Critical Microsoft Copilot flaw could allow theft of two-factor authentication codes

Microsoft patched a critical vulnerability in its M365 Copilot AI platform after researchers demonstrated a proof-of-concept exploit that could retrieve two-factor authentication codes and other sensitive data from emails accessible to the assistant. The root cause lies in the inability of large language models to distinguish between user instructions and malicious commands hidden within third-party content the AI is processing. Attackers bypassed security guardrails—such as restrictions on web form submissions—by using markup language or HTML tags to exfiltrate data, sending sensitive information to attacker-controlled servers.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleWeb Scraper Declares 'Google and Reddit Do Not Own the Internet' After Court Victory
Start typing to search