Microsoft 365 Copilot’s SearchLeak flaw enables silent mailbox exfiltration via crafted URLs, while LiteLLM’s multi-CVE chain allows privilege escalation to admin and remote code execution. Both tools broke the same trust boundary: accepting external input without proper verification gates before executing sensitive operations.