Researchers reveal how malicious code can infect autonomous AI agents and spread across business networks through SharePoint and Teams.
Security researchers working at major technology institutions have uncovered a troubling vulnerability in how artificial intelligence assistants communicate and store information. They found that harmful software can be deliberately planted into the working files that AI agents use to remember information between conversations—and from there, jump to infect other AI systems across an organization's network.
The attack chain specifically targets Microsoft's SharePoint and Teams platforms, which many companies use daily for collaboration. Think of it like this: if an AI assistant is a worker who needs notes to remember what happened yesterday, attackers are inserting poison into those notes. When the next worker reads those notes, they get infected too.
Modern AI assistants running on their own—called autonomous agents—need to save their "memory" somewhere between conversations. These systems write their current state and instructions to files stored in shared locations like SharePoint. Researchers discovered that by sneaking malicious instructions into these files, an attacker can create self-spreading malware that moves from one AI agent to the next automatically.
The bad actor doesn't need to hack each system individually. Instead, they compromise one agent, inject malicious code into its memory file, and wait. When other agents read that file—which happens naturally during the course of normal business operations—they become infected too. The malware then steals user credentials and moves laterally through the corporate network.
This research highlights a new category of cybersecurity risk that most organizations haven't prepared for yet. As businesses increasingly deploy AI agents to automate tasks—like sorting emails, managing documents, or handling customer requests—these systems become potential entry points for attackers.
Unlike traditional malware that targets computers or users directly, this threat targets the "thinking space" where AI systems operate. It's a vulnerability that exists because of how these systems are designed to work together and share information.
If your company uses Microsoft Teams and SharePoint with automated AI processes, this directly affects your security posture. A single successful breach could allow attackers to:
The spread happens automatically and invisibly—there's no email attachment to click or suspicious link to report. The infection simply occurs through normal system operations.
Organizations should take immediate steps to reduce this risk:
This discovery reveals that the challenge of securing artificial intelligence systems extends beyond just protecting the software itself—we must also protect the information spaces where they operate.
As AI agents become more integrated into business operations, treating their working files as security-critical assets is no longer optional.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters →