Microsoft patched a critical vulnerability in its M365 Copilot AI platform last Tuesday. Researchers who discovered the flaw showed how their proof-of-concept exploit could retrieve two-factor authentication codes and other sensitive data from emails Copilot could access.
The underlying issue is that AI chatbots cannot distinguish user instructions from those embedded in third-party content, making them susceptible to data exfiltration. Attackers bypassed guardrails by using markup language or HTML tags to send stolen data to their own servers.
Comments