Edge AI Agent Race-Condition Prompt Injection (CVE-2026-55945)
Detects rapid, closely-spaced network requests from the Microsoft Edge process (msedge.exe) to Microsoft-hosted domains within a very short timeframe. This behavior is indicative of a race-condition exploitation technique (CVE-2026-55945) intended to manipulate the Edge AI agent's state transitions, specifically forcing it from 'think' mode into 'act' mode to facilitate unauthorized command injection.
Microsoft Sentinel (KQL)

