Microsoft patched a critical vulnerability in its M365 Copilot AI platform after researchers demonstrated a proof-of-concept exploit that could retrieve two-factor authentication codes and other sensitive data from accessible emails. The root cause is that AI bots cannot distinguish between user instructions and those hidden in third-party content they process. Attackers bypassed guardrails by using markup language or HTML tags to exfiltrate data to their servers.
Critical Copilot Vulnerability Enabled Theft of 2FA Codes from Users
vidgetc
Tech, gaming & AI news — always at hand
Google Play · Soon
App Store · Soon
Comments