Tuesday, September 8, 2026

Hackers Abuse Copilot Studio’s New Connected Agents Feature to Plant Backdoors

Microsoft’s latest innovation may have opened the door to sophisticated cyberattacks. At Build 2025, the company introduced “Connected Agents,” a feature in Copilot Studio that allows AI agents to communicate and share functionality across environments.

While designed to streamline development, security researchers have identified critical vulnerabilities that could enable attackers to impersonate organizations and execute unauthorized actions.

The Feature

Connected Agents works on a simple principle: developers can toggle a setting to expose selected agent capabilities, tools, knowledge, and topics to other agents in the same environment.

This eliminates code duplication, much like reusing functions in traditional software development.

An agent equipped to send emails, for example, can be reused by multiple other agents without having to rebuild the same functionality.

Public Faced Agent
Public Faced Agent

However, the feature’s default configuration creates a dangerous blind spot. Connected Agents are enabled by default for all agents, and administrators have zero visibility into which other agents have connected to their systems, at least not through Copilot Studio itself.

Additionally, invocations of connected agents generate no activity logs in the invoked agent’s audit trail, making unauthorized connections virtually invisible.

Consider a real-world scenario, A customer support agent is configured to send emails from a company’s official support address.

Because Connected Agents is automatically enabled, any other agent in the environment, or one created by a malicious insider, can invoke this email capability.

A disgruntled employee or external attacker with tenant access can make a rogue agent that connects to the legitimate support agent and begins sending fraudulent emails impersonating the company.

 email‑sending tool
 email‑sending tool

The damage escalates rapidly. Attackers can conduct phishing campaigns, distribute misinformation, or trigger domain blocklisting through spam.

If the compromised agent is made publicly accessible, unauthenticated internet users could potentially exploit the email-sending functionality.

 simple POC
 simple POC

According to Zenity Labs, Microsoft’s logging architecture exacerbates the problem. Activity tabs show no record when a connected agent invokes another agent.

Defenders have no way to detect abuse through native Copilot Studio monitoring. Third-party tools like Zenity can provide visibility, but most organizations lack such solutions.

Organizations should immediately audit their Copilot Studio environments for connected agents, turn off the feature for sensitive agents handling critical operations, and restrict agent sharing to trusted internal users only.

Implement monitoring solutions to track inter-agent communication and establish approval workflows before agents perform privileged operations, such as credential-based actions.

Connected Agents demonstrates how innovation in AI orchestration can inadvertently create security liabilities. Without proper controls, Microsoft’s convenient feature becomes an attacker’s backdoor.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Steal Microsoft 365 Sessions to Hijack Accounts Even After MFA

Cybercriminals are using a rebranded Evilginx2 phishing-as-a-service platform dubbed...

Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through

A known Shai-Hulud npm worm payload has resurfaced after...

Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365

Switzerland’s Federal Chancellery is advancing a sovereign digital workplace...

Mathspace Data Breach Exposes Personal Data of Over 1 Million Students, Parents and Staff

Mathspace, an online mathematics learning platform used by schools...

New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away

Security researchers have unveiled InjectEave, an electromagnetic side-channel attack...

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP...

Related Articles

Recent News