Microsoft has admitted that its new Copilot Actions introduce "novel security risks" like Cross-Prompt Injection (XPIA), ...