CVE Tools

The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive

ESET WeLiveSecurityBy Tomáš Foltýn

Reported exploitedAI AgentsMCP Servers

Our summary

ESET says SMBs adopting AI agents face new risks from excessive permissions, malicious skills, supply-chain changes, and prompt injection. The report highlights Microsoft 365 Copilot and CVE-2025-32711, where indirect prompt injection could expose data, while warning that AI is also accelerating phishing, vulnerability exploitation, and ransomware activity.

Read at ESET WeLiveSecurity

ESET WeLiveSecurity publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store