Two major AI tools—Microsoft 365 Copilot Enterprise Search and LiteLLM—exhibited severe security flaws within weeks, demonstrating a critical failure in enterprise AI trust boundaries. Varonis revealed SearchLeak, an exploit allowing silent data exfiltration via crafted URLs that bypass usual security checks. Obsidian Security uncovered a three-part CVE chain in LiteLLM enabling low-privilege users to gain admin access and execute remote code. Additional tools, Langflow and Mini Shai-Hulud, confirmed the prevalence of this vulnerability pattern across AI tool ecosystems, including path traversal and supply-chain attacks. Market leaders like CrowdStrike have responded aggressively, emphasizing the urgent need for identity governance, AI runtime detection, and tighter security controls. The article provides a practical five-point audit framework to help organizations check and patch these weaknesses today, along with board-ready language to communicate risks effectively. This is a structural, plumbing-level issue, not simply a policy gap—fixing it requires immediate technical action before attackers exploit these systemic flaws.
Back