A critical vulnerability in Microsoft's M365 Copilot AI platform allows hackers to steal 2FA codes and other sensitive data from emails. Researchers have shown how their proof-of-concept exploit can bypass security measures by utilizing the model's inability to distinguish between user instructions and third-party content.
This vulnerability highlights the challenges of securing Large Language Models (LLMs) as they often struggle to differentiate between legitimate requests and malicious inputs, leaving users vulnerable. To mitigate this issue, LLM developers must address this fundamental flaw and implement robust security measures.
Comments