Microsoft says web-enabled AI agents can trigger host-level RCE