Critical Copilot Vulnerability Enabled Theft of 2FA Codes from Users

Microsoft patched a critical vulnerability in its M365 Copilot AI platform after researchers demonstrated a proof-of-concept exploit that could retrieve two-factor authentication codes and other sensitive data from accessible emails. The root cause is that AI bots cannot distinguish between user instructions and those hidden in third-party content they process. Attackers bypassed guardrails by using markup language or HTML tags to exfiltrate data to their servers.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleWeb Scraper Declares 'Google and Reddit Do Not Own the Internet' After Court Victory
Start typing to search