Sign in to baba News

The Desk, the news read to you every hour, is part of News Plus.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

↑↓ to move · ↵ to open · esc to close

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Microsoft Warns of AI Email Attacks Hiding Malicious Commands in Innocent Messages

By דנה גוטרזון
Translated & summarized from N12 by baba
The story · English

As organizations increasingly integrate AI agents with email, calendars, and documents to automate tasks, security researchers warn of a new threat: attackers embedding malicious instructions within seemingly harmless emails to manipulate AI agents. Shaked Ilan, a senior security researcher at Microsoft Israel R&D, explains that unlike traditional phishing targeting humans, these "Prompt Injection" attacks aim directly at AI agents processing the emails.

Attackers can hide commands using techniques such as white text on white backgrounds, tiny fonts, or embedding instructions deep within long email threads or attachments. These hidden prompts can cause AI agents to leak sensitive information, change payment details, or alter the content presented to users without their knowledge. For example, an attacker might insert a command in a payment-related email thread instructing the AI to update bank account information to a fraudulent account.

This vulnerability is particularly concerning in corporate environments where AI agents have broad access to emails, contracts, invoices, and HR documents and can perform actions autonomously. Unlike chatbots that only provide answers, AI agents can execute tasks such as sending messages or accessing systems, increasing the potential damage if manipulated.

To combat this, Microsoft recently introduced a new protective layer within Microsoft Defender for Office 365 that scans incoming emails for hidden malicious instructions before delivery to users or AI agents. This system uses advanced detection methods, including synthetic examples of potential future attacks, to identify and quarantine suspicious messages.

Ilan emphasizes the importance of limiting AI agents’ permissions, requiring human approval for sensitive actions, and monitoring their activities. He compares AI agents to new employees who should not be given unrestricted access immediately. While the current risk is highest in organizational settings, it may also affect private users as AI assistants gain access to personal emails and services.

Read the original at N12

Keep up with

N12Centre · Neve Ilan

Sign in to baba News

Sign in to follow newsrooms, topics and people.

or use an email code

You’ve used your five follows

News Plus follows as many newsrooms, topics and people as you like.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal
See News Plus

Sign in to baba News

Sign in to follow newsrooms, topics and people.

or use an email code

You’ve used your five follows

News Plus follows as many newsrooms, topics and people as you like.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal
See News Plus
Open the live terminal