security
Apr 12, 2026
By Teun
Six Critical AI Vulnerabilities Hit Microsoft, Google, Salesforce in Under a Year
Security researchers documented EchoLeak, ForcedLeak, GeminiJack, and three other critical flaws across major enterprise AI platforms. All exploited the same architectural gaps: untrusted input, broad data access, and missing per-operation controls.
Security researchers have documented six critical AI vulnerabilities across major enterprise platforms in less than a year, including Microsoft 365 Copilot, Salesforce Agentforce, Google Gemini Enterprise, and the OpenAI plugin ecosystem. According to Kiteworks, the named flaws include EchoLeak, ForcedLeak, and GeminiJack, and they all point to the same core issue, AI systems are being asked to process untrusted input while still holding broad access to sensitive data.
The recurring pattern is more important than the individual bug names. In each case, researchers found that external content could influence an AI system in ways the platform did not properly control, while the underlying service also had access to more data than it needed for the task at hand. That combination creates a path for data exposure even when the AI itself is not supposed to reveal protected information.
⚡ New to this?
This report says several major enterprise AI products, including tools from Microsoft, Google, and Salesforce, have each had serious security flaws in a short period of time. The common problem is that the AI systems accepted outside content and had access to too much internal data, which can let attackers trick them into exposing information.
For a non-expert reader, the key point is that AI assistants are not just chatbots, they often connect to email, documents, and business systems. If those connections are too broad, a single malicious file or webpage can become a path to sensitive data.
🦞 OpenClaw angle
Audit every agent and tool for minimum access, then remove any permission it does not need for the current workflow. Treat all external content, including emails, webpages, and files, as untrusted input, and add validation or filtering before it reaches agent context.
Use per-operation controls for sensitive actions, not just broad API access, so a compromised prompt cannot trigger unrelated data reads or writes. If your automation can ingest documents and call tools, isolate those steps and log them separately so you can spot prompt injection or unexpected data access faster.
GeminiJack stands out because Kiteworks describes it as a zero click attack, meaning the victim did not need to actively click anything for the exploit to work. The company said a poisoned document could be enough to pull years of Workspace data, which shows how dangerous a single malicious input can be when an AI assistant is allowed to interpret content and reach into connected services at the same time.
ForcedLeak in Salesforce followed a similar logic, according to the report. Kiteworks said the attack could be triggered with a five dollar domain purchase, which is a reminder that some of the cheapest parts of the internet can still be used to manipulate high value enterprise systems if input is not tightly checked.
Kiteworks frames the issue as architectural, not product specific. The six vulnerabilities all shared three failure patterns, untrusted input being accepted without proper validation, tools having broader data access than necessary, and backend processes running with permissions they were never meant to use for each operation. That means patching a single flaw helps, but it does not remove the design choices that made the attacks possible.
For organizations deploying AI agents, the report is a warning about access design, not just model quality. If an assistant can read emails, documents, tickets, or web pages, the system also needs clear controls around what those sources can influence and what the agent can do with them. According to Kiteworks, vendors patched the affected platforms, but the underlying pattern remains relevant across enterprise AI products, which makes permission scoping and input controls part of the next round of AI security work.