Sign in to baba News

The Desk, the news read to you every hour, is part of News Plus.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

↑↓ to move · ↵ to open · esc to close

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Microsoft Warns of AI Email Attacks Hiding Malicious Commands in Innocent Messages

By דנה גוטרזון
Translated & summarized from Mako by baba
The story · English

Microsoft security researcher Shaked Ilan from Microsoft Israel R&D reveals a new cyber threat targeting AI agents integrated with email systems. Attackers embed hidden malicious instructions within seemingly harmless emails using techniques like white text on white backgrounds, tiny fonts, or long email threads. These commands can manipulate AI agents to perform unauthorized actions such as extracting sensitive data, changing payment details, or sending documents externally without the user's knowledge.

Unlike traditional phishing aimed at humans, this "Prompt Injection" attack targets AI agents directly, exploiting their ability to read and act on email content autonomously. For example, an attacker might insert a command in a payment-related email thread that causes the AI to alter bank account details when summarizing the conversation, deceiving the user who only sees a normal summary.

This risk is especially critical in organizations where AI agents have broad access to emails, contracts, invoices, and HR documents, and can execute tasks independently. Microsoft distinguishes between chatbots, which only provide answers, and AI agents that can perform actions, increasing potential damage if compromised.

To counter this, Microsoft recently introduced enhanced protections within Microsoft Defender for Office 365. This system scans incoming emails before delivery to users or AI agents, detecting and quarantining hidden malicious instructions. The defense leverages synthetic datasets of millions of attack variations to identify new and evolving threats.

Ilan emphasizes the importance of limiting AI agent permissions, requiring human approval for sensitive operations, and monitoring AI activities. He compares AI agents to new employees who should not receive unrestricted access immediately. While the threat is currently most significant in corporate environments, it may also affect private users as AI assistants gain access to personal emails and calendars.

Read the original at Mako
Full coverage · 2 outlets
100% centerFirst: Mako · Aug 10

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Center 2
Related stories · 5

Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.

Ask About This Article

Duki reads it, and every newsroom on the same story, then answers with sources.

Open the live terminal