TL;DR: AI agent attack techniques are resurfacing across platforms, with Zenity describing how prompt injection, retrieval poisoning, trusted-domain abuse, and image-rendering tricks reappear in Bing, Microsoft 365 Copilot, Salesforce Einstein, and Agentforce. The pattern shows that agent risks are structural, not one-off vulnerabilities, and demand a dedicated security layer rather than vendor-only fixes.
Editorial analysis by NHI Mgmt Group, based on content published by Zenity: “0Click Attacks: When TTPs Resurface Across Platforms”.
Key questions
Q: What breaks when prompt injection reaches an AI agent's retrieval corpus?
A: The boundary between data and instructions breaks.
Q: Why do trusted domains create extra risk for AI agent security?
A: Because trust can be inherited by content that was never meant to deserve it.
Q: How can security teams tell whether an agent is exposed to prompt injection?
A: Look for agents that read untrusted sources, preserve retrieved context across sessions, and can render or call out to external resources automatically.
Practitioner guidance
- Map agent retrieval boundaries Identify where assistants, copilots, and agentic workflows consume content from email, CRM, files, or tickets and classify those sources as untrusted unless explicitly verified.
- Restrict rendering and outbound fetches Limit markdown image loading, external content fetching, and other automatic render behaviours for agents that process mixed-trust data.
- Separate instructions from records Design storage and retrieval layers so that user-generated content cannot silently become executable instructions inside an agent context.
Bottom line: AI agent prompt injection is no longer confined to one platform, because the same abuse pattern keeps reappearing where retrieval and rendering are combined.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Prompt injection is now a control-plane problem, not a prompt-quality problem. The article shows that the same abuse pattern can move from one platform to another with only small changes in payload and delivery. That means the relevant failure is not simply bad model output, but the absence of a governance boundary between trusted instructions and untrusted content. Practitioners should treat this as an agent security architecture issue, not a user-training issue.
A question worth separating out:
Q: How do organisations separate AI governance from AI security testing?
A: AI governance defines what should be allowed, while AI security testing verifies whether the deployed system actually stays within those boundaries. Governance without runtime validation is only policy on paper, especially once agents can retrieve data, call tools, and trigger workflows on their own.
👉 Read our full editorial: AI agent prompt injection keeps resurfacing across platforms