Microsoft, Salesforce Patch AI Agent Data Leak Flaws

2026-04-15T14:51:48Zce4e2c1f39e4da4119339d09a0809cdb8c04e9c9b574d3818bb1c0dc5af0d694
active-exploitationadobe-acrobatai-securityanthropic-mythosapt41byovdcloud-credentials-theftcredential-harvestingcve-2026-35616data-leakedr-killerfortinetgrafanaot-icsphi-breachprompt-injectionransomwarereact2shellsupply-chain-attackzero-day

What happened

This Dark Reading roundup highlights a surge of high-impact vulnerabilities and active campaigns across AI agents, cloud environments, endpoint products and OT. Notable patches include prompt-injection fixes for Salesforce Agentforce and Microsoft Copilot that could have leaked sensitive data; a large Microsoft update dominated by elevation-of-privilege bugs (including two zero-days); an emergency Fortinet FortiClient fix (CVE-2026-35616); and an actively exploited Adobe Acrobat/Reader zero-day used via malicious PDFs. Threat activity includes APT41 delivering a stealthy backdoor to harvest AW

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
ce4e2c1f39e4da4119339d09a0809cdb8c04e9c9b574d3818bb1c0dc5af0d694
Enrichment time
2026-04-15T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.