdoor to harvest AW
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- ce4e2c1f39e4da4119339d09a0809cdb8c04e9c9b574d3818bb1c0dc5af0d694
- Enrichment time
- 2026-04-15T14:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.