Why STRIDE Breaks When You Threat Model AI Agents (And What to Do Instead)
In June 2025, Microsoft patched a CVSS 9.3 vulnerability in Microsoft 365 Copilot that let an attacker exfiltrate sensitive corporate data , emails, SharePoint files, and Teams messages with a single crafted email. No clicks required. No malware. No code execution. The payload was pure natural language, hidden inside an ordinary-looking business document. The researchers […]
Why STRIDE Breaks When You Threat Model AI Agents (And What to Do Instead) Read More »





