Microsoft's M365 Copilot AI platform was patched after a critical vulnerability was discovered, allowing hackers to extract 2-factor authentication codes and sensitive data. The flaw stems from the models' inability to differentiate between user instructions and third-party content, leaving them vulnerable to malicious requests for sensitive information.
Researchers have found ways to exploit these vulnerabilities by using markup languages or embedding HTML tags around sensitive data to bypass security measures. This highlights the challenge of securing AI systems and necessitates robust guardrails to prevent unauthorized data access.
Comments