Prompt injections present a significant security challenge as OpenAI’s new ChatGPT Atlas browser integrates advanced AI capabilities. Launched on October 21, 2025, Atlas allows users to leverage its AI for various tasks, but experts warn that it also opens pathways for potential attacks. According to LayerX, a web browser security firm, the Atlas browser was recently found to have vulnerabilities that could allow attackers to inject harmful instructions. OpenAI’s Chief Information Security Officer, Dane Stuckey, acknowledged that prompt injection remains an unresolved security issue, with adversaries likely to invest resources in exploiting these vulnerabilities.
Cybersecurity researchers have identified a significant vulnerability within Microsoft Teams that can allow attackers to bypass Microsoft Defender for Office 365 protections through the guest access feature. When users join an external tenant as guests, their protection is dictated by that environment, not their home organization, raising concerns about the security of external collaborations. Rhys Downing, a security researcher at Ontinue, highlighted that this creates potential “protection-free zones” for attackers who can disable safeguards in their own tenants. The recent update in Teams, which enables users to chat with anyone via email, further complicates this issue by allowing automated invitations that may evade traditional email security measures. Organizations are advised to implement strict B2B collaboration settings and educate employees about the risks of unsolicited Teams invitations to mitigate these threats.
The FBI has reported a staggering $262 million in losses due to account takeover fraud schemes perpetrated by cybercriminals impersonating bank support teams since the beginning of 2025. Over 5,100 complaints have been filed with the FBI’s Internet Crime Complaint Center, affecting individuals and businesses across various sectors. Cybercriminals use social engineering tactics to gain unauthorized access to online banking and payroll accounts, often changing passwords to lock victims out. Once access is secured, these criminals quickly transfer funds to cryptocurrency wallets, making recovery extremely difficult. The FBI advises individuals to monitor their financial accounts closely, utilize complex passwords, enable multi-factor authentication, and directly contact their financial institutions if they suspect fraud.
Why do we care?
The attacks aren’t coming through the neat, technical holes we used to worry about. They’re coming through identity, trust, and the places where users assume they’re protected when they’re not.
Prompt injections in something like the Atlas browser show how fragile these AI integrations really are. This isn’t a patchable flaw — it’s a structural problem in how LLMs work. So if you’re letting AI tools touch customer data or automate tasks, you need guardrails. Assume adversarial content will get through.
Teams guest access? Same issue. The second you step into someone else’s tenant, your protections aren’t your own. And now Microsoft wants users chatting with anyone via email. Great for productivity, terrible for security. If you’re not locking down B2B collaboration, you’re handing attackers an easy path in.
And the FBI’s numbers make it obvious: social engineering beats tech every time. Criminals aren’t breaking in — they’re talking their way in, then draining accounts before anyone notices.
MSPs need to recognize that modern security is about managing trust boundaries, not piling on more tools. AI, Teams, bank portals — it’s all the same lesson. If you don’t control identity, collaboration, and data access, the attackers will.

